OpenAI is treating its upcoming Astra model as its first critical cybersecurity model under the company's Preparedness Framework. The designation places Astra at the framework's highest cyber-risk threshold and means OpenAI is adding controls for its further development. For developers and enterprise buyers, the announcement matters because it signals that advanced cyber capabilities may be subject to tighter testing, access and deployment decisions before they reach broader users.
The company has made frontier cybersecurity a core risk area in its safety work. In its official overview of strengthening cyber resilience, OpenAI describes a strategy that combines safeguards for highly capable models with expanded defensive tools and trusted access for security professionals. Astra sits within that wider approach to governance, rather than representing a conventional product launch.
What Astra's critical designation means
Under OpenAI's Preparedness Framework, cyber capability levels inform the safeguards and deployment gates that apply to a model. OpenAI's public materials define Critical as the highest cyber-capability threshold. Treating Astra at that level means the company is planning development around the possibility that the model could create severe cybersecurity risks if safeguards and access controls are inadequate.










