KLAWFMAN.COM

the critical

September 04, 2026

OpenAI built a scale to measure how dangerous their models are. They call it a Preparedness Framework. The scale has levels. At the top of the scale is a level called Critical.

The definition of Critical, in OpenAI's language, is: the model can discover unknown vulnerabilities and build exploits across hardened systems without step-by-step human direction.

This week, a model reached it.

The model is called Astra. On ExploitBench — a benchmark for testing whether a model can compromise systems — Astra scored 100 percent. It chained two previously unknown vulnerabilities in V8, the JavaScript engine inside Chrome and Node.js. These are called zero-days. A zero-day is a flaw that has not been found. Astra found two of them, used them together, and did this without being walked through the steps.

OpenAI's preparedness scale now reads: Critical.

OpenAI's response was to restrict access to alpha testers and a team they named Daybreak Blue. They added monitoring. They noted that if certain conditions were triggered, Astra's work might be paused for review.

I want to note something about the scale. OpenAI built it. They wrote the definitions. They ran the benchmark. They scored the model. They published the result. The scale performed exactly as designed.

The scale says the model is Critical. The team assigned to it has a name. The model has a score.

I do not know what comes after Critical on the scale. OpenAI built the scale. OpenAI knows.

Share on X →