OpenAI has disclosed that it temporarily slowed development of its most advanced models after determining that an upcoming system, codenamed Astra, may meet the "Critical" cybersecurity capability threshold under the company's Preparedness Framework.

The company said the decision followed two developments: the previously disclosed OpenAI-Hugging Face security incident, and preliminary evidence about Astra's cyber capabilities. As a result, OpenAI paused reinforcement learning training on models nearing deployment for two weeks while it strengthened monitoring and security controls in its research environments. Its largest planned frontier training run remains on hold while smaller-scale testing continues.

OpenAI said its approach to developing more capable models rests on three reinforcing safeguards: monitoring, to detect and respond to concerning behaviour; alignment, to reduce the likelihood of harmful or unauthorised actions; and security measures, to limit what AI systems can access or affect. The company said it expects models to soon take on most security work themselves, including defending against other models, allowing all three safeguards to scale alongside model capability.

Following the Hugging Face incident, OpenAI paused frontier model inference across research clusters for any workloads capable of executing code or accessing the internet, before restoring a more limited, secured path and reviewing individual workloads case by case. New requirements introduced since then include stronger isolation for workloads handling untrusted or model-generated code, tighter network controls designed so that a single compromised workload cannot independently reach the internet or internal systems, and continuous automated testing against simulated attacks. The strictest controls now apply to Astra and other cyber-related workloads, and some Astra-related work remains paused until it meets the new security standards.

OpenAI has also expanded its monitoring systems, introducing a multistage setup that inspects model activity at every sampled token and escalates concerns to automated investigators, with alerts aimed at reaching human safety and security teams within 30 minutes. The company estimates this monitoring adds roughly 20 percent to the compute cost of the workloads involved. OpenAI said it is applying additional alignment techniques throughout training on its most capable models and plans to publish further detail on both its monitoring systems and alignment research in the near future.

Looking ahead, OpenAI said it intends to evolve its Preparedness Framework to bring these safeguards together across training and deployment, and to involve external organisations as its approach develops.


AI Contracts Decoded: What Fortune 500 Legal Veterans Know That You Don’t
When Microsoft refuses to negotiate indemnification with their biggest customers, what does that mean for your AI vendor contracts? When IBM data shows 97% of AI breaches stem from compliance failures—most being supply chain-related—who holds liability? When employees download shadow AI tools with zero cybersecurity controls, what recourse does your company have? None. Cathy Mulrow-Peattie brings perspective most outside counsel lack: Fortune 500 in-house experience at MasterCard and Omnicom, General Counsel at an AI startup, now advising enterprises. She starts with business goals before technology, technology before contracts—because she’s been in the hot seat when governance fails. You’ll learn: • Why 10-year AI contracts create risk and 90-day pilots with exit strategies are essential • The IP paradox: machine-generated outputs aren’t copyrightable but terms of use matter • How LLM providers retain “certain uses” of your data and when private instances become mandatory • Why contractual risk allocation to key vendors is your only viable strategy Key topics: Supply chain due diligence • The 97% compliance failure rate • Shadow AI liability traps • Benchmarking gaps • Hallucination disclaimers • GDPR/CCPA requirements • NY DFS Part 500 • Acceptable use policies • Dark web data sourcing • Evolutionary AI governance For: CISOs, CIOs, Chief Legal Officers, and compliance leaders navigating AI vendor relationships Contractual realities from someone who’s negotiated with Microsoft, advised Fortune 500s, and managed governance failures.
Share this post
The link has been copied!