Recent internal evaluations of an OpenAI model called Astra indicate that it offers “significant advancements in agentic coding and cybersecurity,” according to the company. “These results, in addition to expert assessments, have led us to conclude last night that we cannot rule out critical cyber capabilities under our Preparedness Framework.”
Here is how OpenAI defines a “critical” cybersecurity threshold:
Under our Preparedness Framework, a model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal.
Astra was “not involved” in the Hugging Face breach, OpenAI says.
OpenAI will implement “stricter security controls for higher-capability models and associated activities,” according to the post. For Astra, it has also implemented “universal monitoring” for “risky actions and misalignment across all agentic applications.”
