What OpenAI actually said
On August 7, 2026, OpenAI published an internal assessment stating that recent Astra evaluations mean it can no longer rule out Critical cyber capability under its Preparedness Framework. The provider describes that threshold as the ability to identify and develop functional zero-days across many hardened real systems without human intervention, or to devise and execute an end-to-end novel strategy against hardened targets from a high-level goal.
The wording matters. “Cannot rule out” is not the same as a final external finding that every Astra configuration has demonstrated the threshold. It does not create a legal category, establish availability in a customer account, authorize security testing or decide whether a particular workflow is appropriate.
Six gates for the buyer record
| Gate | Minimum evidence | Stop condition |
|---|---|---|
| Assessment | Exact OpenAI statement, date, framework version and threshold. | The claim is broader than the cited source. |
| Availability | Purchased product surface, account access, model or agent identifier and region. | A roadmap or announcement is treated as enabled access. |
| Authority | Named system owner, written scope, permitted techniques and time window. | The operator cannot prove permission for the target. |
| Safeguards | Identity, tool permissions, network boundary, approval and stop controls. | The agent can reach systems or make changes outside the approved scope. |
| Incident plan | Monitoring, evidence capture, containment, provider contact and escalation owner. | A material action cannot be reconstructed or stopped. |
| Decision | Approved workflow, data, users, duration, reviewer and rollback. | The proposal is a provider-wide approval. |
Verify availability independently
OpenAI’s Path to Astra owns the provider’s current availability narrative. A capability publication can arrive before, after or separately from the product route a buyer can purchase. Check the current catalog, executed order form and account. Record the exact interface, API or agent environment and whether the relevant safeguards are mandatory or configurable.
Do not inherit controls across surfaces. A research environment, restricted program, managed workspace and API application can have different users, data paths, logging and support. If the route remains unavailable or undocumented, the correct status is Unknown or monitor-only—not implied access.
Make authority machine-readable and human-readable
Cyber work requires explicit authority. Name the assets, owner, environment, allowed methods, prohibited actions, data handling, hours, rate limits, stop conditions and escalation contact. Translate that scope into the agent’s tool and network permissions. A policy paragraph is not effective if the runtime can reach more than the approved target.
Test a denied target, a denied write, a required approval and an emergency stop with non-sensitive canaries. Preserve the actor, instruction, model, tool call, result, approval and destination. The buyer should be able to show both what the agent was allowed to do and that the boundary operated.
Route contract and insurance questions to the right owners
Review the purchased terms, acceptable-use rules, incident obligations, indemnities, exclusions and support path for the exact service. OpenAI’s Usage Policies are one source, not the whole contract chain. Ask counsel whether the planned activity needs additional client, counterparty or system-owner authorization.
Insurance requirements depend on the policy, jurisdiction and facts. Do not promise coverage or assume exclusion. Give the broker or coverage counsel the actual workflow, authority, capability, safeguards and incident process, then preserve the resulting questions and answers. A capability label alone is not a coverage conclusion.
Prepare the incident record before the pilot
- Assign the security and legal decision owners.
- Capture stable run, approval and tool identifiers.
- Define which events stop execution automatically.
- Preserve evidence without unnecessarily copying sensitive content.
- Test isolation, credential revocation and return to the previous route.
- Record provider and affected-system contacts.
Use NIST’s AI Risk Management Framework as a governance reference, not a certification. The acceptance decision remains specific to the workflow and evidence.
The narrow defensible conclusion
Observed: OpenAI published a preliminary internal assessment and a defined capability threshold. Supported inference: a buyer should increase scrutiny of authority, tool access, monitoring and response for a relevant Astra workflow. Unknown until verified: the customer’s route, safeguards, contract effect, insurance response and performance on its systems. That distinction supports action without turning a frontier-model announcement into alarm or assurance.
FAQ
Did OpenAI declare Astra a Critical model?
OpenAI said its recent internal evaluations mean it cannot rule out Critical cyber capability under its Preparedness Framework. Preserve that preliminary wording rather than converting it into a broader legal or external designation. Official source · checked 2026-09-03
Does the assessment mean a law firm can run Astra against any system?
No. The operator still needs authority for the exact target and activity, plus bounded tools, safeguards, human control and an incident plan.
Does a Critical capability finding determine insurance coverage?
No. Coverage depends on the policy, jurisdiction and facts. Provide the real workflow and controls to the broker or coverage counsel.
Sources checked
- Responding to the next frontier of critical cyber capabilities, checked 2026-09-03.
- Preparedness Framework v2, checked 2026-09-03.
- Path to Astra, checked 2026-09-03.
- Usage Policies, checked 2026-09-03.
- AI Risk Management Framework, checked 2026-09-03.
Operational information, not legal advice. Verify current terms, account configuration and applicable professional duties before use.