Frontier AI crosses the “Critical” cyber line

OpenAI rated GPT-6 Astra “Critical” for cyber capability and released it broadly. It is the first OpenAI model to reach that level. Nineteen days later, Anthropic shipped Opus 5.5 with most cybersecurity tasks rerouted to an older model.

Down: Critical
GPT-6 Astra · cyber rating
$10/$50
Astra · per M tokens
$4/$20
Opus 5.5 · per M tokens
Sep 22
Opus 5.5 released

OpenAI’s GPT-6 Astra system card, published September 3, says the model “is a significant step up in cyber capabilities and meets our Critical threshold.” It is the first OpenAI model to reach that threshold. OpenAI explains what that means: “With the right tools and access, GPT-6 Astra can find previously unknown security flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step.” The model nonetheless rolled out broadly to paid ChatGPT plans, the API, and Amazon Bedrock. It costs $10 per million input tokens and $50 per million output.

On September 22 Anthropic released Claude Opus 5.5, which it says “performs at the level of Claude Fable 5.1 on most work and costs 40% less to run than Opus 5,” at $4 and $20 per million tokens. Because the model “has extremely strong cyber capabilities,” Anthropic applied safeguards under which routine bug-fixing still works, “but most cybersecurity tasks will be re-routed to Opus 4.8.” Vetted defenders get a separate path through an expanded Cyber Verification Program.

Two risks, one month

The first risk is on the threat side. Autonomous discovery and exploitation of unknown flaws is now a commercial capability, with the labs’ safeguards as the main brake on misuse. For a community bank, the exposed surface is mostly someone else’s code, such as the core, the online-banking platform and the payment processor. That makes a provider’s patch cadence and incident transparency a first-order control.

The second is on the vendor side. Safeguard routing means the model a vendor contracts for is not always the model that answers. By design, some requests go to a different, older model. Enterprise access is also a configuration decision, because ChatGPT Enterprise administrators must switch Astra on for their organizations. A vendor attestation that names one model and one version no longer describes what actually runs.

When the model can find the zero-day, the question for your vendors is no longer whether they use AI. The question is how fast they patch, and how fast they tell you.
What this means for your bank
  • Ask core and digital-banking providers for their patch-cadence commitments and incident-notice timelines in writing. The new core-provider statement supports the request.
  • Update AI-vendor attestations to cover routing. They should say which models may serve your requests, under what conditions, and how you are told when that changes.
  • Add AI-accelerated vulnerability discovery to your cyber risk assessment and tabletop scenarios this quarter.
From Zovos AI

Zovos records the model, version, and routing disclosures behind every AI feature in your vendor stack, and opens a review when a provider’s release changes them.

Sources

This is for information only and is not legal or investment advice. Verify all figures against the linked primary sources before acting.