OpenAI delays Astra launch after cybersecurity risks found
OpenAI paused Astraโs launch after tests showed it could autonomously find unknown cybersecurity flaws, classifying it as the first model to reach its highest risk tier. The delay highlights urgent sโฆ
OpenAI has paused the planned launch of its next-generation AI model, Astra, saying it needs stronger safety measures after tests showed the system could autonomously find and exploit previously unknown cybersecurity flaws. The company revealed the move in a Tuesday blog post, calling Astra its first model to reach the โcritical cybersecurity capabilityโ threshold. That means it can probe complex IT systems for unpatched vulnerabilities without human prompting, a power OpenAI now says is too risky to release in its current form.
This is the first time OpenAI has openly flagged a model as reaching the highest risk tier under its own internal safety framework. The company began grading models by potential danger in late 2023 after outside researchers warned that frontier AI could soon automate both defensive and offensive cyber operations. Earlier this year, Microsoft and Google cut back on some AI-driven security tools after discovering they could be misused to help hackers. Astraโs ability to discover zero-day flaws โ flaws that vendors donโt yet know about โ raises the stakes because it could be repurposed by criminals or state actors before patches exist.
OpenAI did not say when Astra might ship or what exact safeguards it is adding. The company said it is working with cybersecurity firms and governments to set red-team tests that measure how easily the model could be weaponized. So far, Astra has been tested only in controlled lab environments, but the results have alarmed some OpenAI staff who pushed for a delay. Reuters reported that at least two researchers resigned in the past month over concerns the company was moving too fast on safety.
The delay buys time for policymakers who are racing to regulate AI tools that interact with critical infrastructure. The EUโs AI Act, due to take full effect next year, will require high-risk AI systems to undergo stringent pre-market checks, including penetration testing similar to what Astra failed. If OpenAI cannot satisfy regulators, Astra could be blocked from key markets or forced into a slower, more expensive certification process. That would give competitors like Anthropic and Mistral a chance to refine their own models first โ and could shift the balance of power in the emerging AI security sector.
Read Full Story at The Hill โ


