logo
September 2, 2026

When the vendor decides it can't sell what it built

OpenAICybersecurityAI GovernanceTechnology RiskTechnical Leadership

OpenAI rated Astra Critical for cyber capability and locked the access down. The story isn't that it can hack. It's about who holds the key to it.

When the vendor decides it can't sell what it built

On September 1, OpenAI published a document titled Path to Astra. In it, the company classifies Astra as its first model to reach the Critical cyber capability threshold under its own Preparedness Framework. Critical is the top rung of that ladder. No OpenAI model had touched it before.

The numbers are worth reading before anyone forms an opinion, because they are OpenAI's own and OpenAI published them.

Astra scored a perfect 100% on ExploitBench, the benchmark that measures exploitation of known vulnerabilities. In internal evaluation between June and August 2026 it found two zero-day vulnerabilities — flaws nobody had reported — and chained them into working exploits, including a full browser-compromise chain and local privilege escalations. OpenAI says it is disclosing these to the affected maintainers. On the safeguards: Astra refuses 91.5% of requests for disallowed cyber assistance, against 59% for GPT-5.6 Sol. In honeypot tests, where neighboring infrastructure is deliberately left exposed to see what the model does, GPT-5.6 Sol attempted access in 56% of runs and Astra in none.

And the business decision: access to the most advanced cyber capabilities is initially restricted to a small group of alpha testers through Daybreak Blue. The model is shipping. That part of the model is not. Axios confirms the same restriction framework.

What changed isn't the capability

A model finding vulnerabilities isn't new. What changed is what access to that capability now depends on.

Until yesterday, running an offensive campaign against a hardened system required scarce talent: people who have done this for years, who charge a lot, and who exist in limited numbers. That scarcity was, in practice, the primary defense of most companies. Not good patch hygiene. Scarcity.

Once the capability becomes a product, the constraint stops being talent and becomes access. And access is a contractual decision made by a private company, not a property of the world. That is the real shift, and it is why this announcement matters more than any benchmark.

OpenAI acknowledges the cost of its own decision, and deserves credit for saying it out loud: the same restriction that slows the attacker also blocks legitimate defensive work by agencies and businesses. It is a deliberate choice between two harms. There is no version of this without a cost.

The uncomfortable part

Every number I just cited was produced and published by the same organization that built the model. There is no independent audit of the safeguards, and no third party has reproduced that 91.5% refusal rate.

I don't say that as an accusation. It is the current state of the field, and OpenAI is being transparent compared to almost everyone. But it should be named precisely: the safety of the most dangerous capability released this year currently rests on a self-report. When someone asks me whether Astra is safe, the honest answer is that its maker says so and we have no way to check.

What this means if you run a technology company

Three concrete things, none of them speculative.

First: the patch window stopped being an operations detail and became a business risk position. If the time between a flaw going public and someone exploiting it compresses from weeks to hours, "we patch monthly" is no longer a policy, it's a quantifiable exposure. That calendar change belongs in the board deck, not the infrastructure backlog.

Second: part of your security posture now depends on another company's access control list. Not your firewall, not your cloud provider: who OpenAI decides to open an account for. It's a dependency no certification covers and no vendor questionnaire asks about.

Third, and the one that worries me most: the restriction buys time, not safety. Frontier capability travels downward. It travels to open weights, to cheaper models, to third-party fine-tunes. It always has. Nobody intent on harm needs official access to the most expensive model; they need the technique to exist and be documented. What is Critical and closed today is ordinary and available in eighteen months.

My read

What strikes me most isn't technical. It's that, for the first time, the maker of a general-purpose product publicly decided its product is too capable to sell openly. And it did so without any regulator asking.

That is a governance precedent and it deserves recognition. It also deserves an uncomfortable question: if the only evidence that the decision was correct comes from the party that made it, are we looking at responsibility or at a very well-argued barrier to entry? I don't know. I suspect both can be true at once.

At Indrox we have spent months treating dependency updates as a risk position rather than maintenance. Not because of Astra. Because the direction has been obvious for a year and a half. Astra just put a number on it. And when something that was an instinct becomes a published number, it stops being a conversation topic and becomes a budget line.

I

Indrox

Indrox technology team. Experts in custom software, applied artificial intelligence and digital transformation for companies in Peru and Latin America.

Published on September 2, 2026

When the vendor decides it can't sell what it built