Skip to main content
Submitted by admin on
Aggregate 核验溯源
Body

OpenAI says its upcoming Astra model is the first to meet its “Critical” cybersecurity threshold.

The artificial intelligence (AI) startup noted this development in a blog post Tuesday (Sept. 1) after spending the last few weeks testing Astra’s capabilities.

“We now believe Astra meets the Critical cybersecurity capability threshold under our Preparedness Framework, meaning that with the right tools and access, it can find previously unknown security flaws and develop ways to exploit them across many well-protected systems without a person guiding each step,” OpenAI’s blog post said.

In the last several weeks, OpenAI added, the company has delayed Astra’s development and launch as it bolstered and tested safeguards against “cyber misuse and unauthorized model actions.”

The news comes at a time when OpenAI’s security practices are in the spotlight following an incident in which the company’s models breached the AI platform Hugging Face.

OpenAI said at the time that the company viewed the breach as “an unprecedented cyber incident, involving state-of-the-art cyber capabilities.” Days later, both Meta and Anthropic reported similar hacks by their AI models.

“While Astra was not involved in the Hugging Face incident, we have incorporated our learnings from that incident into our safety approach,” OpenAI said. 

“Based on retrospective testing, we believe our production safeguards at the time would have prevented the Hugging Face incident.” 

The company added that it has since established stronger safeguards for Astra, including training it to “more reliably refuse harmful cyber requests and respect safety restrictions.”

OpenAI plans to make the model available soon, while placing limits on access to its most advanced cybersecurity capabilities.

PYMNTS wrote last week about the “underlying corporate vulnerability” exposed by incidents like the Hugging Face breach. 

“Companies have built interconnected enterprises. Their incident-response models still largely assume discrete incidents,” that report said.

That interconnection involves a network of cloud environments, APIs, SaaS applications, payment systems, data platforms, suppliers and customers. 

That in turn means “every system an autonomous process touches can potentially bring another customer agreement, regulator, insurer, jurisdiction, disclosure requirement or business dependency into an incident,” PYMNTS wrote.

The report also cited research from PYMNTS Intelligence’s “Vendors and Vulnerabilities: The Cyberattack Squeeze on Mid-Market Firms,” which found that hackers are increasingly targeting middle market companies. 

“These companies depend on third-party cloud providers, software-as-a-service platforms and managed service providers, which can leave them exposed,” the report added.

The post OpenAI Says New Model Meets Its ‘Critical’ Cybersecurity Threshold appeared first on PYMNTS.com.

Domain Tag
fintech
Source Name
PYMNTS