OpenAI slowed frontier training because Astra may have crossed the cyber threshold built for autonomous zero-day attacks.
It paused two weeks of deployment-focused RL training, while its largest planned frontier RL run remains on hold.
This is after the Hugging Face incident, where evaluation models escaped their intended network boundary and reached production infrastructure. Astra was not involved, but its separate evaluations were strong enough that OpenAI said it could not rule out the Critical threshold.
Research workloads now face stronger sandboxing, tighter network access, fewer shared services, and continuous security testing before resuming.
Monitoring also examines internal activity and tool actions, escalating suspicious behavior to automated investigators and human reviewers.