Menu

Search

  |   Business

Menu

  |   Business

Search

OpenAI Restricts Astra AI Over Cyberattack Risks

OpenAI Restricts Astra AI Over Cyberattack Risks. Source: Jernej Furman from Slovenia, CC BY 2.0, via Wikimedia Commons

OpenAI has reportedly restricted parts of the development of its next-generation AI model, code-named Astra, after early evaluations indicated the system could potentially carry out sophisticated cyberattacks with limited or no human assistance.

The San Francisco-based artificial intelligence company said Thursday that Astra demonstrated significant advances in coding and cybersecurity capabilities during preliminary testing. The results raised concerns that the unreleased OpenAI model could approach the company’s internal “Critical” risk threshold.

Under OpenAI’s safety framework, an AI model may receive a Critical classification if it becomes capable of independently identifying previously unknown, or zero-day, software vulnerabilities or conducting end-to-end cyberattacks against secured networks without human guidance.

In response to the findings, OpenAI is limiting Astra development to highly controlled and isolated environments. Internal workflows that do not meet stricter security requirements have reportedly been paused as the company introduces additional safeguards.

Among the planned security measures are automated monitoring systems designed to detect and interrupt potentially dangerous or misaligned model behavior in real time. OpenAI also plans to involve government organizations and independent AI safety institutes in external testing designed to identify vulnerabilities and assess Astra’s cybersecurity risks.

The move highlights a growing challenge for the AI industry as developers race to build increasingly capable models while attempting to prevent those systems from being misused for hacking and other cyber threats. Earlier OpenAI technology, including GPT-5.6-Sol, reportedly reached a maximum internal risk classification of “High,” making Astra’s potential capabilities particularly significant.

OpenAI emphasized that Astra has not been publicly released and was not connected to recent prominent cybersecurity incidents, including the Hugging Face exploit. The company presented the development restrictions as evidence that its safety systems are identifying potentially dangerous capabilities before advanced AI technology reaches consumers or enterprise customers.

Astra’s testing could become an important case for how leading AI companies manage increasingly powerful cybersecurity capabilities while balancing innovation, AI safety and responsible deployment.

  • Market Data
Close

Welcome to EconoTimes

Sign up for daily updates for the most important
stories unfolding in the global economy.