Cyber capability signal · preliminary vendor assessment

OpenAI Astra Critical Cyber Capability: What Legal Buyers Can Decide

OpenAI says it cannot rule out that Astra reaches its Critical cyber threshold. That is a dated internal capability assessment—not a legal classification, product approval or permission to test a system.

Direct answer

Treat OpenAI’s Astra statement as a material capability signal. Before any use, verify the purchased surface and current availability, the actor’s authority, data and tool boundary, safeguards, human control, incident plan and any contract or insurance notice questions. Do not turn a preliminary vendor assessment into a legal designation or a general conclusion that the product is safe or unsafe.

Governance gates separating OpenAI Astra capability assessment from availability, authority, safeguards, insurance and incident readiness
Decision map. An internal capability threshold is a dated risk signal, not a legal classification or product approval.

What OpenAI actually said

On August 7, 2026, OpenAI published an internal assessment stating that recent Astra evaluations mean it can no longer rule out Critical cyber capability under its Preparedness Framework. The provider describes that threshold as the ability to identify and develop functional zero-days across many hardened real systems without human intervention, or to devise and execute an end-to-end novel strategy against hardened targets from a high-level goal.

The wording matters. “Cannot rule out” is not the same as a final external finding that every Astra configuration has demonstrated the threshold. It does not create a legal category, establish availability in a customer account, authorize security testing or decide whether a particular workflow is appropriate.

Six gates for the buyer record

GateMinimum evidenceStop condition
AssessmentExact OpenAI statement, date, framework version and threshold.The claim is broader than the cited source.
AvailabilityPurchased product surface, account access, model or agent identifier and region.A roadmap or announcement is treated as enabled access.
AuthorityNamed system owner, written scope, permitted techniques and time window.The operator cannot prove permission for the target.
SafeguardsIdentity, tool permissions, network boundary, approval and stop controls.The agent can reach systems or make changes outside the approved scope.
Incident planMonitoring, evidence capture, containment, provider contact and escalation owner.A material action cannot be reconstructed or stopped.
DecisionApproved workflow, data, users, duration, reviewer and rollback.The proposal is a provider-wide approval.

Verify availability independently

OpenAI’s Path to Astra owns the provider’s current availability narrative. A capability publication can arrive before, after or separately from the product route a buyer can purchase. Check the current catalog, executed order form and account. Record the exact interface, API or agent environment and whether the relevant safeguards are mandatory or configurable.

Do not inherit controls across surfaces. A research environment, restricted program, managed workspace and API application can have different users, data paths, logging and support. If the route remains unavailable or undocumented, the correct status is Unknown or monitor-only—not implied access.

Make authority machine-readable and human-readable

Cyber work requires explicit authority. Name the assets, owner, environment, allowed methods, prohibited actions, data handling, hours, rate limits, stop conditions and escalation contact. Translate that scope into the agent’s tool and network permissions. A policy paragraph is not effective if the runtime can reach more than the approved target.

Test a denied target, a denied write, a required approval and an emergency stop with non-sensitive canaries. Preserve the actor, instruction, model, tool call, result, approval and destination. The buyer should be able to show both what the agent was allowed to do and that the boundary operated.

Route contract and insurance questions to the right owners

Review the purchased terms, acceptable-use rules, incident obligations, indemnities, exclusions and support path for the exact service. OpenAI’s Usage Policies are one source, not the whole contract chain. Ask counsel whether the planned activity needs additional client, counterparty or system-owner authorization.

Insurance requirements depend on the policy, jurisdiction and facts. Do not promise coverage or assume exclusion. Give the broker or coverage counsel the actual workflow, authority, capability, safeguards and incident process, then preserve the resulting questions and answers. A capability label alone is not a coverage conclusion.

Prepare the incident record before the pilot

  1. Assign the security and legal decision owners.
  2. Capture stable run, approval and tool identifiers.
  3. Define which events stop execution automatically.
  4. Preserve evidence without unnecessarily copying sensitive content.
  5. Test isolation, credential revocation and return to the previous route.
  6. Record provider and affected-system contacts.

Use NIST’s AI Risk Management Framework as a governance reference, not a certification. The acceptance decision remains specific to the workflow and evidence.

The narrow defensible conclusion

Observed: OpenAI published a preliminary internal assessment and a defined capability threshold. Supported inference: a buyer should increase scrutiny of authority, tool access, monitoring and response for a relevant Astra workflow. Unknown until verified: the customer’s route, safeguards, contract effect, insurance response and performance on its systems. That distinction supports action without turning a frontier-model announcement into alarm or assurance.

FAQ

Did OpenAI declare Astra a Critical model?

OpenAI said its recent internal evaluations mean it cannot rule out Critical cyber capability under its Preparedness Framework. Preserve that preliminary wording rather than converting it into a broader legal or external designation. Official source · checked 2026-09-03

Does the assessment mean a law firm can run Astra against any system?

No. The operator still needs authority for the exact target and activity, plus bounded tools, safeguards, human control and an incident plan.

Does a Critical capability finding determine insurance coverage?

No. Coverage depends on the policy, jurisdiction and facts. Provide the real workflow and controls to the broker or coverage counsel.

Sources checked

Operational information, not legal advice. Verify current terms, account configuration and applicable professional duties before use.