OpenAl’s new model is so capable, the company had to lock parts down

OpenAl’s new model is so capable, the company had to lock parts down

Every product launch is an argument about what something can do.

That is the entire genre. A company builds a thing, then spends a launch day listing the tasks it handles faster, cheaper, or better than whatever came before. Carmakers list horsepower. Chipmakers list transistors. Artificial intelligence labs list benchmark scores, and for roughly three years those scores have moved in one direction, which is up.

Read more Toyota Corolla vs. Honda Civic: Which One Is More Reliable?

The competitive logic got simple enough that investors stopped interrogating it. More capability means more paying customers, more enterprise contracts, and more justification for the hundreds of billions in data center spending now underwriting the AI trade. Nobody in that chain had much reason to advertise restraint.

That pattern has held through every model release since ChatGPT arrived, including the ones that shipped with safety documentation attached. The documentation described risks. The product still went out whole.

So it registers when a launch inverts the format. On Thursday, Sept. 3, OpenAI released GPT-6 Astra and spent a meaningful share of the announcement explaining which capabilities the model would refuse to use.

What OpenAI actually held back inside Astra

Astra is the first model the company has classified at the Critical cybersecurity threshold under its own Preparedness Framework, a designation that triggers deployment restrictions the rest of the industry has never had to apply.

The version reaching most customers refuses advanced offensive security work, including requests to write proof-of-concept exploits. In the application programming interface, a flagged task stops outright instead of pausing for approval. Enterprise administrators have to switch Astra on themselves, because workspace access is off by default.

Related: Apple’s accusations are making things uncomfortable for OpenAI

Astra’s ability to find and develop zero-day exploits “creates a need for stronger safeguards,” OpenAI said in its launch post.

The numbers behind that sentence are worth sitting with:

  • Astra scored a perfect 100% on ExploitBench without production safeguards, up from 78.5% for predecessor GPT-5.6 Sol, according to OpenAI.
  • The model found and used two previously unknown vulnerabilities during an internal test built from flaws disclosed in the three months before launch, according to OpenAI.
  • It solved 88.0% of software reverse-engineering tasks on a single attempt, against 55.9% for Sol, according to OpenAI.
  • Developers pay $10 per million input tokens and $50 per million output tokens, reported CSO Online.

OpenAI President Greg Brockman framed the release in bigger terms. “Welcome to the AGI era,” he told reporters, Forbes reported.

Why the Critical label is a disclosure and not a capability jump

The instinct here is to treat Astra as newly dangerous. When I read the launch post against OpenAI’s own August disclosures, that reading fell apart.

More Artificial Intelligence:

  • Berkshire CEO explains Buffett’s surprise AI stock bet
  • Michael Burry doubles down on his surprising AI bet
  • Palantir just won the Army and lost Michael Burry

OpenAI paused internal work on Astra in early August after the model showed sharp gains in agentic coding and cybersecurity, a decision covered here when the company split its Daybreak program into two access tiers. The capability existed then. What arrived on Sept. 3 was the measurement.

“The testing changed. The model did not,” said Sanchit Vir Gogia, chief analyst at Greyhound Research, CSO Online reported.

That inverts the obvious enterprise response, Gogia argued. Astra is now the only frontier model whose offensive cyber ceiling has been measured against a published threshold and disclosed. Every unlabeled model already sitting behind corporate credentials has never been tested that way, and will not be until its vendor decides to test it.

Those models are not safer. They are unmeasured. My analysis of the comparison table OpenAI published alongside the launch found rival models scoring within striking distance on the same exploit benchmarks, without any equivalent public threshold attached to them.

That is the part worth carrying into a portfolio decision. The market has spent this year pricing AI cyber risk off incidents, which arrive at random and fade in a week. Astra prices it off a published measurement, which does not fade and which competitors will eventually have to answer.

Read more Brazilian court suspends licenses for Sigma Lithium mine

CFOTO / Getty Images

What the Astra lockdown signals for cybersecurity stocks

For investors, the disclosure lands on a trade that has been working all year.

Enterprise security budgets have been repricing since spring, and the catalyst has consistently been AI capability rather than any single breach. CrowdStrike (CRWD) and Palo Alto Networks (PANW) both hit record highs on Aug. 10 following the Black Hat conference, where AI security demand dominated the agenda.

“AI agents have fundamentally changed the threat landscape,” BTIG analysts wrote to clients after that conference, CNBC reported.

Astra hardens that thesis rather than complicating it. A vendor voluntarily disabling its own model’s best offensive capability is telling security buyers, in the plainest language available, that the attacker side of the equation just got cheaper. Chief information officers do not need a briefing note to translate that into a budget line.

The distribution layer benefits too. Astra ships through Microsoft (MSFT) Azure and Amazon (AMZN) Bedrock, which means the two largest cloud vendors are now selling a model whose capability ceiling is a public compliance fact rather than a marketing claim.

The read-across is not uniform, and that matters for position sizing. Endpoint and identity vendors sit closest to the agentic attack surface Astra widens. Firewall-heavy revenue mixes sit further from it. Palo Alto shares had already roughly doubled year to date before this disclosure, which leaves less room for a headline to do the work a quarter usually has to do.

The gap between OpenAI monitoring Astra and enterprises auditing it

The uncomfortable finding sits further down the launch post, where OpenAI acknowledged that Astra’s written reasoning is harder to monitor than its predecessor’s.

The company attributes the decline to Astra solving problems in fewer written steps. The practical effect is the same either way. A model that behaves better, while revealing less about why, is a model that outruns the audit tooling built around it.

Gogia made the sharper version of that point to CSO Online, noting that OpenAI’s ability to monitor Astra does not give an enterprise the ability to audit it. The telemetry stays with the vendor.

There is a cost on the other side as well. Users outside OpenAI’s vetted access programs may hit slowdowns, pauses, or outright blocks, sometimes in the middle of work unrelated to security, according to MarkTechPost, which cited OpenAI’s Mia Glaese.

OpenAI has said it will loosen those restrictions for vetted defenders through Daybreak in the coming weeks. That is the number worth tracking, and it is not a benchmark score. It is the ratio of how much capability gets unlocked to how many organizations clear the vetting.

If that ratio stays narrow, Astra becomes a compliance product with a genuine moat, and the cybersecurity names selling defense against everything below the frontier keep their run. If it widens quickly, the restraint on display Sept. 3 may turn out to have been a launch-week posture, and the safety disclosure investors are currently reading as a moat starts reading as a pause.

Related: OpenAI just disclosed something genuinely alarming

The Arena Media Brands, LLC THESTREET is a registered trademark of TheStreet, Inc.

Read more Israel’s Netanyahu orders West Bank settler outposts to be removed, sources say

This story was originally published September 6, 2026 at 11:03 AM.

Post Comment