OpenAI has slowed work on its upcoming model, Astra, after internal testing raised the possibility that the system carries "critical" cybersecurity capabilities.

In a post titled "Responding to the next frontier of critical cyber capabilities," OpenAI said it is sharing preliminary cybersecurity evaluations for Astra along with the steps it is taking to strengthen safeguards and security controls.

According to Axios, which reported the story exclusively, OpenAI says it "cannot rule out" that Astra has critical cyber capabilities — a designation that has prompted the company to expand safety testing around the model, potentially delaying its launch. Reuters reported that OpenAI flagged the possible critical cybersecurity risk and is tightening controls in response. Bloomberg reported that the company has paused some work on the model over cyber concerns.

The key phrase is "cannot rule out." OpenAI is not saying Astra definitively can conduct serious cyberattacks; it is saying its own evaluations were not able to establish that it can't. Under the company's safety framework, that uncertainty alone is enough to trigger extra scrutiny before release.

What makes the cyber category distinct from other AI safety worries is how directly it maps onto real-world harm. A model capable of finding and exploiting software vulnerabilities at scale would be useful to defenders — and equally useful to attackers, who need no lab, no hardware, and no specialized supply chain.

OpenAI has not published a revised launch date for Astra, and the sources here do not specify what the expanded testing involves beyond strengthened safeguards and security controls.

This matters because it is one of the clearest cases yet of a leading AI company delaying a product it has already built on the basis of its own risk evaluations — a test of whether the voluntary safety commitments the industry has made hold up when they cost something.