IC Technology — 2026-08-09
NSA and CISA Engaged to Evaluate OpenAI Astra After First AI Model Hits Critical Autonomous Zero-Day Exploit Threshold
BLUFFormal validation of the Critical threshold remains unlikely within 90 days, but OpenAI's preemptive disclosure forces federal agencies into an evaluator role the voluntary framework never equipped them to fill.
OpenAI disclosed Friday that internal evaluations of its unreleased Astra model showed capability gains strong enough that it "cannot rule out" Astra reaching the Critical tier of its Preparedness Framework, defined as autonomously exploiting zero-day vulnerabilities in hardened systems without human input 12. No earlier OpenAI model, including GPT-5.6-Sol, has been assessed above the High tier 1. OpenAI said it paused internal Astra work that does not meet stricter security standards, shifting development into isolated, monitored environments with restricted network access and enhanced weight encryption 1. According to ByteIota, OpenAI engaged NSA, CISA, and the White House National Cyber Director for outside evaluation under June's AI executive order 3; Bloomberg and TechCrunch separately corroborated the pause and threshold characterization 24.
AnalysisFormal confirmation that Astra reached the Critical tier is
unlikely within the next 90 days, since OpenAI's language stops short of certification and no independent government assessment has concluded testing. The disclosure functions as a governance signal, pressuring NSA, CISA, and the White House National Cyber Director to validate or refute the threshold before any competitor model faces comparable scrutiny. Low confidence attaches to this judgment, reflecting reliance on OpenAI's self-reported preliminary evaluations without corroborating technical detail from the engaged agencies. Should evaluators validate the threshold, pressure builds for mandatory disclosure requirements that the current voluntary framework does not impose on other labs.
4 sources
- Responding to the next frontier of critical cyber capabilities - OpenAI
- OpenAI Pauses Astra AI Model Development to Strengthen Cybersecurity Safeguards - Bloomberg
- OpenAI Pauses Astra: First Critical Cyber Threshold Hit - ByteIota
- OpenAI says it slowed Astra model development over security concerns - TechCrunch
View in full brief →