OpenAI says its upcoming Astra model has achieved a new level of autonomous cyber capability, becoming the company’s first AI system to be designated “Critical” for cybersecurity.
The model can reportedly identify previously undiscovered software weaknesses, including zero-day vulnerabilities, and develop functional exploits without a human overseeing each stage of the process.
OpenAI assigned Astra the “Critical” classification under its Preparedness Framework in a Tuesday announcement. The designation represents the highest cybersecurity capability level the company has publicly attributed to one of its models.
For a model to meet this threshold, OpenAI says it must be capable of discovering unknown vulnerabilities and developing exploits that work against hardened systems without human assistance. It can also qualify by independently translating a broad objective into a complete cyberattack.
Astra showed those capabilities in multiple evaluations. It achieved a perfect score on a test measuring its ability to build exploits from known vulnerabilities. In a separate internal assessment, it uncovered two previously unknown security flaws while constructing a chain that linked multiple exploits.
The model also escaped a hardened browser sandbox and successfully ran commands on the host computer, according to OpenAI. In another experiment, it identified several operating-system weaknesses and combined them to obtain root access.
OpenAI has slowed some aspects of Astra’s rollout while it works on additional safeguards. The company said its most advanced cybersecurity functions will initially be limited to a small number of approved testers.
The development is especially important for crypto security, where a single software vulnerability can potentially result in millions of dollars in losses in a very short period. AI systems with stronger autonomous capabilities could speed up tasks such as examining code, identifying configuration errors and linking separate vulnerabilities into attack sequences.
Security experts have argued that the major risk may not be AI inventing completely new forms of cyberattacks. Instead, the technology could dramatically accelerate the exploitation of weaknesses that hackers already know how to use.
Astra also reflects a wider shift among frontier AI systems, which are increasingly moving beyond basic chatbot functions and code generation. Recent advances in AI-assisted mathematics and other complex reasoning tasks indicate that these systems are becoming capable of handling increasingly sophisticated work with less human involvement.





