OpenAI's new model is too good at hacking to switch on by default
GPT-6 Astra is the first OpenAI model rated ‘Critical’ for cyber risk, and enterprise admins have to opt in to use it.

OpenAI released GPT-6 Astra, its new flagship, on September 4. It's the first model the company has classified as reaching the ‘Critical’ cybersecurity level under its own risk framework. That means it can materially help find and exploit software vulnerabilities.
What happened
In pre-launch testing, the model found previously unknown vulnerabilities. For business customers, Astra ships switched off by default, so an administrator has to enable it deliberately. OpenAI's most advanced cyber capabilities are reserved for vetted defenders through a separate access programme.
Why it matters
Attackers' costs just dropped again. Finding an exploitable weakness used to need a skilled specialist and weeks of time. It now needs a capable model and a good prompt. The same tools help defenders, but only if defenders actually use them.
What it means for your business
Treat AI-assisted security testing as a baseline, not a luxury. That means scanning your own code and infrastructure before someone else does. Also decide who in your organisation can switch on frontier models, and log what they use them for.
Sources: CSO Online, Metacurity, Quartz (Sep 3–4)