OpenAI said internal evaluations of its upcoming Astra model showed such strong agentic coding and cybersecurity skills that it can no longer rule out 'critical' cyber capability under its Preparedness Framework — a first for the company. Under that definition, a model could find working zero-day exploits in hardened real-world systems or run end-to-end attacks from a high-level goal without human help. In response, OpenAI is pausing internal uses of Astra that lack safeguards, moving it to isolated environments with restricted network access, encrypting its weights, and bringing in government agencies and safety organizations for further testing.