<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/openai-s-astra-paused-for-safety-leaked-anyway-and-priced-like-a-luxury-car-rql9isr7d" -->

---
title: OpenAI&#x27;s Astra: paused for safety, leaked anyway, and...
description: OpenAI reportedly paused training on an internal model codenamed Astra over cited cybersecurity risks, but leaked outputs from a checkpoint labeled...
canonical: https://daily.dev/posts/openai-s-astra-paused-for-safety-leaked-anyway-and-priced-like-a-luxury-car-rql9isr7d
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: OpenAI&#x27;s Astra: paused for safety, leaked anyway, and priced like a luxury car | daily.dev
og:description: OpenAI reportedly paused training on an internal model codenamed Astra over cited cybersecurity risks, but leaked outputs from a checkpoint labeled...
og:url: https://daily.dev/posts/openai-s-astra-paused-for-safety-leaked-anyway-and-priced-like-a-luxury-car-rql9isr7d
og:image: https://api.daily.dev/og/posts/Rql9iSR7d.png
og:image:alt: OpenAI&#x27;s Astra: paused for safety, leaked anyway, and priced like a luxury car
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenAI's Astra: paused for safety, leaked anyway, and priced like a luxury car

**[Trends](https://daily.dev/sources/trends)** · 2 min read · 0 upvotes · 0 comments

## Summary

OpenAI reportedly paused training on an internal model codenamed Astra over cited cybersecurity risks, but leaked outputs from a checkpoint labeled 'mozaik-alpha-fdm' are already circulating on Discord. Leaked architecture details suggest Astra is designed to run continuously for weeks or indefinitely, functioning more like a persistent agent than a traditional app, with a new interface reportedly in development to support it. At a rumored 10 trillion parameters, pricing extrapolated from GPT-5's current rate could land between $66-$100 per million output tokens, pushing it into enterprise-only territory. Skeptics, including one veteran developer, dismiss the safety pause as fear marketing rather than genuine risk management, pointing to an Apple study showing AI models failing on novel benchmarks as a more honest picture of current capabilities.

## Content

OpenAI is about to release Astra, and the headline isn't the benchmark numbers — it's that the model found two previously unknown zero-day vulnerabilities during evaluation and turned them into working exploit chains. Nobody asked for that. It just happened.

The capability numbers are genuinely alarming. Astra scored 100% on ExploitBench, the existing benchmark for autonomous exploitation. That was good enough that OpenAI had to build a harder internal version — 20 high-severity V8 vulnerabilities disclosed more recently — and Astra still outperformed GPT-5.6 Sol by a wide margin on arbitrary code execution. This is why the model hit OpenAI's "Critical" threshold under their Preparedness Framework, which is apparently a real category they have.

Sam Altman's statement is worth reading straight: "Astra has been done training for a while now and is a significant step forward in both capabilities and alignment. For the models after that, we have been slowing things as needed." The subtext is that they've been sitting on this, and the cybersecurity capabilities will be restricted at launch. What exactly gets locked down isn't fully specified.

The technical details leaking out are interesting on their own. Astra reportedly uses "recurrent depth," an architectural choice that has people expecting open-source models to follow. It's also designed to run for weeks continuously, with a version planned that runs indefinitely — what one observer called "the other word for agent employees." OpenAI is apparently building a new interface for these long-running agents that isn't a traditional app.

On pricing: if Astra is the rumored 10T parameter model, rough extrapolation from current GPT-5.6 Sol pricing puts output costs somewhere between $66 and $100 per million tokens. That's not a consumer product.

The skeptic corner exists. One veteran developer is calling the cybersecurity pause "fear-based marketing" in the same category as Y2K panic, arguing the Apple benchmark study shows AI still can't generalize beyond its training distribution. That's a reasonable pushback, but it's doing a lot of work against a model that independently discovered zero-days in a controlled evaluation.

Astra is coming. The question is how much of it actually ships.

