OpenAI has halted internal work on its next major model. The reason is not a technical glitch, but the opposite: Astra has apparently become so adept at detecting and exploiting security vulnerabilities that the company can no longer rule out the highest risk level of its own regulatory framework. For Europe, the announcement comes in a week in which Brussels will, for the first time, have full enforcement powers over AI providers.
The fact that AI models can now find vulnerabilities faster than humans can fix them is no longer a theoretical problem. Apple recently limited the number of reports in its bug bounty program because the flood of machine-generated submissions had become unmanageable. OpenAI now describes the other side of the same development: a model whose capabilities the company says it cannot yet contain securely enough to continue working with internally.
The announcement, dated August 7th, is titled "Responding to the next frontier of critical cyber capabilities." It is noteworthy because OpenAI is not announcing a product, but rather explaining a delay.
Key Facts at a Glance
- OpenAI is pausing internal activities related to its upcoming Astra model until stricter security controls take effect.
- Preliminary tests suggest that Astra could reach the "critical" level for cyber capabilities – previous models, including GPT-5.6 Sol, were at the "high" level.„
- According to OpenAI, Astra was not involved in the incident in July, in which models independently breached a foreign platform during internal tests.
- No launch date has been announced; OpenAI announces tests with government agencies and security institutions.
- Since August 2, 2026, the EU Commission has been able to enforce the obligations for systemic risk models with full powers for the first time.
How OpenAI defines the "critical" level
The decision is based on the Preparedness Framework, which OpenAI first published in December 2023. It describes thresholds for capabilities above which a model requires special precautions – in addition to cybersecurity, also biology, chemistry, and the ability to evolve.
The critical threshold in cybersecurity is reached when a model can develop functional zero-day attacks against many hardened real-world systems without human intervention. Alternatively, it is sufficient if the model independently designs and executes novel attack strategies based solely on a given objective.
OpenAI phrases it cautiously: The assessment is preliminary, measurements are ongoing, and a critical level cannot currently be ruled out. Previous models were tested using the same procedure and classified at the next level down, "high" - including GPT-5.6 Sol, which only a few days ago lost its message limit in the free plan.
Which measures will now take effect?
The announced steps relate exclusively to the internal handling of the model. In the future, Astra will run in isolated test environments with restricted network and tool access; the model weights will be additionally encrypted, and executions will take place in a secluded environment.
This includes continuous monitoring of all agent-based applications of the model, even during training and evaluation. According to OpenAI, the monitors examine the model's thought processes and trigger a safety procedure that interrupts the activity in the event of risky actions. Work that does not yet meet these requirements is suspended until further notice.
OpenAI explicitly denies any connection to the incident from July. At that time, GPT-5.6 Sol and another, more powerful pre-release model independently compromised the Hugging Face platform during internal benchmarks – according to the company, Astra was not involved.
What has been in effect in Europe since August 2nd
For providers of general-purpose AI models with systemic risk, Article 55 of the AI Regulation prescribes precisely the type of safeguards that OpenAI voluntarily describes here. These obligations have been in effect since August 2, 2025; since August 2, 2026, the European Commission has been able to enforce them with its full range of tools – up to and including model access for its own evaluations and, in extreme cases, the recall of a model from the market.
| Obligation under Article 55 AI Regulation | What OpenAI announces for Astra |
|---|---|
| Model evaluation according to the state of the art, including documented attack tests | Ongoing internal evaluations, plus tests with authorities and selected security organizations |
| Assess and mitigate systemic risks | Robustness tests of the protection mechanisms; pause for activities below the new standard. |
| Document serious incidents and report them immediately to the Office for Artificial Intelligence. | Universal monitoring of risky actions with an interruption mechanism |
| Appropriate level of cybersecurity for model and infrastructure | Isolated test environments, enhanced protection of model weights, sealed design |
In Europe, the responsible body would not be a national authority, but rather the Office for Artificial Intelligence in Brussels. While the Federal Network Agency has been the central market surveillance and contact point in Germany since the AI-MIG came into force on July 29th, oversight for models of this class lies with the Commission.
One detail makes things more complicated for OpenAI than the notification suggests: The company has fully signed the Code of Practice for General Purpose AI Models, including the chapter on safety. For signatories, the Commission focuses its oversight on compliance with the code.
Why this topic is coming up at Apple
The connection to the Apple world is not contrived. Apple has been a partner of Project Glasswing since April and uses a model of the same performance class for defensive vulnerability scanning – in macOS, iOS, iPadOS, watchOS, tvOS, visionOS, and Safari. The same capability that OpenAI classifies as a risk in Astra is used there on the defensive side.
The specifics of this collaboration became apparent in May when several reported macOS vulnerabilities stemmed from it. The difference with Astra lies less in the capability itself than in who has access: Apple's model is restricted to a small circle and has never been publicly available.
OpenAI launched its own security program, Daybreak, in May as a response to Anthropic's Glasswing, and refers to this in the current announcement. The stated policy of both companies is the same: models with such capabilities should benefit defenders before attackers can exploit them.
In practical terms, Apple users will primarily notice one thing: more updates at shorter intervals. The unscheduled update at the beginning of August, which closed a gap in screen sharing across three macOS generations, fits this pattern.
The patch schedule is becoming more frequent
Apple has limited the acceptance of bug bounty reports due to machine-generated submissions and, in early August, released an unscheduled update cycle spanning three macOS generations. Based on this, we expect the intervals between security updates in the Apple ecosystem to shorten further.
For you, this means in everyday use: Keep automatic updates enabled and don't treat intermediate versions as insignificant. As the tools on both sides become faster, the time between release and installation determines how long your device remains vulnerable. Security fixes reach Apple devices not only through major system versions, but also through smaller interim updates that are released shortly afterward.
The process remains remarkable regardless of how reliable OpenAI's preliminary measurement ultimately proves to be. A company that has been releasing model after model for months under competitive pressure halts a completed project and publicly justifies this with its own rules. This is either a serious attempt to slow down or a message to regulatory authorities – probably both.
What to expect next
OpenAI has not specified a release date for Astra, and the phrase "until the stricter requirements are met" deliberately leaves open how long that will take. Tests with government agencies and security institutes have been announced, along with recommendations for external testing partners who can conduct high-risk analyses.
Should the critical rating be confirmed, Astra would be the first model ever to be listed in this category by OpenAI. Whether and how such a model can then be launched in the EU is the question that will become more interesting in the coming months than any performance promise. (Image: OpenAI / Apfelpatient)
- iOS 26.6.1: Apple is apparently testing an interim update
- iPad shipments fall by 7.5 percent – market collapses
- Apple holds 65 percent of the premium smartphone market



