OpenAI’s safety review for GPT-6 Astra says the model reaches the company’s Critical cybersecurity capability threshold. The statement appears in the GPT-6 Astra safety card, which was published as part of OpenAI’s deployment documentation.

The classification matters because OpenAI’s Preparedness Framework uses capability thresholds to determine when stronger protections are needed. Reaching a threshold is not a statement that the model will cause harm. It is a signal that the model’s capabilities require additional safeguards and closer monitoring.
OpenAI says GPT-6 Astra ships with stronger safeguards for cyber-related use. Those safeguards are intended to limit harmful assistance while preserving legitimate work such as defensive security research, code review and incident response. The company’s document describes the controls and evaluations, but it does not present them as a complete solution to every risk.
Cybersecurity is a difficult area for any general-purpose model. The same technical knowledge can help a security team find a weakness or help an attacker exploit one. A safe deployment therefore depends on the model’s behaviour, the product controls around it and the judgment of the person using the system.
OpenAI’s review also carries an important limitation. The absence of a harmful result in testing does not prove that a model will never produce one. Evaluations cover defined scenarios, while real-world prompts can be more varied. That is why the safety card treats monitoring and continued testing as part of the deployment process.
For organisations, the practical message is to keep access controlled and maintain normal security procedures. A model should not receive unrestricted authority over production systems simply because it can understand code or operate tools. Logs, approval steps and human review remain necessary when an AI system is used in sensitive environments.
GPT-6 Astra’s safety documentation shows how frontier AI releases are now being assessed against capability-based risk thresholds. The model’s cybersecurity status is significant, but the review is equally clear about uncertainty. OpenAI’s safeguards reduce risk; they do not remove the need for responsible use, testing and oversight.


