San Francisco, August 8, 2026

The US company OpenAI is partially restricting the release of new AI models when, according to its own safety policy, they are capable of independently identifying zero-day vulnerabilities or carrying out complex cyberattacks on high-security targets.

The provision is part of internal safety guidelines that OpenAI applies to its model families. Under these, a model is classified as critical as soon as it can independently find and exploit serious software vulnerabilities or carry out coordinated attacks on well-secured infrastructures. In such cases, the company intends to no longer release certain versions in full or to release them only in restricted form.

Background: When is a model considered critical?