A landmark event has occurred in the artificial intelligence industry: OpenAI has for the first time assigned its future model Astra the highest level of cybersecurity — Critical. This decision, made on September 1 under the internal Preparedness Framework, signals that we are entering a new era where AI is becoming not just a tool, but an independent actor in cyber warfare.

It is important to emphasize: this is not about the standard version of the model, but about a configuration with extended access, known as Daybreak Blue. It is in this modification that Astra demonstrated capabilities previously considered theoretical. My expertise suggests that such a step is both an acknowledgment of the technology's power and an attempt to build a system of checks and balances in advance.

Key Test Results

According to the Preparedness Framework criteria, the Critical level is assigned to systems capable of autonomously detecting and exploiting zero-day vulnerabilities in real protected systems. And Astra confirmed this status in practice. On the public ExploitBench benchmark, it achieved a 100% result, which is impressive in itself.

However, the internal tests proved most telling. OpenAI created an isolated version of ExploitBench with 20 fresh high-severity vulnerabilities in the V8 engine to avoid contaminating training data. Astra not only found but also successfully exploited two previously unknown zero-day vulnerabilities as part of a complex attack chain. Moreover, in expert scenarios, the model demonstrated the ability to escape the sandbox of a protected browser and execute commands on the host system, as well as escalate privileges to root in a protected OS.

Limitations and Security Strategy

Aware of the colossal risk, OpenAI has taken unprecedented precautions. At the initial stage, only a limited group of testers will gain access to Astra's advanced cyber capabilities. The model was additionally trained to refuse prohibited cyber assistance: in tests attempting to bypass restrictions, it rejected 91.5% of malicious requests, significantly higher than the 59% rate of the previous GPT-5.6 Sol version.

The company is also implementing automated monitoring systems to detect and stop unauthorized model actions in real time. This resembles an arms race where offensive capabilities must constantly be balanced by defensive measures.

My analysis: OpenAI's decision is a dual precedent. On one hand, it is a demonstration of technological leadership; on the other, an acknowledgment that AI has already reached a level where its cyber capabilities require restrictions at the level of national security. The question is not whether AI can carry out attacks, but who will control this potential and how. The market must realize: investments in AI are now inextricably linked to investments in cybersecurity.