What happened
- On September 1, 2026, OpenAI reported that GPT-6 Astra is the company’s first model to cross the critical cybersecurity capability threshold of its Preparedness Framework.
- According to the company’s post, the model can find undocumented vulnerabilities and develop ways to exploit them against protected systems without continuous human direction.
- The phased rollout began on September 3. Offensive capabilities are limited to verified organizations within the Daybreak program; the rest of the model reaches the Plus, Pro, Business and Enterprise plans, as well as the API, Microsoft Azure and Amazon Web Services.
- The company announced stricter isolation, encrypted checkpoints, expanded monitoring and additional restrictions for accounts flagged as risky.
Why it matters
- The capability OpenAI restricts exists and is documented. Any team that maintains a website, a payment interface or an exposed database is now up against tools that discover flaws without supervision.
- For a Chilean small business with no security team, the practical change isn’t adopting the model: it’s assuming that the cost of leaving dependencies un-updated has gone up, and that the windows between patch and exploitation are getting shorter.
- The restriction depends on verifying who gets access. It’s an administrative control, not a technical one, and therefore only as solid as the process that decides who gets approved.
The number
It’s the first model OpenAI places in the critical category of its own preparedness framework.
Context
The company describes Astra as its most aligned model to date and reports that it respects task boundaries better than its predecessor. In the same technical documentation it acknowledges that monitoring the model’s intermediate reasoning has become substantially harder. Both statements coexist in the same document. The framework that sets the threshold was written, applied and communicated by the company itself, just as with the internal goal OpenAI declared met this week.
What’s next
- Broad access in regular chat remains more limited than in the work and coding tools, with no published date for full opening.
- Secondary reports mention a prior safety review by the U.S. government, with no official confirmation to date.
Bottom line
A year ago, the debate over frontier models was settled with benchmark scores. This time the headline was set by the company itself, in its risk category, not in its results table.
Sources
- OpenAI says Astra AI model crosses ‘Critical’ cyber capability — CNBC, September 1, 2026
- OpenAI begins rolling out Astra model after warning of its advanced cyber capabilities — CNBC, September 3, 2026
Edited by Rodrigo Cornejo. How we select and verify the facts: who writes these notes.


