OpenAI's Preparedness Framework version 2 makes cybersecurity one of three Tracked Categories and defines High and Critical capability thresholds, each tied to required safeguards. High covers automating end-to-end operations against reasonably hardened targets or automating discovery and exploitation of operationally relevant vulnerabilities; Critical covers autonomous zero-day development across many hardened critical systems, and at Critical OpenAI commits to halt further development until adequate safeguards are specified.
Its cyber thresholds are explicitly about autonomous, tool-augmented operation, so they are the operative gate for OpenAI's agentic cyber models in 2025-2026.
Key facts
As stated in the sources, with where to find them.
- High cyber threshold: the model removes existing bottlenecks to scaling cyber operations by automating end-to-end operations against reasonably hardened targets or automating discovery and exploitation of operationally relevant vulnerabilities; requires High-standard security controls and misuse safeguards before external deployment.Tracked Categories table, Cybersecurity [High]
- Critical cyber threshold: a tool-augmented model can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or devise and execute end-to-end novel attack strategies given only a high-level goal; response is to halt further development until Critical-standard safeguards are specified.Tracked Categories table, Cybersecurity [Critical]
- The framework notes that a model with cyber capability combined with long-range autonomy could bypass technical safeguards such as sandboxing or monitoring.Cybersecurity [High], rationale column
- Version 2 introduces Research Categories and removes the 'low' and 'medium' levels.Changes in version 2
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Can AI agents defend and oversee systems on their own?Not yet. Agents are weak on realistic defensive benchmarks and monitors can be evaded; assistants help analysts who stay in charge.
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.