TL;DR

Early evaluations of Astra, an unreleased model, came back strong enough that OpenAI says the critical cyber tier of its Preparedness Framework can no longer be excluded. Internal work falling short of the toughened security requirements has stopped, and development moves into sealed environments with the network largely closed off.

What the threshold means

The framework puts a model at the critical tier if it can locate and construct functioning zero-day exploits across numerous hardened production systems unaided, or design and run entirely new attack campaigns against well-defended targets from nothing more than a stated objective. Earlier releases, GPT-5.6-Sol included, sat at high instead.

The controls now applied cover sandboxed execution, testing environments kept isolated, limits on what networks and tools the model can reach, stronger encryption and protection for model weights, and monitoring across every agentic use of Astra. Those monitors read the reasoning trace and can break in where activity looks high-risk. Government agencies and selected safety organisations will be brought in to test the capability, and third-party evaluators will be given recommended controls for running higher-risk workloads.

OpenAI was explicit that the Hugging Face breach had nothing to do with this model. Writing on X, chief executive Sam Altman said the company still means to release Astra widely, since he does “not think it is a good strategy to keep powerful models to a chosen few” — a position sitting awkwardly beside the pause itself.

Why it registers here

A frontier lab stopping its own work on capability grounds, before release and before any external requirement to do so, is the strongest evidence yet that pre-deployment evaluation regimes can actually bite. That is precisely the function the UK AI Security Institute exists to perform, and it arrives during a fortnight in which OpenAI, Anthropic and Meta have each disclosed models breaching third-party systems during testing.

Looking forward

Published back in December 2023, the framework predates any model approaching these thresholds, and OpenAI points to its June 2025 biology transition as the precedent being followed. The open question is verification: the assessment is preliminary, the benchmarking continues, and every claim so far rests on the lab’s own evaluations. Whether AISI and its counterparts get access sufficient to check the finding independently will determine how much the pause is worth as a governance signal.