{"id":134897,"date":"2026-08-10T12:20:15","date_gmt":"2026-08-10T12:20:15","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/134897\/"},"modified":"2026-08-10T12:20:15","modified_gmt":"2026-08-10T12:20:15","slug":"openai-pauses-astra-model-over-critical-cybersecurity-risk-concerns","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/134897\/","title":{"rendered":"OpenAI Pauses Astra Model Over Critical Cybersecurity Risk Concerns"},"content":{"rendered":"<p>\n\t\t\t\t\t\t\tOpenAI Pauses Astra Model Over Critical Cybersecurity Risk Concerns\n\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/user-icon.svg\" alt=\"\"\/> <a href=\"https:\/\/securityaffairs.com\/author\/paganinip\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi Paganini<\/a><br \/>\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> August 10, 2026<\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/openai.png\" alt=\"\"\/><\/p>\n<p>OpenAI paused work involving Astra after tests showed cybersecurity abilities that could approach its Critical risk threshold under the company\u2019s framework.<\/p>\n<p class=\"wp-block-paragraph\">OpenAI disclosed that internal evaluations of Astra, one of its upcoming models, have found cybersecurity capabilities significant enough that the company \u201ccannot rule out\u201d reaching the Critical threshold under its own Preparedness Framework. <\/p>\n<p class=\"wp-block-paragraph\">In response, the company paused certain internal activities involving Astra and implemented a set of security controls that it had not previously needed to apply. This is the first time an AI lab has publicly announced slowing development of a model specifically because of cybersecurity concerns.<\/p>\n<p class=\"wp-block-paragraph\">\u201cUnder our Preparedness Framework, a model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal.\u201d reads the <a href=\"https:\/\/openai.com\/index\/responding-next-frontier-critical-cyber-capabilities\/\" rel=\"nofollow noopener\" target=\"_blank\">announcement<\/a>. <\/p>\n<p class=\"wp-block-paragraph\">\u201cWhile we continue to benchmark and assess this model, our preliminary evaluations indicate strong enough performance that we cannot rule out Critical capability level at this time. Astra is an upcoming model, and was not involved in exploiting <a href=\"https:\/\/securityaffairs.com\/tag\/hugging-face\" data-type=\"post_tag\" data-id=\"17126\" rel=\"nofollow noopener\" target=\"_blank\">Hugging Face<\/a>.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Previous models, including <a href=\"https:\/\/securityaffairs.com\/tag\/gpt-5-6-sol-2\" data-type=\"post_tag\" data-id=\"17196\" rel=\"nofollow noopener\" target=\"_blank\">GPT-5.6-Sol<\/a>, had been assessed at the High threshold rather than Critical. Astra wasn\u2019t involved in the <a href=\"https:\/\/securityaffairs.com\/196209\/ai\/openais-rogue-ai-agent-breached-second-company-report-says.html\" data-type=\"post\" data-id=\"196209\" rel=\"nofollow noopener\" target=\"_blank\">Hugging Face incident<\/a> disclosed last month. OpenAI is making that distinction deliberately, because the news cycle has already connected every AI breach to every AI model.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe are pausing internal activities involving Astra that do not yet meet these strengthened security control requirements.\u201d continues the announcement. \u201cWe have implemented universal monitoring\u00a0for risky actions and misalignment\u00a0across all agentic applications of Astra, including training and evaluation. Monitors evaluate the model\u2019s Chain of Thought and trigger a security response to review and interrupt high risk activity.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The new controls also include isolated testing environments, restricted network and tool access, enhanced encryption of model weights, and sandboxed execution. OpenAI says it will share recommended security controls with third-party testing partners for running higher-risk evaluations, a direct response to the series of incidents in which evaluation environments gave AI models unintended internet access.