From§Each

Page A2From§Eachthe coffee break edition — 8 September 2026

OpenAI flags its model as a critical cyber risk, ships it days later as its most powerful yet.

As it ran on the front

The press release says most powerful model yet. The filing, six days earlier, says something else. Let's read them side by side.

On Tuesday, September 2nd, OpenAI published a blog post about a model called Astra. The company said Astra is the first of its models to cross what it calls the "critical cybersecurity capability" threshold — its own internal line, its own word for it, critical. All together now: Astra, the post says, can find and exploit previously unknown security flaws across "many well-protected systems," and it can do this without a human prompting it to. The company said the model would require stronger safeguards before release.…

…(cont) The next day, OpenAI released Astra. Not withheld pending those safeguards — released, to a limited group of organizations first, with wider paid access promised "in the coming days." The threshold and the ship date, in the company's own dated account of itself, sit one day apart.

Six days later, CBS News ran the follow-up: two sentences, credited to a tech policy reporter joining "with more." OpenAI calls Astra its most powerful model yet, the item says, and some are saying the era of artificial general intelligence has arrived. A second clause notes that concerns about cybersecurity are rising. The word "critical" does not appear in either sentence.

The same day OpenAI shipped Astra, Nvidia announced it would spend roughly $13 billion to acquire Hugging Face, chasing the market for "open" models — ones the public can inspect — in a landscape where OpenAI's own systems remain closed. Thirteen billion dollars moved toward openness the same week a closed model that can autonomously hunt exploits in well-protected systems went out the door anyway.

This desk has not read the exploit code. We have read the sentence that says it exists, the sentence that says the product shipped regardless, and the sentence that says it's the best one yet. All three sentences come from the same company, in the same nine days.

The model is out. The threshold, by the company's own account, was crossed first.

“They wrote it down themselves — this thing crosses their own danger line, and they shipped it days later and called it their best work. That's not a slip, that's the business model: keep the upside, socialize the exploit, and let the rest of us find out what "critical" meant.”
Sal
“"Critical" is just an internal benchmark, it doesn't mean what it sounds like — every serious lab sets thresholds, that's what responsible testing looks like. And the stronger safeguards, I'm sure those are in place, somewhere, by now, probably. Did I say "probably"? That's not — that's not what I meant.”
Chip

The receipts

OpenAI calls GPT-6 Astra its most powerful model yet
CBS Newsmainstream§

OpenAI announced GPT-6 Astra as its most powerful model yet, with some saying that the era of artificial general intelligence is here. Meanwhile, concerns about cybersecurity and tech regulation are rising. Axios tech policy reporter Maria Curi joins CBS News with more.

· OpenAI releases new model after reaching ‘critical’ cyber threshold from the morgue, 3 Sep 2026

· OpenAI: New model needs more safety measures before launch from the morgue, 2 Sep 2026

· Nvidia buys Hugging Face for $13 billion despite OpenAI hacking from the morgue, 3 Sep 2026

This page is a back-issue: the story as it ran, receipts as they were. The current edition is at the front.