GPT-6 Astra Is Rated "Critical" for Cyber Risk. What That Means for You

By Andrew Owens |

On September 3, OpenAI released GPT-6 Astra. It's the first model OpenAI has classified as "Critical" for cybersecurity risk under its own Preparedness Framework, which is the scale they use to decide how careful to be before shipping something.

I want to explain what that rating means in plain terms, because the one number behind it matters a lot for anyone running a website.

What "Critical" means here

OpenAI grades new models on a few risk areas before release. Cybersecurity is one of them. Critical is the top of that scale, and it's triggered by a model that can find vulnerabilities nobody knew about and turn them into working exploits with very little help from a person.

Hitting that level forces OpenAI's own restrictions. According to reporting from The Hacker News and CSO Online, summarized in a Cloud Security Alliance research note, the version of Astra the public gets is limited to secure code review and patching help, it refuses requests for proof-of-concept exploits, and companies have to opt in to turn it on rather than getting it by default.

The number that matters

The benchmark getting the most attention is called ExploitBench. It measures how well a model takes a vulnerability that's already public and turns it into a working exploit. Astra reportedly scored 100%.

In other words: for the kinds of bugs in that test, once a vulnerability is disclosed, the model basically always gets to a working attack.

That lines up with what Anthropic said about its Mythos model back in April, which I wrote about in what Claude Mythos means for your website. Anthropic's model went from nothing but a CVE number and a patch to a working exploit in half a day, for under $1,000.

Two different labs, same direction. The gap between "a fix is published" and "a working attack exists" is collapsing.

Why this is a small company problem

Big companies have security teams that patch critical issues within days. A lot of small companies patch when they get around to it. That was always a risk, but it used to be a manageable one, because writing a working exploit for a new vulnerability took real skill and real time. Plenty of disclosed bugs never got exploited at all because nobody bothered.

When exploit writing gets fast and cheap, "nobody bothered" stops being a defense. Attackers can go after every known bug on every unpatched server, and the unpatched servers are disproportionately at small companies.

The public Astra won't write exploits for you. But the capability exists now, and not every model or every person using one plays by those rules.

What I'd change this month

  • Turn on automatic security updates for your OS, your runtime, and your dependencies. GitHub's Dependabot, Renovate, whatever you use. Make security updates merge fast.
  • Write down what you run. Framework, language version, database, major libraries, and any third-party software on your servers. When a big CVE drops you want to know in five minutes whether it affects you, not after a day of digging.
  • Shorten your patch window. If a critical fix for something you use is out, aim for days, not "next sprint."
  • Put a WAF in front of your app if you don't have one. It can block known attack patterns while you get the real patch out.
  • Test after you patch. Updating a package doesn't always mean the vulnerable code is gone. Confirm it from the outside.

One more thing about the rating

Credit where it's due: OpenAI publishing a Critical rating and putting restrictions on its own flagship model is the system working the way it's supposed to. A lab saying "this one is dangerous" is useful information.

Treat it as a warning, not a news item. The tools attackers have are improving on a schedule of months. Your patch process probably hasn't changed in years.

If you're not sure how exposed you are right now, run the free scan. If you want a real answer, the pen test is $495 and back in 24 hours.

Ready to fortify your defenses against cyber threats?

Start Your Penetration Test Now