OpenAI's GPT-6 Astra just crossed a cybersecurity line no model has crossed before — what it means for anyone commissioning software
OpenAI confirmed on 3 September 2026 that GPT-6 Astra is the first model to cross its internal 'critical' cybersecurity threshold — able to find and exploit previously unknown vulnerabilities across well-protected systems without step-by-step human guidance, including two real zero-days found during testing.
5 September 2026
OpenAI confirmed on 3 September 2026 that GPT-6 Astra is the first model to cross its own “critical” threshold on cybersecurity capability under its preparedness framework. In practice, that means Astra can find and exploit previously unknown vulnerabilities in well-protected systems without a person guiding each step — and during OpenAI’s own testing, it found two genuine zero-day flaws, which are now being disclosed to the software vendors involved. Access to the model’s most capable cyber-relevant features is being restricted to companies in OpenAI’s application-based cybersecurity program.
This isn’t a benchmark score or a marketing claim — it’s OpenAI’s own safety classification, published in the model’s system card, stating plainly that a general-purpose AI model can now do something that used to require a skilled human attacker with time and access.
Why this changes the calculus, not just the headlines
For most of 2026, the conversation about AI and security has run in one direction: AI-generated code ships with more vulnerabilities than human-written code, and teams need better review processes to catch it. Astra adds a second, sharper edge to that conversation — the same class of model that writes your code can now also be the thing probing it for weaknesses, at a capability level OpenAI itself is restricting. Any organisation running software with a public attack surface — which is most commissioned software — should read that as a signal that the baseline for “good enough” security testing just moved. Automated vulnerability discovery at this level won’t stay locked behind an application form for long; attackers get access to capable models too, on a lag measured in months, not years.
So what
If you’re commissioning software — particularly anything handling customer data, payments, or regulated information — this is a reason to ask your development partner a concrete question now, not after an incident: how does your security testing account for AI-capable adversaries, not just AI-generated code? Static analysis and a manual pen test once a year was a defensible baseline in 2024. It’s a thinner one now. Our custom software development and AI-assisted development work builds security review into delivery as standard, not as an afterthought bolted on before launch — get in touch if you want that built into your next project from day one.