OpenAI's Astra is the first model to hit the Critical cybersecurity capability threshold defined in the company's Preparedness Framework. That designation is not a marketing label. It means the model demonstrably crosses a line OpenAI itself set as requiring heightened intervention before deployment.
The Preparedness Framework exists to classify models by risk tier: Low, Medium, High, and Critical. Reaching Critical in any domain, including cybersecurity, biologics, or CBRN, is supposed to trigger mandatory safeguards before release. The blog details exactly what those safeguards look like in practice for Astra, which is the part worth reading in full. The gap between a framework existing on paper and a framework actually shaping a release decision is where most of the interesting technical and governance detail lives.
What comes next is the real question. OpenAI has now published a concrete case of a Critical-tier model reaching deployment. The precedent matters. Future models will be measured against this handling, and critics will have a documented baseline to challenge. Read the original for the specifics on which cybersecurity capabilities triggered the threshold and what the safeguard architecture actually required.
[READ ORIGINAL →]