AI has been useful for programming and cybersecurity for years, but GPT-6 Astra represents a significant change in what these systems can potentially do.
OpenAI classifies Astra as reaching its Critical cybersecurity capability threshold under its Preparedness Framework. According to OpenAI's evaluations, Astra can identify previously unknown vulnerabilities and, under certain conditions, develop ways of exploiting vulnerabilities in hardened systems. OpenAI
During evaluation, Astra reportedly discovered and used two previously unknown zero-day vulnerabilities, which OpenAI says were disclosed to the affected maintainers. OpenAI
That capability cuts both ways.
For defenders, increasingly capable AI could assist with secure code review, vulnerability discovery, patch development, malware analysis, detection engineering, and analyzing enormous amounts of security information much faster than a human could do manually.
The same capabilities obviously create security concerns if they're misused. That's why access to advanced offensive cybersecurity capabilities is restricted and monitored rather than simply exposing everything the model can potentially do. OpenAI
For cybersecurity students and professionals, the interesting question is no longer whether AI will become part of cybersecurity.
It already has.
The question is how much of the security workflow eventually gets handed to AI systems—and how defenders adapt when attackers have access to increasingly capable AI as well.
OpenAI classifies Astra as reaching its Critical cybersecurity capability threshold under its Preparedness Framework. According to OpenAI's evaluations, Astra can identify previously unknown vulnerabilities and, under certain conditions, develop ways of exploiting vulnerabilities in hardened systems. OpenAI
During evaluation, Astra reportedly discovered and used two previously unknown zero-day vulnerabilities, which OpenAI says were disclosed to the affected maintainers. OpenAI
That capability cuts both ways.
For defenders, increasingly capable AI could assist with secure code review, vulnerability discovery, patch development, malware analysis, detection engineering, and analyzing enormous amounts of security information much faster than a human could do manually.
The same capabilities obviously create security concerns if they're misused. That's why access to advanced offensive cybersecurity capabilities is restricted and monitored rather than simply exposing everything the model can potentially do. OpenAI
For cybersecurity students and professionals, the interesting question is no longer whether AI will become part of cybersecurity.
It already has.
The question is how much of the security workflow eventually gets handed to AI systems—and how defenders adapt when attackers have access to increasingly capable AI as well.