OpenAI’s Astra ‘Critical’ rating clouds Microsoft rollout
OpenAI’s Astra received a ‘Critical’ rating after finding new vulnerabilities and building exploit chains, prompting access limits and rollout delays that may slow Azure and Copilot deployments.
On Sept. 1 OpenAI classified its Astra model as ‘Critical’ under the company’s Preparedness Framework after internal testing found previously unknown security flaws and produced working exploit chains. OpenAI reported that Astra built a browser‑compromise chain that escaped a sandbox and identified weaknesses in a hardened operating system, and described the model as a significant advance over GPT‑5.6 Sol for cybersecurity tasks.
OpenAI tightened controls in response. Advanced cyber functionality will initially be available only to a limited group, some development work was paused while protections were strengthened, and monitoring systems can interrupt activity deemed risky. OpenAI acknowledged those safeguards could create additional friction at launch.
Microsoft and OpenAI operate under an amended April agreement that keeps Microsoft as OpenAI’s primary cloud partner, grants Microsoft model and product IP rights through 2032 and continues revenue‑sharing payments through 2030. Because of that commercial and technical relationship, the pace at which OpenAI rolls out highly capable models can affect Microsoft’s ability to deploy them in Azure services and in Copilot products.
Analysts offered differing assessments of the implications. KeyBanc analyst Jackson Ader raised concerns about dependence risk from Microsoft’s close partnership with OpenAI. Bank of America analyst Tal Liani raised his Microsoft price target to $600 and maintained a Buy rating, noting Microsoft can reserve the largest models for complex tasks while using smaller, cheaper models for high‑volume workloads and combining internal models with external ones. D.A. Davidson analyst Gil Luria said enterprises need an orchestration layer above frontier models to switch providers and route work by cost, performance and risk, referring to Copilot as that orchestration layer.
If Astra remains restricted, Microsoft can host the model in environments that justify extra controls and compliance measures while routing routine or high‑volume workloads to smaller or in‑house models. A model‑agnostic routing strategy would let companies allocate tasks based on sensitivity, cost and latency rather than relying on a single provider for all workloads.
OpenAI’s restrictions on Astra also reflect growing enterprise demand for governance and control. Companies may require software that decides which model can access sensitive data, what actions an autonomous agent may perform and when a safer or more auditable model should replace a more powerful one. Those decision layers could affect demand for Copilot’s management and control tools.
Some analysts note that Wall Street has priced faster AI monetization into Microsoft’s outlook; if leading models need tighter access, heavier monitoring or slower rollouts, anticipated revenue from Azure and Copilot could take longer to materialize. OpenAI stated Astra will not be released widely at once and that the tighter safeguards aim to reduce misuse while enabling uses such as cybersecurity research and automated coding.
Astra is the first model to receive the ‘Critical’ designation under OpenAI’s Preparedness Framework.








