OpenAI has postponed the release of its upcoming model, Astra, after internal testing suggested the system may be approaching a threshold the company treats as a red line for cybersecurity.

According to Business Standard, preliminary evaluations conducted over the past several days, along with assessments from outside experts, indicated that Astra may be capable of performing increasingly sophisticated cyber tasks autonomously. In other words: not just explaining how an attack works, but carrying out steps of one on its own.

Firstpost reports that OpenAI is pausing some internal work involving Astra after testing found the model had reached a critical level of cybersecurity capability. Coverage aggregated by SOFX frames it slightly differently, describing the model as having neared a critical cyber ability rather than crossed it. That gap between "reached" and "neared" matters, and the public record so far does not settle it.

Firstpost notes the decision follows separate reports concerning AI agents — software that acts with limited human supervision rather than simply answering questions.

The available reporting does not specify how long the delay will last, what safeguards would clear Astra for release, or which specific capabilities triggered the concern. It also does not detail which outside experts were consulted.

Why it matters: this is one of the clearest instances yet of an AI company delaying a product because its own safety testing said to — a signal that the industry's voluntary risk thresholds can actually bite, and a preview of the pressure regulators, security teams, and rivals will face as models edge closer to autonomously executing cyberattacks.