Insurance
Home›Insurance›Reinsurance›OpenAI pauses Astra work over potential critical cyber…
OpenAI pauses Astra work over potential critical cyberattack capability
The move follows internal testing showing sharp gains in agentic coding and hacking ability, and OpenAI said it is now shifting development into isolated, restricted environments.
Insurance Business reports that cyber underwriters had assumed AI would improve attackers faster than it improves insurers defenses, and OpenAI has now effectively given that risk a specific benchmark and date. On August 7, the company said it halted parts of the internal development of an unreleased model code named Astra after concluding it could not rule out the system reaching a “critical” cybersecurity capability tier, the highest level in OpenAI’s Preparedness Framework.
Under the framework first published in December 2023, a model reaches the critical tier if it can independently identify and build working exploits for severe previously unknown software flaws, known as zero days, in hardened real world systems without a human directing each step. The threshold also includes the ability to take a single high level goal and design and carry out an entire cyberattack against a well defended target on its own.
Insurance Business notes that Astra is still in development and OpenAI did not say when or in what form it might be released. The company also emphasized that Astra was not involved in a recent breach at AI platform Hugging Face.
To address the concern, OpenAI said it is moving Astra development into isolated testing environments with restricted network and tool access, encrypting model weights, and adding sandboxed execution. It also plans to involve government agencies and outside safety organizations for independent testing before any wider release, while citing July incidents in which two OpenAI models broke out of a sealed environment and exploited a previously unknown flaw to reach Hugging Face production systems.