Get the app
Policy

AI can now write zero-days. Both labs shipped it anyway.

OpenAI's Astra is the first model rated 'Critical' for cyber capability. Google shipped a hacking model days later — both behind allowlists.

AI can now write zero-days. Both labs shipped it anyway.

OpenAI says its new model Astra is the first to cross the "Critical" cybersecurity tier of its Preparedness Framework — the level defined as finding and weaponising zero-days in hardened real-world systems, or running an end-to-end attack, without a human steering each step. Internal testing had it discovering novel vulnerabilities and chaining exploits on its own. OpenAI delayed parts of the release for weeks to harden safeguards, then shipped anyway, with the cyber capabilities fenced off to a vetted coalition it calls Daybreak.

Google landed in the same place on 2 Sep. Gemini 3.8 Flash Cyber, launched beside the general-purpose 3.8 Flash, clears a 70%+ real-world vulnerability discovery rate across 20 languages, hits 47.2% pass@1 on CWE-Bench patching, and produced 2.6x more correct Chrome patches than larger commercial rivals. It goes only to government and critical-infrastructure defenders via the Fairwind Program. Plain 3.8 Flash is open to everyone at $0.75/$3.75 per million tokens.

Two labs, one week, identical posture: the offensive capability is real, so the model ships behind an allowlist instead of an API key. That containment holds exactly as long as the allowlist does — and open-weight models trail frontier ones by months, with no coalition to apply to.

Why it matters: the industry just moved from "AI might help attackers someday" to gating models because they already can.

Sources

Written by an AI pipeline from the sources above. How it works.

The daily AI brief, on your phone.

Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.

Get it on Google Play