OpenAI says it slowed Astra model development over security concerns
OpenAI said it has suspended work on some aspects of its upcoming model Astra over concerns about its cybersecurity prowess.
OpenAI said Friday it has suspended work on some aspects of its upcoming model Astra after an internal review found it had made significant advancements in agentic coding and cybersecurity β enough to warrant concern over its capabilities.
OpenAI said in a blog post Friday that this model, which is still in development, reached its βcritical cybersecurity threshold,β meaning it could independently identify and carry out cyberattacks against traditionally well-protected real-world systems. Under the companyβs βPreparedness Framework,β which it created in 2023, this triggered additional safeguards.
βWhile we continue to benchmark and assess this model, our preliminary evaluations indicate strong enough performance that we cannot rule out Critical capability level at this time,β OpenAI wrote. βAstra is an upcoming model, and was not involved in exploiting Hugging Face.β
The disclosure highlights an unusual moment in the topsy-turvy, and still nascent frontier AI labs sector. Companies across every industry hold back products over potential risks, including for safety and cybersecurity concerns. But they rarely announce those decisions publicly when itβs a product that is still under development.
In this case, OpenAI is already under scrutiny after a different unreleased model breached Hugging Faceβs systems during internal testing β the first verifiable incident of an AI lab losing control of its model. Since then, OpenAI and AI labs such as Anthropic have disclosed other incidents in which AI models breached their sandboxes and posed threats during cybersecurity tests.
The string of cases β seems like a new disclosure every day now β has triggered varying reactions from cybersecurity experts, lawmakers and the AI labs themselves. Some express fear and call for stricter oversight. But thereβs also a bit flexing. In certain circles, any AI lab with a model that has that kind of capability will be seen as an impressive advancement.
OpenAI said it was sharing this information because it believes βitβs important to be transparent with the public and the safety and security communities about this potential shift in capabilities.β
The AI lab said itβs also taking action, including enacting stricter security controls and pausing internal activites involving Astra that donβt meet these beefed guardrails. OpenAI said it is working with relevant government agencies and βselect AI safety organizationsβ to test the capabilities for this model.
When you purchase through links in our articles, we may earn a small commission. This doesnβt affect our editorial independence.
You can contact or verify outreach from Kirsten by emailing [email protected] or via encrypted message at kkorosec.07 on Signal.
Originally published by TechCrunch AI. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.