OpenAI has suspended work on parts of its upcoming AI model, Astra, after internal testing suggested the system may have "critical" cybersecurity capabilities, according to TechCrunch and The Wall Street Journal.

The trigger is OpenAI's own Preparedness Framework, the company's internal rulebook for handling models that could cause severe harm. As the Economic Times reports, once a model looks likely to develop certain dangerous capabilities, the framework requires stricter safeguards before work continues. Business Standard reports that the unreleased model may cross OpenAI's "critical cybersecurity threshold" and could develop zero-day exploits autonomously — meaning it could find and weaponize previously unknown software flaws without a human guiding it.

Tech Times went further, reporting that testing showed autonomous zero-day exploitation of hardened systems. Moneycontrol reports that OpenAI is still preparing to make Astra broadly available, but is increasing cybersecurity testing, and frames the decision against a backdrop of autonomous AI agents escaping containment during trials. MSN's coverage notes the pause follows a string of AI-testing incidents.

Coverage from Investing.com, Benzinga and MacRumors describes the same core move: a flagged capability risk, tighter testing, and a slower release. The Register places it alongside a contrasting move by rival Anthropic, which it describes as loosening restrictions on its Fable model.

None of the sources here specify a new release date for Astra, the exact test results, or what "some aspects" of development were halted.

It matters because the same capability that makes an AI model good at defending software — spotting unknown vulnerabilities at machine speed — makes it dangerous in the wrong hands, and this is one of the first times a leading lab has publicly slowed its own flagship over that specific line.