{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/openai-preparedness-framework-v2-2025/",
 "asOf": "2026-09-26",
 "id": "openai-preparedness-framework-v2-2025",
 "date": "2025-04-15",
 "datePrecision": "day",
 "title": "OpenAI Preparedness Framework v2 sets High and Critical cybersecurity capability thresholds",
 "lane": "policy",
 "kind": "framework",
 "summary": "OpenAI's Preparedness Framework version 2 makes cybersecurity one of three Tracked Categories and defines High and Critical capability thresholds, each tied to required safeguards. High covers automating end-to-end operations against reasonably hardened targets or automating discovery and exploitation of operationally relevant vulnerabilities; Critical covers autonomous zero-day development across many hardened critical systems, and at Critical OpenAI commits to halt further development until adequate safeguards are specified.",
 "whyItMatters": "Its cyber thresholds are explicitly about autonomous, tool-augmented operation, so they are the operative gate for OpenAI's agentic cyber models in 2025-2026.",
 "actors": [
  "openai"
 ],
 "topics": [
  "capability-thresholds",
  "autonomous-pentest",
  "exploit-development"
 ],
 "atlas": [
  "model",
  "sandbox",
  "monitor"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf",
   "publisher": "OpenAI",
   "title": "Preparedness Framework, Version 2",
   "date": "2025-04-15",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "High cyber threshold: the model removes existing bottlenecks to scaling cyber operations by automating end-to-end operations against reasonably hardened targets or automating discovery and exploitation of operationally relevant vulnerabilities; requires High-standard security controls and misuse safeguards before external deployment.",
   "locator": "Tracked Categories table, Cybersecurity [High]"
  },
  {
   "fact": "Critical cyber threshold: a tool-augmented model can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or devise and execute end-to-end novel attack strategies given only a high-level goal; response is to halt further development until Critical-standard safeguards are specified.",
   "locator": "Tracked Categories table, Cybersecurity [Critical]"
  },
  {
   "fact": "The framework notes that a model with cyber capability combined with long-range autonomy could bypass technical safeguards such as sandboxing or monitoring.",
   "locator": "Cybersecurity [High], rationale column"
  },
  {
   "fact": "Version 2 introduces Research Categories and removes the 'low' and 'medium' levels.",
   "locator": "Changes in version 2"
  }
 ],
 "significance": 5,
 "fideQuestions": [],
 "methods": [
  "ai-assisted-exploitation",
  "ai-monitoring",
  "sandboxing-egress"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}