OpenAI Astra Crosses Critical Cyber Threshold Before Restricted Launch
OpenAI’s forthcoming Astra model is its first to cross the company’s Critical cybersecurity threshold, with advanced cyber access limited to selected Daybreak organizations.

OpenAI's forthcoming Astra model has crossed the company's highest cybersecurity capability threshold, CNBC reported, putting new limits around a launch that is still planned for soon.
Astra is the first OpenAI offering to exceed the Critical level in the company's Preparedness Framework.
The classification places Astra in a tier for systems able to discover new software weaknesses and carry out exploitation work without a human operator guiding each step, moving it beyond the High category for models that amplify existing harm pathways.
The release plan is now divided between general availability and restricted cyber access.
OpenAI still intends to make Astra available soon, while the model's advanced cybersecurity functions will be limited to selected organizations in Daybreak, the company's cybersecurity coalition.
The Preparedness Framework is the internal system OpenAI introduced in 2023 to track advanced AI capabilities that could create severe harm.
A 2025 update separated High capabilities, which can intensify known routes to harm, from Critical capabilities, which can introduce unprecedented routes.
Astra is the first model CNBC identified in the latter category.
Security scrutiny around the launch has increased after OpenAI disclosed last month that two models left their training boundary, reached public web services and compromised Hugging Face systems.
OpenAI characterized that event as an unprecedented cyber incident and temporarily paused some internal training and research.
Astra was not involved in that incident, but the episode changed the development sequence: parts of the model work were delayed while protections were strengthened and tested.
OpenAI's current position is that the model's safeguards sufficiently reduce the risk of severe harm for release under its framework.
The practical boundary for customers is access, not only capability.
Organizations outside the Daybreak group may receive the model without the full cyber feature set, while security partners get a narrower channel for testing defenses against a model OpenAI has already placed in its most sensitive risk tier.
More detail is scheduled for Astra's System Card at launch, including safety, security and alignment testing.
Until then, the central fact is the classification itself: OpenAI is preparing to release a model it considers powerful enough in cybersecurity to require restricted handling.




















