OpenAI hit the brakes on certain internal activities related to its Astra model on August 7, 2026, after preliminary findings suggested the AI had reached what the company classifies as “critical” cybersecurity capabilities. But CEO Sam Altman wants to be clear: Astra’s core training never stopped, and new models are still on track to ship soon.
What triggered the pause
The concern centers on Astra’s cybersecurity capabilities, which reportedly reached or approached the “critical” tier in OpenAI’s Preparedness Framework. That’s the highest classification the company uses to evaluate model risks.
In practical terms, the model demonstrated sophisticated agentic coding skills and the potential to identify or exploit zero-day vulnerabilities. Zero-day vulnerabilities are security flaws that software vendors don’t yet know about, making them extraordinarily valuable to both defenders and attackers.
The pause lasted a little more than two weeks as OpenAI implemented new security measures around those specific capabilities. During that window, the company assessed the risks and put guardrails in place before resuming the affected activities.
Astra’s broader capabilities
The cybersecurity angle is only one dimension of what appears to be an exceptionally powerful model. An earlier version of Astra reportedly solved 10 major open problems in mathematics and theoretical computer science, a claim that, if verified independently, would represent a landmark achievement in AI research.
Altman has stated that Astra is intended to be made “generally available,” meaning it won’t be locked behind restricted research access indefinitely. But he acknowledged it requires more time to ensure the model is safely developed, with a particular focus on addressing its cyber capabilities before a broader rollout.
The safety-speed balancing act
OpenAI’s Preparedness Framework was designed precisely for moments like this. The framework establishes risk tiers, from “low” to “critical,” across categories including cybersecurity, persuasion, autonomy, and biological threats. When a model hits the critical tier in any category, it triggers additional review and mitigation steps before deployment can proceed.
What to watch from here
The near-term question is when Astra, or models derived from it, actually ships to users. Altman’s statement that new models are expected soon suggests the timeline hasn’t shifted dramatically despite the pause.
The other thing worth tracking is whether OpenAI publishes detailed findings from its safety evaluation. A model that hits the critical tier in cybersecurity risk would seem to warrant a thorough public accounting of what was found and what mitigations were put in place.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
15









English (US) ·