OpenAI said on Sept. 1, 2026, that Astra meets the Critical cybersecurity capability threshold under its Preparedness Framework, calling it the first model the company designates at that level. TechCrunch reported the Path to Astra post the same day.
Under OpenAI's framework language, Critical means the model can identify and develop functional zero-day exploits of all severity levels in many hardened real-world systems without human intervention, or devise and execute end-to-end novel strategies against hardened targets from a high-level goal. OpenAI says Astra is a significant jump versus GPT-5.6 Sol on vulnerability identification and exploit development.
Company tables put Astra at 100% on ExploitBench for developing exploits from known vulnerabilities. On an internal June to August 2026 ExploitBench port of 20 high-severity V8 bugs, OpenAI says Astra used two zero-day vulnerabilities in an exploit chain and is disclosing them to maintainers. The post states those Astra results reflect Daybreak Blue access, not the default production configuration.
OpenAI says it delayed parts of Astra's development and release while it strengthened cyber-misuse and unauthorized-action protections, including a two-week pause on certain frontier training after the Hugging Face incident and a large frontier reinforcement-learning restart on Aug. 28, 2026. On its cyber jailbreak evaluations, OpenAI reports Astra refuses 91.5% of requests versus 59% for GPT-5.6 Sol, and it plans additional chain-of-thought monitoring in production.
Path to Astra said advanced cybersecurity workflows would start with a small tester group, then expand through Daybreak Blue for defensive use. Independent follow-ups tracked the next step: CSO Online reported on Sept. 4 that GPT-6 Astra had begun rolling out with Critical-threshold disclosure and Daybreak plans for vetted defenders, and SC Media argued on Sept. 15 that the access limits are a warning shot for security teams.
What remains open is how far default production safeguards differ from Daybreak Blue results, how third parties will reproduce ExploitBench and zero-day claims, and how quickly Daybreak access expands beyond early testers. OpenAI's Critical designation and safeguard tables should be weighed separately from outside coverage until those points are settled.