What 'Critical' Actually Means
OpenAI's Preparedness Framework sorts model risk into tiers, and until now no OpenAI model had ever tripped the top one for cybersecurity [1]. Internal evaluations of Astra, the company's next-generation model, found capability advances significant enough that OpenAI 'cannot rule out critical cyber capabilities' [2]. Under the framework, 'Critical' means a model that can independently identify and build functional zero-day exploits across many hardened real-world systems, or take a single high-level goal and execute an entire novel cyberattack strategy against a hardened target without a human directing any step [2][3]. That is a different order of capability than 'High,' the tier Astra's predecessor GPT-5.6 Sol reached, making this the first time OpenAI has flagged a model at the ceiling of its own risk scale [4]. The jump is tied to rapid gains in agentic coding and reasoning through test-time compute, the same underlying capability that reportedly let Astra work through ten open math problems for roughly $2,000 in API costs [4].


