OpenAI pauses development of Astra: the model approaches a "critical" threshold of cyber capabilities

OpenAI has officially announced a temporary suspension of some work on its flagship model, Astra. The reason is not technical failures or a lack of resources, but an alarming signal from its internal risk assessment system, the Preparedness Framework. According to my analysis, this is the first public case where the company openly admits that its own development may cross the line beyond which AI becomes a tool for autonomous cyberattacks.
Preliminary tests have demonstrated notable progress in agentic programming and solving cybersecurity tasks. This is not about a simple improvement in code, but about the model's ability to independently find and exploit zero-day vulnerabilities in real, protected systems. In my estimation, this is a qualitative leap: Astra can already construct and carry out attacks with only a general statement of the goal, without human involvement in the intermediate stages.
The internal "critical" level threshold that the company established in the Preparedness Framework implies exactly this scenario. If the model reaches this level, its potential becomes comparable to the actions of an experienced team of pentesters, but with inhuman speed and scale. For the industry, this is a double signal: on one hand, we see an acceleration in AI development; on the other, a real threat that regulators have not yet had time to fully comprehend.
The suspension of work is not an abandonment of the project, but a pause to review security protocols. However, in my view, the very fact of such an admission indicates that the arms race in the AI field has reached a new level. Developers are forced to balance between innovation and risks that are becoming increasingly concrete and measurable.
My expert conclusion: the market underestimates the speed at which AI is approaching autonomous cyber capabilities. Investors and regulators should prepare for the "critical threshold" to be crossed within the next 12–18 months, which will require a revision of not only technical but also legal security standards.