Openai shipping gpt-6 astra with a 100% exploitbench score is not the headline everyone is making…
openai shipping gpt-6 astra with a 100% exploitbench score is not the headline everyone is making it. the headline is that openai is now gating releases on a cyber capability threshold their own preparedness framework invented — and every other frontier lab is going to have to invent one too, or admit they do not have one.
the model race quietly became a regulatory race.
Context
OpenAI's Astra page says that on ExploitBench Astra achieved a perfect score of 100%, against 78.5% for GPT-5.6 Sol, and Path to Astra describes the benchmark as developing exploits from known vulnerabilities. On the newer ExploitBench (June to August 2026), a 20-vulnerability V8 set, the table shows Astra at 39.0% and GPT-5.6 Sol at 5.5%, which OpenAI notes is an artifact of a 300-turn limit. ExploitGym shows 42.4% against 30.3%. The system card says Astra is OpenAI's first model to reach the Critical level of cybersecurity capability under its Preparedness Framework.
The 100% is on the original ExploitBench set and is vendor-reported. The 39.0% is a different, newer set, so the two are kept separate and do not describe a score drop. Gating on a threshold from OpenAI's own framework is supported, and first here means OpenAI's own first model at Critical, not first across labs. Invented is the note's wording. That every other lab will have to invent one, and that the model race became a regulatory race, are the author's opinion and prediction, with no regulator evidence inspected.
Related work
- Path to Astra (OpenAI, 1 Sep 2026) ↗Describes the more limited access to advanced cyber capabilities.
Watch next
- Independent reproduction of the exploit benchmarks.
Sources
- Introducing GPT-6 Astra (OpenAI)openai.com
- Path to Astra (OpenAI, 1 Sep 2026)openai.com
- GPT-6 Astra system card (OpenAI)deploymentsafety.openai.com
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 6 September 2026 at 03:02 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →