OpenAI says its upcoming Astra model can find and exploit previously unknown security flaws without human guidance. The company has classified Astra as its first model to meet its “Critical” cybersecurity threshold and plans a limited release soon.

Cybersecurity shield graphic representing safeguards around OpenAI Astra

What is OpenAI Astra?

Astra is an unreleased OpenAI model designed for demanding tasks, including cybersecurity work. In its official Astra announcement, OpenAI says the model can identify unknown vulnerabilities and develop working exploit chains across hardened systems when given the necessary tools and access.

The company says Astra achieved a perfect score on ExploitBench, a benchmark for developing exploits from known vulnerabilities. In an internal test containing 20 high-severity vulnerabilities disclosed more recently, OpenAI says Astra found and used two zero-day vulnerabilities as part of an exploit chain. Those claims come from OpenAI’s own testing and have not been independently confirmed.

Why OpenAI is limiting Astra’s release

OpenAI says Astra will initially be available to a small group of alpha testers, with advanced cybersecurity access limited further. Access through Daybreak Blue will follow, with a focus on defensive cybersecurity work.

The release follows an earlier period in which OpenAI slowed some frontier training and held back parts of Astra’s development while it hardened research environments. The company describes stronger sandboxing, network isolation, expanded monitoring and additional alignment training in its account of the cyber-capability safeguards.

OpenAI says Astra will also use chain-of-thought monitoring to detect potentially unauthorised actions. Its tests found that Astra refused 91.5% of disallowed cyber requests, compared with 59% for GPT-5.6 Sol, although the company says these results reflect its own evaluation setup.

What Astra means for cybersecurity teams

OpenAI has not announced a public release date, UAE pricing or a general API availability date for Astra. The first users are expected to be selected testers, and the most capable cybersecurity functions will not be broadly available at launch.

The model could help defenders find vulnerabilities faster, but the same capabilities make access controls and monitoring part of the product rather than an optional extra. OpenAI says legitimate defensive work may sometimes be slowed, paused or stopped when its systems detect possible misuse or unauthorised activity.

For UAE organisations, Astra’s immediate availability is unconfirmed. Security teams should treat OpenAI’s performance figures as company-reported until the system card, external evaluations or a wider release provides more evidence. tbreak previously covered OpenAI’s pause after the Hugging Face incident, which is part of the background to the new safeguards. UAE teams can also read our UAE Cybersecurity Council guidance on AI tools.

The model’s release will put OpenAI’s safeguards alongside its claims about capability. TechCrunch reports that independent confirmation is still absent. Both will need testing outside the company’s own lab.

NEWSLETTERS

Subscribe to our Newsletters

Two newsletters. Zero noise. Pick what lands in your inbox.

Unsubscribe anytime. We don’t share your email.

What is OpenAI Astra?

Astra is an upcoming OpenAI model that the company says can identify unknown vulnerabilities and develop exploit chains with the necessary tools and access.

When will OpenAI Astra be released?

OpenAI says Astra will be available soon, beginning with a small group of alpha testers. It has not announced a public release date.

Will OpenAI Astra be available in the UAE?

OpenAI has not announced UAE pricing, local availability or a general API release date for Astra.