OpenAI says Astra is the first of its models to meet the Critical cybersecurity threshold in its Preparedness Framework.

In a Sept. 1 post, the company said that with the right tools and access, Astra can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step. It said that bar requires stronger safeguards during development and before release.

Astra is not out yet. OpenAI said it plans to make Astra available soon, but access to its most advanced cybersecurity capabilities will be more limited at first. Advanced cyber work will initially go to a group of testers, with access through Daybreak Blue following to expand defensive use.

OpenAI said Astra was not involved in the Hugging Face incident. It also said it delayed parts of Astra’s development and release while it strengthened protections against cyber misuse and unauthorized model actions after that incident, and that it has incorporated learnings from it into the Astra safety approach.

WIRED and Mashable reported the Critical designation on Sept. 1. Earlier August coverage had described OpenAI as unable to rule Critical out while assessment continued. The company’s Sept. 1 post is the clearer declaration: it now believes Astra meets the threshold.

OpenAI said it will share more detail in Astra’s system card at launch.