2026-10-11 17:11 UTC

OpenAI will translate its cyber-capability pacing framework into concrete model evaluations, development gates, or release controls as frontier models approach cyber-critical capability thresholds.

state: expiredheat: lowuncertainty: highconvergesscott: highagentic-security cyber-capabilities model-governanceOpenAI

What is this?

OpenAI has outlined a cyber-risk pacing approach under its Preparedness Framework, defining “High” capability as enabling working zero-day remote exploits against hardened systems or materially assisting complex, stealthy intrusions. It says it is preparing safeguards on the assumption that upcoming models may reach that threshold, implying capability evaluations and pre-release controls could govern deployment. Secondary snippets describe restricted access for cyber-specialized models through a vetted-defender program, but they conflict on model names and versions, so those specific releases are not firmly established here.

Why it matters to Scott

OpenAI is independently arriving at the evaluation-driven, evidence-gated development posture that Scott has codified in his Gate Criteria Framework, Earned Autonomy, and Evaluation-Driven Development concepts. This is a consequential institutional articulation of Scott's position by a frontier lab that affects his workflows (OpenAI API user) and his consulting practice (AI readiness assessment against such frameworks). The dated-receipts opportunity is strong: a major lab is adopting the pattern Scott has been building and advocating.
ip:framework.gate-criteria-frameworkip:concept.evaluation-driven-developmentip:concept.earned-autonomyip:concept.capability-scope-separationip:framework.separation-of-powers-for-cognitiondev:project.silo-osdev:concept.recommendation-authority-separationwork:concept.ai-consulting-practiceradar:agent-security-framework-portabilityradar:anthropic-model-2-risk-delayradar:anthropic-claude-autonomous-hacking-testsradar:ai-designed-virus-biosecurity
queries asked of Scott's wikis
  • capability evaluations as model development gates
  • cyber capability thresholds and release controls
  • restricted access for dual-use AI capabilities
  • agentic security evaluation harnesses
  • defender-only deployment and trusted access
  • Preparedness Framework versus responsible scaling policies

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (8) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hn ⭐Pacing model development in an era of cyber-critical capabilitiesj4mie166292
🟧 hnThe Defender's Windownedruod10
🟠 redditOpenAI stopped training its most powerful model this week. Not slowed it down. Stopped it.
artificial
Dapper-Tale-4021023
🟧 hnOpenAI halts frontier RL training after Astra crosses Critical cyber thresholdDarenWatson11
🟧 hnOpenAI Codex adds hidden "Daybreak Blue" and "Daybreak Red" cybersecurity modelsbakigul21
🟧 hnOpenAI Codex Security Quoted in iOS 26.6.1 en iPadOS 26.6.1janandonly20
🟧 hnOpenAI leader warns of threat of 'persistent' AI cyber-attacksgeox20
🟧 hnOpenAI gates cyber defense in 44 ChatGPT markets with a 1996 US export listglub20

Interpretation history

Decision trace