OpenAI's New GPT-6 Astra Can Hunt Exploits at Expert Level — Here's What SMBs Need to Know
OpenAI has officially released GPT-6 Astra, calling it its most intelligent and well-aligned model to date. The announcement follows OpenAI's own assessment that the model has reached the 'Critical' cybersecurity capability threshold under its internal Preparedness Framework — a designation reserved for AI systems capable of significantly amplifying both offensive and defensive cyber operations. As part of this, OpenAI says it is now blocking requests that ask the model to generate proof-of-concept exploit code.
The milestone reflects a broader trend: AI models are becoming highly capable at tasks like vulnerability discovery, software analysis, and automated exploitation research — skills that were once the domain of specialist security researchers. While this can help defenders find and fix flaws faster, it also lowers the bar for less-skilled attackers who might attempt to misuse similar capabilities, either through this model or others that lack the same safeguards.
For small and medium businesses, the direct risk isn't that GPT-6 Astra will be used against them specifically — OpenAI has built in restrictions — but that the pace of AI-assisted attack tool development is accelerating industry-wide. Attackers are increasingly using AI to speed up reconnaissance, phishing content creation, and vulnerability research, meaning the window between a flaw being discovered and being exploited is shrinking.