On Friday evening, OpenAI published a blog post stating it could not rule out that its upcoming model Astra had reached the "Critical" cybersecurity threshold under its own Preparedness Framework. It paused internal development activities that did not meet the corresponding containment requirements.

Sam Altman posted that the company did not think keeping powerful models "to a chosen few" was a good strategy, and that it needed "a little longer to do this safely. But hopefully not too long."

Start with the steelman. The Framework was published in December 2023, revised in April 2025, and has now been tested by something real. Previous models, including GPT-5.6 Sol, were assessed at "High" — capable of identifying bugs and exploitation primitives, but not producing end-to-end exploit chains against hardened targets autonomously. Astra appears to have crossed that line. The company did not wait for a formal determination. It applied the development-stage controls, published the disclosure, and accepted the commercial delay.

That is not nothing. For nearly three years, the Framework sat there as a hypothetical. Critics described it as a PR instrument. A September 2025 arXiv paper concluded it "does not guarantee any AI risk mitigation practices." Georgetown CSET reached a similar finding. Those structural critiques have not been refuted. But the Framework did produce a real brake, under real cost, with real public disclosure. One data point does not reverse a trend, but it is more than a white paper.