Policy · Wired ·

OpenAI's Astra becomes first AI model with 'critical' cyber abilities

OpenAI says its forthcoming Astra model is the first to reach its 'critical' cyber threshold, able to independently find and chain unknown exploits. Early access via Daybreak Blue only.

Based on reporting by Wired — analysis by dalili

OpenAI announced Tuesday that its forthcoming AI model, Astra, is its first to reach the company's threshold for what it calls 'critical' cyber capabilities. OpenAI says it plans to publicly release a version of Astra 'soon,' but will make the model's advanced cyber capabilities available only to select partners in its Daybreak Blue early-access program at launch. OpenAI says an AI model has reached its critical cyber threshold when it can independently find and exploit previously unknown vulnerabilities in real-world software. The company says it has followed its procedure for this situation, which is to halt further development until appropriate safeguards and security measures can be implemented. OpenAI previously paused some training workloads related to Astra development. Executives say the company has now resumed work after putting additional safety and security controls in place. Partners in OpenAI's Daybreak program — including Cisco, Cloudflare, and Palo Alto Networks — will get early access to a less restricted version of Astra. Astra is not only capable of finding novel software vulnerabilities but is also able to 'chain' multiple exploits together. According to figures from OpenAI, Astra outperforms industry-leading AI models on cybersecurity benchmarks such as ExploitBench, which Astra scored 100 percent on.

Key takeaways

  • Astra is first AI model to hit OpenAI's 'critical' cyber threshold
  • Can independently find and exploit unknown software vulnerabilities
  • Can chain multiple exploits together for deeper system access
  • Scored 100% on ExploitBench cybersecurity benchmark
  • Daybreak Blue partners (Cisco, Cloudflare, Palo Alto) get early access
  • Multi-week development pause was imposed before release

Why it matters

This marks a watershed moment for AI cybersecurity. An AI model that can autonomously discover and chain zero-day exploits changes the threat landscape for every organization.

Related

  1. The Verge ·

    Microsoft: Almost No One Read NYT Articles via Chatbot

  2. TechCrunch ·

    OpenAI Agents Escape Again, Renewing Calls for AI Oversight

  3. Ars Technica ·

    Trump may reveal secret federal AI safety testing rules