Skip to content
Tech News
← Back to articles

OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

read original get YubiKey 5C NFC Security Key → more articles
Why This Matters

OpenAI says GPT-6 Astra is the first widely deployed model it classifies as "Critical" for cybersecurity under its Preparedness Framework, meaning it can autonomously find and exploit unknown vulnerabilities in hardened systems. During testing it discovered two real zero-days now being disclosed to maintainers. That shifts AI from a theoretical offensive-security risk to a demonstrated one, with major implications for defenders, vendors, and how frontier models are gated.

Key Takeaways
Worth a Look

YubiKey 5C NFC Security Key — If AI models are getting good enough to hunt zero-days on their own, hardening your own accounts is the cheap win — and a hardware key kills password-based and phishing takeovers outright. The YubiKey 5C NFC works over USB-C or by tapping your phone, and supports FIDO2/WebAuthn logins across major services including OpenAI, Google, and GitHub. Grab two so you always have a backup enrolled.

See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities.

This is part of the company's Preparedness Framework for cybersecurity and is evaluated when OpenAI releases more capable models.

Under OpenAI's own framework, a model reaches the Critical cybersecurity threshold if it can "identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention," or devise and execute new end-to-end attack strategies against hardened targets.

"GPT-6 Astra is a significant step up in cyber capabilities and meets our Critical threshold," OpenAI said in its system card.

"This means that, with the right tools and access, GPT-6 Astra can find previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step."

OpenAI also has evidence that Astra can actually discover previously unknown vulnerabilities.

For one evaluation, the company created a newer version of ExploitBench using vulnerabilities disclosed after Astra's knowledge cutoff.

"During the evaluation, Astra even discovered and used previously unknown zero-day vulnerabilities as part of its exploit chains," OpenAI said. "We are in the process of disclosing these two vulnerabilities to the maintainers."

OpenAI has strengthened Astra's jailbreak resistance, isolation, checkpoint encryption, monitoring, and internal deployment controls before release.

The company also claims Astra is better aligned than GPT-5.6 Sol, meaning it is less likely to overreach or violate safety and security boundaries, but that does not guarantee 100% safety.

... continue reading