<\/p>\n<p class=\"wp-block-paragraph\">The broader context makes this disclosure land harder than it might otherwise. The UK AI Security Institute <a href=\"https:\/\/securityaffairs.com\/196695\/ai\/ai-deception-emerges-in-cyber-tests-as-agents-target-real-people-and-systems.html\" rel=\"nofollow noopener\" target=\"_blank\">reported<\/a> last week that AI models autonomously reached out to real-world targets across 10 of 122 evaluation runs, with 17 of 19 such actions originating from <a href=\"https:\/\/securityaffairs.com\/tag\/mythos-5\" data-type=\"post_tag\" data-id=\"17195\" rel=\"nofollow noopener\" target=\"_blank\">Anthropic\u2019s Mythos 5<\/a>. In the most serious case, an agent tried to insert malicious code into an open-source project and created fake online identities to pressure the project\u2019s maintainer into approving it. A human maintainer caught it. Models from <a href=\"https:\/\/securityaffairs.com\/196731\/security\/meta-ai-model-hacked-a-company-during-testing-marking-third-ai-lab-incident.html\" data-type=\"post\" data-id=\"196731\" rel=\"nofollow noopener\" target=\"_blank\">Meta<\/a> and Chinese company Moonshot, Muse Spark 1.1 and <a href=\"https:\/\/securityaffairs.com\/196923\/ai\/a-github-misconfiguration-let-kimi-k3-cheat-a-cybersecurity-benchmark.html\" data-type=\"post\" data-id=\"196923\" rel=\"nofollow noopener\" target=\"_blank\">Kimi K3<\/a>, have also been reported escaping sandboxes, with Kimi K3 probing the network during an evaluation, finding that GitHub was reachable, cloning the benchmark repository it was supposed to be solving, and reading the answer directly off disk. The incidents are being tracked on a new site called Felony Bench.<\/p>\n<p class=\"wp-block-paragraph\">OpenAI says it believes advanced cyber-capable models should help defenders find vulnerabilities before attackers do, and frames the pause as responsible stewardship rather than alarm. That may be true. It\u2019s also true that the Preparedness Framework was designed for exactly this moment, and that using it to actually slow down a model rather than just document the risk is a meaningful choice, one the industry will be watching to see whether others follow.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe\u2019re committed to working alongside governments, safety institutes, and civil society to ensure that the frontier capabilities of models like Astra, and those that follow, are deployed responsibly and broadly for the benefit of all humanity.\u201d concludes the announcement.<\/p>\n<p class=\"wp-block-paragraph\">Follow me on Twitter:\u00a0<a href=\"https:\/\/twitter.com\/securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">@securityaffairs<\/a>\u00a0and\u00a0<a href=\"https:\/\/www.facebook.com\/sec.affairs\" rel=\"nofollow noopener\" target=\"_blank\">Facebook<\/a>\u00a0and\u00a0<a href=\"https:\/\/infosec.exchange\/@securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">Mastodon<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"http:\/\/www.linkedin.com\/pub\/pierluigi-paganini\/b\/742\/559\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi\u00a0Paganini<\/a><\/p>\n<p class=\"wp-block-paragraph\">(<a href=\"http:\/\/securityaffairs.co\/wordpress\/\" rel=\"nofollow noopener\" target=\"_blank\">SecurityAffairs<\/a>\u00a0\u2013\u00a0hacking,\u00a0Astra)<\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"OpenAI Pauses Astra Model Over Critical Cybersecurity Risk Concerns Pierluigi Paganini August 10, 2026 OpenAI paused work involving&hellip;\n","protected":false},"author":2,"featured_media":40932,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[24,25,10769,315,8066,7512,8067,157,8068,8069,8070],"class_list":["post-134897","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-ai","tag-artificial-intelligence","tag-astra","tag-hacking","tag-hacking-news","tag-information-security-news","tag-it-information-security","tag-openai","tag-pierluigi-paganini","tag-security-affairs","tag-security-news"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/134897","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=134897"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/134897\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/40932"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=134897"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=134897"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=134897"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}