Skip to content
Menu
Menu

OpenAI Restricts Astra Development Over Advanced Cyberattack Risks

The company acted after tests indicated Astra may be approaching its highest category for dangerous cybersecurity capabilities.

 

OpenAI restricted development of its upcoming Astra model by pausing internal work that does not meet stronger security requirements.

The company announced the restrictions after several days of internal testing and expert reviews raised concerns about Astra’s cybersecurity capabilities. OpenAI has not confirmed that the model can perform the advanced attacks it is testing for.

Stronger controls now govern Astra work

OpenAI said Astra development must now take place under stricter controls.

Those controls include isolated testing environments, limits on the networks and software tools Astra can access, stronger protection and encryption for the model’s core files, additional monitoring, and systems that contain the model’s actions during testing.

OpenAI paused internal Astra activity that is not yet protected by the stricter security controls.

The company also added monitoring across Astra applications that can plan and carry out tasks with limited human direction. The monitors examine the model’s internal reasoning and can trigger a security review or interrupt activity considered high risk.

Tests raised concerns about advanced attacks

OpenAI’s highest cybersecurity risk category, called “Critical,” covers models that can independently find and exploit unknown software flaws in many well-protected real-world systems previously.

The category also includes models that can plan and carry out a new cyberattack against a protected target after receiving only a broad goal.

OpenAI said Astra performed strongly enough in preliminary tests that the company is treating this level of capability as a possibility while its evaluation continues. The tests did not establish that Astra can perform either type of attack.

Earlier OpenAI models, including GPT-5.6-Sol, were rated at the lower “High” level for cybersecurity capabilities.

Government agencies will help test Astra

OpenAI plans to work with government agencies and selected AI safety organizations to test Astra’s capabilities.

The company will also give outside testing partners recommended security controls for conducting higher-risk tests. OpenAI did not provide a timeline for completing the evaluation or resuming the paused activities.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!