
AI cybersecurity just hit a symbolic milestone. On August 7, 2026, OpenAI announced that its upcoming model, named Astra, may have reached a "critical" level of offensive cybersecurity capability, as defined by its own internal safety framework. For the first time, a leading AI lab is publicly acknowledging it cannot rule out that one of its models could design and carry out cyberattacks against protected systems on its own. For a business owner, the question is no longer whether AI will change the cybersecurity landscape, but how fast to prepare for it.
In brief
- On August 7, 2026, OpenAI announced that its upcoming Astra model may cross the "Critical" cybersecurity threshold of its Preparedness Framework, a safety framework published in 2023 (source: OpenAI, reported by TechCrunch and Axios).
- OpenAI stated: "our preliminary evaluations indicate strong enough performance that we cannot rule out Critical capability level at this time" (source: TechCrunch).
- The Critical threshold applies to a model that can independently find unknown ("zero-day") vulnerabilities in hardened systems, or design and execute a full cyberattack from a simple high-level goal, without human help.
- The previous model, GPT-5.6 Sol, only reached the "High" level, one step below: Astra therefore marks a fast, documented jump in capability (source: TechCrunch).
- OpenAI has paused some internal work on Astra, tightened its isolated testing environments, and is rolling out restricted access to its most advanced cybersecurity capabilities (the Daybreak program, GPT-5.6-Cyber) limited to verified users (source: Usine Digitale).
- For an SME, this is not an immediate alarm bell but a reminder: the basics of cyber defense (patching, authentication, backups) matter more than ever.
What does a "critical threshold" mean for an AI model's cybersecurity capability?
OpenAI evaluates each of its models before release against an internal document called the Preparedness Framework, first published in 2023. It rates a model's capabilities in sensitive domains (biology, cybersecurity, agentic autonomy) on a four-level scale: Low, Medium, High, Critical.
Definition
According to OpenAI, a model reaches the "Critical" cybersecurity level if, without human help, it can identify and develop functional "zero-day" exploits in hardened real-world systems, or design and execute an end-to-end novel cyberattack strategy against a protected target from a simple natural-language goal. A "zero-day" is a security flaw unknown to the software vendor, and therefore unpatched: it is the type of vulnerability attackers prize most.
Crossing this threshold does not mean Astra has already been used to attack a real system, nor that it will be released to the public in this state. It means that, internally, OpenAI's own safety tests can no longer rule out this scenario with certainty, which automatically triggers the stronger safeguards defined in the framework.
Astra: from a math breakthrough to a cyber alert, in days
The timeline of the announcement shows how fast model capabilities are moving, and how quickly labs are now expected to react.
2023
Preparedness Framework published
Late July 2026
Astra impresses in mathematics
August 7, 2026
Critical cybersecurity alert
August 2026
Restricted access and dedicated models
How OpenAI is managing this risk
According to reporting from TechCrunch, PCWorld and Usine Digitale, OpenAI has put several concrete safeguards in place around Astra while evaluations continue.
Isolated testing environments
Restricted tool access
Pause on sensitive internal use
External collaboration
Verified, staged access
Key takeaway
This public announcement, about a model that has not even shipped yet, is a fairly reassuring signal: OpenAI is choosing transparency and voluntarily slowing down, rather than releasing a risky model without controls. It illustrates the kind of measured optimism worth having about AI: capabilities are advancing fast, but so are the safeguards, at least at labs that play the disclosure game.
What this means for SME cybersecurity
No SME has a reason to panic today: Astra is not public, and its "Critical" classification is not yet definitively confirmed by OpenAI. But the underlying trend is already actionable.
| Level (Preparedness Framework) | What the model can do | Known example |
|---|---|---|
| Low / Medium | Assists an experienced human, without full autonomy | Common consumer-grade models |
| High | Strongly accelerates an attack, still needs human supervision | GPT-5.6 Sol (OpenAI's previous model) |
| Critical | Can design and run a full attack end-to-end, without human help | Astra: level not ruled out since August 7, 2026 |
In practice, this means the skill barrier needed to run a sophisticated cyberattack keeps dropping, year after year. An SME is not the priority target for a bespoke "zero-day" attack, which stays costly to produce even with AI. It remains, however, an easy target for whatever trickles downstream: more convincing phishing, automated intrusion scripts, and scanning for known flaws on unpatched software.
That last figure is not a coincidence: models deemed to carry "systemic risk" under the EU AI Act are already subject to adversarial testing and serious-incident reporting obligations, a logic that overlaps with the Preparedness Framework. For more on these regulatory obligations, LUWAI covered what changed with the AI Act on August 2, 2026.
What to do right now
For an SME, the best response to this news is not cutting-edge technology: it is the often-neglected fundamentals, worth checking before the end of 2026.
- Systematically update software exposed to the internet (video conferencing, email, VPN, websites), prioritizing anything with a recent security patch.
- Roll out two-factor authentication across admin accounts, email, and any AI tool connected to company data.
- Review the permissions of internal AI agents: an agent with access to code, email or payment systems should be limited to the strict minimum it needs.
- Test backups, not just schedule them: a backup that cannot be restored offers no protection after a successful attack.
- Ask AI vendors (chatbots, agents, automation tools) how they handle this type of risk evaluation and what contractual guarantees exist in case of an incident.
These habits echo the ones already recommended for securing AI agent connectors in a business: continuous updates, least privilege, and access monitoring.
FAQ
What is OpenAI's Preparedness Framework?
It is an internal framework, published by OpenAI in 2023, that evaluates the potentially dangerous capabilities of its models before release, in domains such as cybersecurity, biology, and AI agent autonomy. It rates each model on a four-level scale (Low, Medium, High, Critical) and automatically triggers protective measures beyond a given threshold.
Is Astra already available to the public?
No. Astra is still under development and was not public as of August 17, 2026. OpenAI has explicitly slowed some internal work on it while it confirms the model's exact risk level and puts additional safeguards in place.
What is a "zero-day" exploit?
It is the exploitation of a security flaw that is still unknown to the software vendor concerned, and therefore unpatched. This type of flaw is especially prized by attackers because no standard protection anticipates it, unlike already-known and patched vulnerabilities.
Is an SME a likely target for AI-driven cyberattacks?
A bespoke attack, still costly to produce even with AI, primarily targets large organizations or critical infrastructure. An SME remains exposed, however, to the democratization of simpler techniques (better-crafted phishing, automated scanning for known flaws), which makes basic best practices all the more important.
Conclusion
OpenAI's announcement about Astra marks a milestone: it is the first time a leading lab has publicly acknowledged it cannot rule out one of its models reaching a critical level of offensive cybersecurity capability. The lab's response, transparency, voluntary slowdown, and restricted access, is reasonably reassuring about how the risk is being managed at this stage. For an SME, the right move is not to panic but to use this signal as a prompt to check cybersecurity fundamentals, which are often more useful day to day than a defense against a still-hypothetical threat. To build a full roadmap, explore our AI resources for business leaders.


