Zero Day
5 min read

OpenAI Just Called Its Zero-Day-Finding AI “Critical.” Defenders Should Too.

Published on
September 9, 2026
An AI model rendered as a glowing node network traces an exploit path across a grid of servers, through a shield barrier, to a server highlighted red as critical

By Viral Trivedi, Director of Solution Engineering and Customer Success, Tuskira

On September 1, OpenAI disclosed that Astra is the first model to meet the “Critical” cybersecurity capability threshold under its Preparedness Framework. In OpenAI’s words, with the right tools and access, the model can find previously unknown security flaws and develop ways to exploit them without a person guiding each step. During evaluation it discovered and used two zero-day vulnerabilities as part of an exploit chain, which OpenAI is now disclosing to the maintainers.

The model itself is shipping. The advanced cybersecurity workflows are not, at least not broadly: those go first to a group of testers, with access expanding later through OpenAI’s Daybreak Blue program for defensive use, while the company builds out monitoring for cyber misuse and unauthorized model actions.

That is the part security leaders should sit with. A frontier lab assessed its own model, concluded it can find and exploit previously unknown vulnerabilities with limited human guidance, and slowed access because the operational controls had to catch up.

Why the gating matters more than the discovery

AI-assisted vulnerability research isn’t new. What’s new is a lab formally classifying its own system as having crossed an offensive threshold, in writing, under a framework built for exactly this moment. That’s a different signal than a research paper or a red-team demo. It’s OpenAI telling the market: this capability is real, it’s here now, and we don’t yet have monitoring mature enough to hand it out broadly.

Access-gating is a real safeguard today. It buys time. It is not, on its own, a plan for what happens when the next lab ships a model at or past this line, and one will.

What this does to mean-time-to-exploit

For roughly 25 years, the SOC’s job has effectively been to out-detect a human-paced adversary: find the intrusion, understand the blast radius, respond, faster than the attacker can act. That model assumes exploitation still runs on human timelines. Research, weaponization, deployment, each step taking days or weeks a defender can work inside of.

Astra breaks that assumption at the research and weaponization steps. If a frontier model can find an unknown vulnerability and build a working exploit for it faster than most security teams can patch a known one, mean-time-to-exploit compresses in a way patch cadence and manual triage were never built to match.

The backlog model breaks with it. “Critical but not yet exploited” stops being a comfort the moment exploitation itself runs at machine speed. That gap doesn’t close because one lab restricted access. It closes when defenders can see, continuously, which of their own exposures would actually be reachable and exploitable if a model like Astra came looking, and shrink that surface before the model has to be right even once.

The takeaway

OpenAI’s disclosure is honest, and the restraint is the responsible call. But gating access to the model that can do this is a stopgap while the industry works out what “critical” means operationally, not a substitute for it.

In that world, exposure management cannot be a periodic scan or a spreadsheet of theoretical CVEs. It has to become continuous proof of what is reachable, exploitable, and worth fixing first. The organizations that will handle this well are the ones that already know which of their systems are exploitable today, without needing a frontier model to find out first.

See how Tuskira validates what is actually reachable and exploitable before attackers do →

Sources: Path to Astra: critical capabilities and frontier safeguards (OpenAI) · OpenAI to limit access to Astra’s most powerful cyber capabilities (Axios) · OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days (SecurityWeek) · OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI (Security Affairs)