OpenAI’s Astra raises the bar for cyber-critical model access

Illustrative AI safety image used by WIRED for its Astra coverage.WIRED
Illustrative AI safety image used by WIRED for its Astra coverage.WIRED
AI & Automation

OpenAI says its upcoming Astra model is the first to meet its Critical cybersecurity capability threshold, with its strongest cyber abilities initially limited to trusted testers.

OpenAI says its forthcoming Astra model is the first it has determined to meet the “Critical” cybersecurity capability threshold in its Preparedness Framework. The company plans to make Astra available soon, while limiting its most advanced cyber capabilities to a smaller group of trusted testers at launch.

That makes this an access-and-controls story as much as a model announcement. OpenAI is publishing the safety posture before broad availability, and the exact product name, launch date, pricing, and final access rules remain undisclosed.

What OpenAI says Astra can do

OpenAI’s September 1 announcement says Astra can identify previously unknown software vulnerabilities and develop ways to exploit them across hardened systems. The company says the model performed better than its earlier systems on the relevant internal evaluations and was also more likely to respect explicit security restrictions than GPT-5.6 Sol.

Those are OpenAI’s evaluation claims, not an independent benchmark result. They describe a capability threshold under OpenAI’s own framework, so readers should not treat the label as a universal industry rating or as evidence that every Astra deployment will have the same behavior.

Why Astra’s strongest capabilities will be restricted

OpenAI says Astra will use stronger safeguards at the model layer and additional controls around access and deployment. The company’s prior security disclosures describe tighter requirements for tool-enabled inference, monitoring, and infrastructure isolation when models approach cyber-critical capability.

The practical split is important: “available soon” does not mean unrestricted access to every capability. Trusted testers may face identity, account-security, monitoring, approved-use, and legal-attestation requirements. OpenAI has not yet published the complete eligibility list or a general release date.

What security teams should verify

Teams evaluating Astra should wait for the final API or product documentation before planning around it. Check whether access is limited to approved organizations, which tools and network paths are enabled, how prompts and logs are retained, whether elevated actions require review, and whether the model is available in the regions and plans you use.

The near-term signal is broader than one model. Once a frontier system reaches a provider’s cyber-critical threshold, model selection alone is no longer enough for risk assessment. The surrounding identity, execution, monitoring, and approval boundaries become part of the product’s effective security profile.

OpenAI’s Astra announcement is the primary record. WIRED’s independent report adds context on the planned restricted rollout and the capability threshold. Neither source establishes a public launch date or universal access.

Sources and methodology

This article uses OpenAI’s September 1 announcement and News RSS entry as the primary source, with WIRED as independent corroboration. The wording preserves OpenAI’s distinction between a forthcoming release and restricted access to advanced cybersecurity capabilities.

From reading to doing

Try the related loot

Use Cloudflare Optional OAuth Scopes for narrower app permissions

Open loot