Current outcome
On September 1, OpenAI announced that its unreleased Astra model meets the "Critical" cybersecurity threshold under its Preparedness Framework, the first model to receive that designation. Astra scored a perfect 100% on ExploitBench and autonomously discovered and chained two previously unknown zero-days in Google's V8 JavaScript engine. This is a frontier-lab milestone in AI safety and capability, showing that models can autonomously execute full compromise chains against hardened real-world systems. It will likely shape access restrictions, defensive AI programs, and industry-wide discussions about catastrophic cyber risk. OpenAI says Astra tops GPT-5.6 Sol, which maxed out at the lower "High" tier, and Astra refused 91.5% of cyber jailbreak attempts in internal tests versus 59% for GPT-5.6 Sol. Access starts with a small alpha test group and will later expand through the Daybreak Blue defensive security program; a public launch date has not been set.
Progress timeline
1 material updates- #01
OpenAI's Astra Becomes First AI Model with 'Critical' Hacking Abilities
On September 1, OpenAI announced that its unreleased Astra model meets the "Critical" cybersecurity threshold under its Preparedness Framework, the first model to receive that designation. Astra scored a perfect 100% on ExploitBench and autonomously discovered and chained two previously unknown zero-days in Google's V8 JavaScript engine. This is a frontier-lab milestone in AI safety and capability, showing that models can autonomously execute full compromise chains against hardened real-world systems. It will likely shape access restrictions, defensive AI programs, and industry-wide discussions about catastrophic cyber risk. OpenAI says Astra tops GPT-5.6 Sol, which maxed out at the lower "High" tier, and Astra refused 91.5% of cyber jailbreak attempts in internal tests versus 59% for GPT-5.6 Sol. Access starts with a small alpha test group and will later expand through the Daybreak Blue defensive security program; a public launch date has not been set.
Source evidence: Decrypt