
OpenAI has said its upcoming AI model, Astra, may reach the "critical" cybersecurity capability threshold under its internal Preparedness Framework. The company said internal evaluations showed notable improvement in the model's ability to perform cybersecurity tasks, including identifying zero-day exploits in hardened real-world systems without human intervention. OpenAI stressed that Astra was not involved in the recent Hugging Face breach and that evaluations are still preliminary.

In response, OpenAI has expanded safety testing, implemented stricter security measures such as isolated testing environments and encrypted model weights, and paused some internal Astra-related activities. The company said it will work with government agencies and third-party partners on higher-risk evaluations. Separately, Chinese lab Z.ai has delayed release of its GLM 5.3 model due to similar concerns, claiming it has already found over 2,400 security flaws including more than 1,000 rated critical or high severity.
OpenAI President Greg Brockman has urged organisations to "fundamentally uplevel" cybersecurity practices now, warning that AI-powered attackers are approaching. He shared a 10-point defensive playbook including deploying AI agents in security teams and automating detection triage.
All three sources present the same emerging trend: advanced AI models are becoming capable of autonomous cyberattacks, and their developers are reacting with caution. The ET/ANI report frames OpenAI's disclosure as a transparency exercise under its Preparedness Framework, emphasising internal processes and planned safeguards. Times Now's two stories take a more alarmist tone, highlighting warnings from Greg Brockman and from Chinese lab Z.ai, and framing the race between the US and China as a zero-sum contest. The middle ground is that while these red-teaming disclosures are a positive sign of voluntary safety culture, they also confirm that the capability gap between AI-powered defenders and attackers is closing fast. Watch for government responses and whether other labs follow with similar delays or restrictions.
Coverage: 3 sources, 1 neutral, 2 sensationalist
Sources (3): ciso.economictimes.indiatimes.com (neutral report), timesnownews.com (sensationalist), timesnownews.com (2) (sensationalist)
This story was synthesised by AI from the 3 sources linked above. Methodology and corrections.
Updated: this story now draws on 3 sources.