OpenAI's Next AI Hits Its Own Top Danger Level for Cyberattacks
The same skills that stop hackers can also train them.
OpenAI says it is preparing to release a new AI model called Astra, and it is making a bold claim about it: the system is a major leap forward in cybersecurity, strong enough to reach the top of OpenAI's own internal risk scale. That top tier is called "Critical." It's the company's way of saying an AI could meaningfully help someone cause serious real-world harm — not just write a mean email, but potentially find and use weaknesses in the software that runs banks, hospitals, power grids and phones.
Here's why that's a strange thing to brag about. "Reaching Critical" is normally a warning label, not a selling point. OpenAI grades its models on a four-step ladder — Low, Medium, High, Critical — and most released models sit well below the top. So when a company says its new model hits the highest rung in cyber capability, it's saying two things at once: this AI is extremely good at security work, and it is exactly the kind of tool a bad actor would want.
There is a hopeful reading. The same AI that can spot a hidden flaw in software can help the good guys find it first and patch it before anyone exploits it. Security teams are hugely outnumbered, and a tireless AI assistant that reads millions of lines of code looking for holes could be a genuine gift — like hiring a night-shift security guard who never sleeps. That's almost certainly the framing OpenAI prefers.
The honest catch: we don't actually know yet. OpenAI didn't say when Astra launches, what exactly it can do, whether outside experts verified the claim, or what safeguards will be built in. Big safety promises made before launch don't always survive contact with a competitive market. Until independent researchers test Astra themselves, treat "Critical" as a flag to watch, not a finished verdict.
- OpenAI says its upcoming model, Astra, is exceptionally strong at cybersecurity — enough to hit 'Critical,' the highest rung on its own four-level risk scale.
- 'Critical' normally signals danger, not bragging rights: it means the AI could potentially help someone attack real systems like banks or hospitals.
- The upside is real too — an AI that hunts software flaws could help defenders patch them faster, but OpenAI hasn't given a launch date or explained its safeguards.
Why It Matters
A stronger AI could protect your bank, hospital and phone data — or hand attackers a powerful new tool.