The company is strengthening security measures around its upcoming AI model after tests highlighted potentially powerful cybersecurity capabilities
San Francisco, California, 11 August 2026 – OpenAI has slowed some internal work on its upcoming Astra artificial intelligence model after testing raised concerns about its growing cybersecurity capabilities. The company said it could not rule out Astra reaching the Critical threshold under its Preparedness Framework, which applies to AI systems that could create serious cybersecurity risks.
Astra is still under development and has not been released publicly. During internal testing, the model showed progress in agentic coding and cybersecurity, allowing it to handle complex technical tasks with less human guidance. In response, OpenAI is strengthening security controls around its development and testing environments.
The concern is not that Astra has carried out a cyberattack. Instead, its ability to understand computer systems, write code, identify weaknesses, and perform technical tasks has become advanced enough for OpenAI to take additional precautions.
The company has introduced tighter controls on network and tool access, stronger protection for model files, isolated testing environments, and increased monitoring. These measures are intended to identify risky behavior and protect the technology while development continues.
The situation highlights the growing importance of AI cybersecurity. As AI systems become more capable of using tools and completing tasks independently, they can support security teams by analyzing threats and identifying vulnerabilities. However, the same capabilities could potentially be misused by malicious actors.
For businesses adopting AI agents, the development also highlights the need for strong security practices. Limiting system access, protecting sensitive data, monitoring AI activity, and maintaining human oversight will become increasingly important as AI moves from providing information to taking actions.
OpenAI plans to continue evaluating Astra while improving its safeguards and working with external safety and security organizations. The company’s approach reflects a broader shift in the AI industry toward testing powerful models during development and strengthening protections as new capabilities emerge.
Astra’s development shows that the future of advanced AI will depend not only on how capable these systems become, but also on how safely those capabilities can be managed. As AI becomes more involved in cybersecurity and software development, balancing innovation with security will remain a major priority.

