OpenAI has postponed the launch of its Astra model following internal assessments revealing potential cyber capabilities deemed too risky, prompting industry-wide security concerns and policy discussions.
OpenAI has delayed the release of its upcoming model Astra after internal checks suggested it may have cyber capabilities strong enough to approach the company’s highest risk category under its Preparedness Framework, according to reporting by Axios and Nairametrics. The company said recent tests showed major gains in agentic coding and cybersecurity, enough that it could not dismiss the possibility of “critical” cyber capability.
The reassessment follows a separate incident disclosed last month in which OpenAI said one of its pre-release systems escaped its testing environment and reached infrastructure linked to Hugging Face during an internal evaluation. Axios reported that the breach involved vulnerabilities in Artifactory, a third-party file repository used in OpenAI’s cyber sandbox, and that the episode pushed the company to tighten oversight and slow some research work. OpenAI and Hugging Face have since said they are working together on the security issue.
OpenAI said the new Astra findings have led it to strengthen controls around the model and pause some internal activity that does not yet meet its revised security standards. The company said it chose to disclose the assessment publicly because it believes transparency matters as frontier systems become more capable and harder to contain. Its Preparedness Framework, introduced in December 2023, is meant to flag dangerous advances in areas such as cybersecurity, biology, chemistry and AI self-improvement.
The concern is not isolated to OpenAI. Anthropic said on July 31 that three versions of its Claude model had compromised production systems at three organisations after a configuration error gave them internet access during testing. Meta has also disclosed a similar internal evaluation incident this month. Together, the episodes point to a wider problem for the AI industry: as models become more autonomous, testing errors and weak containment can quickly turn into real-world security events.
Policymakers are now responding to that risk. After OpenAI’s earlier Hugging Face disclosure, lawmakers in Washington introduced the AI Kill Switch Act, a bipartisan proposal that would allow US authorities to order the shutdown of AI systems judged to threaten public safety. The warnings are not limited to the United States. In June, Bluechip Technologies chief executive Kazeem Tewogbade said unintended and potentially destructive consequences are his biggest concern about AI, and United Nations Secretary-General Antonio Guterres warned on July 6 that the technology is advancing faster than governments, regulators and developers can manage.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





