The Critical cyber classification, and what's actually restricted
OpenAI's GPT-6 Astra, launched September 3-4, 2026, is the first model to reach the 'Critical' level of cybersecurity capability under the company's Preparedness Framework, able to find and exploit novel vulnerabilities in hardened targets without step-by-step human guidance [1]. Without production safeguards, the model scored 100% on ExploitBench, up from 78.5% for predecessor GPT-5.6 Sol, and 42.4% on ExploitGym versus 30.3% for Sol, and it discovered two previously unknown zero-day vulnerabilities during pre-release testing that OpenAI is now disclosing to the affected software makers [2]. OpenAI's response was to tier access rather than withhold the model: the publicly released Astra is restricted to secure code review and patching and refuses proof-of-concept exploit requests, while a less restricted version goes only to vetted defenders through the company's Daybreak program [2]. One security analyst argued the label itself is the real story - Astra is now the only frontier model whose cyber capability enterprises can verify against a published threshold, rather than simply a new danger in isolation [3].


