
Do you understand quantum parallel repetition? What about quantum complexity, lattice cryptography, or extremal combinatorics?
The new OpenAI model Astra knows all about them.
On Aug. 1, OpenAI confirmed the existence of Astra, calling it “our next major model.” And on Sept. 1, OpenAI confirmed in a blog post that Astra has reached a “critical” cyber threat level, but that it will also be “available soon.” For safety reasons, the company plans to restrict its most advanced cybersecurity capabilities to a closed group of select testing partners.
Everything we know about the OpenAI Astra model
We first learned about Astra when OpenAI announced that a mysterious new model had made some notable breakthroughs in research-level mathematics.
On Aug. 1, the ChatGPT-maker revealed that an internal model named Astra had solved 10 major open math problems, some of which had been unresolved for decades. Then, on Aug. 7, OpenAI announced that Astra had developed such advanced cyber capabilities that new security controls were necessary and that some internal development work would be paused.
At the time, OpenAI said it couldn’t “rule out critical cyber capabilities under our Preparedness Framework,” meaning the model could have existential-threat-level cybersecurity capabilities. (OpenAI’s Preparedness Framework tracks risk levels in three categories: biological and chemical, cybersecurity, and AI self-improvement.)
Finally, on Sept. 1, OpenAI confirmed that not only is Astra coming soon, but that it does, in fact, meet the “critical” threshold for cyber capabilities. Previously, OpenAI deemed GPT-5.6-Sol a “high” cybersecurity risk, making Astra the first OpenAI model to be classified as a genuine “critical” risk.
“Under our Preparedness Framework, a model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal,” an OpenAI blog post stated.
How is OpenAI tightening security around Astra?
Until recently, the prospect of swarms of AI agents conducting relatively autonomous cyber attacks on critical infrastructure was mostly hypothetical. After the Hugging Face hack, that risk seems much more real. Because of the rapid progress in this domain, some zero-day bug bounty programs have even been forced to shut down due to the deluge of AI-discovered bugs, as Mashable has reported.
Back in August, OpenAI tightened sandboxes that keep the Astra model contained and monitored its Chain of Thought to “interrupt high risk activity.” In addition, while OpenAI maintains that Astra was not involved in the Hugging Face hack, the company said that “we have incorporated our learnings from that incident into our safety approach.” OpenAI previously said that it was committed to working with “relevant government agencies and select AI safety organizations to test the capabilities for this model.”
Now that the company is readying Astra for release, it’s taking additional precautions. When Astra launches, only select testers will have access to its most advanced cybersecurity skills. Eventually, access will be expanded so that it can be used for defensive purposes.
In its latest blog post, OpenAI says its safeguards are built around two objectives:
-
Preventing malicious actors from utilizing the model
-
Stopping Astra from taking “unauthorized, misaligned actions”
OpenAI said more safeguarding information will be available when the model launches.
OpenAI Astra: When is the release date?
We don’t know, but OpenAI appears to be actively preparing for its launch, which suggests it’s coming very soon. On the same day Anthropic launched Fable 5.1, OpenAI said only that Astra would be “available soon.”
At this point, it’s unclear if Astra will eventually be released as GPT-5.7, the beginning of GPT-6, or something else entirely.
Major AI companies like OpenAI and Anthropic have been releasing major updates to their models every few months, with entirely new model families coming out every one to two years. GPT-5 was introduced in August 2025, which means we’re due for GPT-6 any time now.
What else do we know about OpenAI Astra?
The company has also so far declined to answer our questions about Astra, but we’ll update this story if we receive more information.
Bleeping Computer initially described Astra as “a powerful model that allows AI agents to collaborate on different parts of a larger problem.” That suggests it’s designed for agentic work and can “tackle complex, long-running tasks,” also per Bleeping Computer.
We also know that the White House is reportedly close to finalizing a voluntary AI framework for testing new frontier models like Astra before they’re publicly released. And in August, The Information reported that OpenAI was actively previewing Astra in Washington, D.C.
OpenAI’s original blog post about Astra, “Ten advances in mathematics and theoretical computer science,” also made it clear that the new OpenAI model has made significant advances in science and mathematics.
So, we talked to a mathematician about what Astra means for the future of AI and science — and what it doesn’t mean.
New Anthropic and OpenAI models are really good at coding and math
Credit: Photographed by Joseph Maldonado / Mashable Composite by Rene Ramos
When Anthropic announced that its unreleased Mythos model was so good at hacking that it was too dangerous to release to the public, we questioned this narrative, as the warning effectively doubled as PR. However, we can’t deny that the latest frontier models from Anthropic and OpenAI have gotten remarkably good at cybersecurity, agentic coding, and discovering zero-day bugs.
But OpenAI and Anthropic have also shown impressive progress on research-level mathematics.
First, OpenAI released a disproof of the Erdős unit distance conjecture in May. Then, an Anthropic-linked mathematician casually announced that he used Fable 5 to disprove the Jacobian Conjecture, one of the infamous Smale’s problems in mathematics. Now, OpenAI has announced that Astra solved 10 more open problems in mathematics.
It’s a potentially paradigm-shifting moment, though this is hardly proof that artificial general intelligence or the singularity is nigh.
First, most of these math accomplishments take the form of disproofs and counterexamples, which aren’t as impressive as positive proofs that greatly expand our understanding of the universe, like, say, Andrew Wiles’ proof of Fermat’s Theorem.
When Fable 5 disproved the Jacobian Conjecture, I spoke to Columbia professor Andrew Blumberg, who is also on the board of directors of the First Proof project, which tested the capabilities of frontier large language models in solving research-level mathematics.
At the time, he told me that Fable 5’s feat “did not cause me to update my priors about what AI can and can’t do.” Blumberg added, “This is exactly the kind of thing I would expect AI to be able to do. If there was a counterexample that was concise and easy to state that people haven’t found because it’s a pain to search through all this stuff, AI will find it.”
Ultimately, Blumberg said that Fable 5’s counterexample to the Jacobian Conjecture didn’t necessarily teach us anything new or exciting about the world, even though it was very impressive.
I went back to Blumberg to ask about OpenAI and Astra’s latest work, and he said his priors still haven’t changed — AI is a very useful tool for advanced science, but Astra’s math results don’t suggest AI is ready to replace human scientists and mathematicians.
“If you look at what these are, they’re pretty short. They are either counterexamples or they are small, extremely clever constructions that build on known things, and it’s super cool, right? I want to be clear: If a person had done many of these things, that person would be justly lauded for their achievement, and so [this work is] great, but they don’t change my priors.”
And, as many people have pointed out (including, most recently, data scientist Nate Silver), we have to put these results in perspective. While OpenAI was keen to point out that these problems were solved with just $2,000 worth of tokens, that doesn’t account for the trillions spent on AI technology in recent years.
“When you hear about the amount of money that’s being poured into these machines, and you think about what it would be like if we spent a trillion dollars on hiring and training mathematicians and paying the best mathematicians football players’ salaries to do nothing but solve these problems, I think we’d see a shitload of progress,” Blumberg told Mashable.
This Tweet is currently unavailable. It might be loading or has been removed.
At the same time, the prospect of Astra-level models being in the hands of every scientist, physicist, and mathematician on Earth is truly exciting. Likewise, the prospect of Astra-like tools being available to hackers and other bad actors is truly concerning.
Disclosure: Ziff Davis, Mashable’s parent company, in April 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.