## Questions this post answers

### What is OpenAI's Astra model and why was it paused?

Astra is an internal OpenAI model reportedly paused during training due to flagged critical cybersecurity risks. Despite the official pause, leaked outputs from a checkpoint labeled mozaik-alpha-fdm have already circulated via Discord, including image renders described as impressive, undercutting the containment claim. Some developers argue the safety framing is more about narrative control than actual risk management.

_Developers weighing frontier model risk claims can follow verified coverage of Astra's status on daily.dev._

### How much might a 10 trillion parameter OpenAI model cost per million tokens?

Extrapolating from GPT-5's pricing of $20 per million output tokens at an estimated 2-3 trillion parameters, a full 10 trillion parameter model could cost roughly $66 to $100 per million output tokens. That pricing would put it well outside typical developer tool budgets and into enterprise procurement territory rather than everyday API use.

_Teams budgeting for frontier model access can track pricing shifts like this on daily.dev._

### What makes OpenAI's rumored Astra model different from existing agent architectures?

Astra is reportedly designed to run continuously for weeks, with a planned variant intended to run indefinitely, functioning less like a traditional request-response app and more like a persistent background process. OpenAI is said to be building a new interface specifically for these continuously running agents, which critics describe as effectively 'agent employees' rebranded.

_Developers exploring long-running AI agent designs can follow how this architecture unfolds on daily.dev._

## Community take

How the wider developer community reacted, aggregated from 4 discussions and 100 comments across x (as of 2026-09-02).

**TL;DR:** Reactions are dominated by frustration over losing GPT-4o, distrust of Altman's 'safety' framing as PR spin timed against competitors, and scattered skepticism about pricing and release timing, with only a small minority expressing genuine excitement for Astra.

**Sentiment:** 10% positive · 25% mixed · 65% skeptical

**The case for**

- A few express genuine excitement and appreciation for the stated safety-first approach before launch.
- Some see the training-complete-but-delayed-for-safeguards framing as a notable shift toward safety-bottlenecked releases.

**The pushback**

- Many suspect the safety narrative is just marketing spin timed to distract from competitor releases.
- Repeated demands for GPT-4o's return suggest dissatisfaction with newer models replacing it.
- Several question whether 'pacing progress' is a real technical control or just vague messaging.
- Some doubt the cybersecurity threat framing is genuine rather than fear-based hype.
- Concerns raised about who benefits from restricted cybersecurity access and enterprise control over their own data.

**By community**

- x (heated): A chaotic mix of GPT-4o nostalgia complaints, accusations that the safety talk is PR spin, occasional genuine enthusiasm, and general trolling/insults directed at Altman.

**Hottest debate:** Whether the 'safety-first' framing around Astra is a legitimate caution or just convenient marketing timed against competitor launches.

**Open questions**

- What specific cybersecurity capabilities will actually be restricted at launch and how will access be verified?
- When exactly will Astra be released?
- Will enterprises get their own control layer instead of relying on OpenAI's built-in safeguards?

**Highlights**

> @sama The tension gets harder as your competition is releasing better models so you need to come out with a safety note. Hilarious
> — [lt\_trades on x](https://x.com/lt_trades/status/2094948004050395582)

> @sama "Pacing progress" is a policy, not a control. The thing defenders can actually use is the diff: which Astra capabilities are behind identity verification today, what tripwire fires when a verified account starts chaining zero-days, and who gets told. Safety you can't audit from
> — [SarahLakzit on x · 1 points](https://x.com/SarahLakzit/status/2094949178577400078)

> @sama The most interesting signal here isn’t just “next model soon.” It’s that Astra finished training a while ago, and the bottleneck to release is increasingly becoming safeguards and alignment rather than capability. That feels like a very different phase of the frontier race.
> — [null\_founder on x](https://x.com/null_founder/status/2094954608301047846)

> @sama the obvious tension being "safety" and "launching our next model soon" in the same breath
> — [babachefz on x](https://x.com/babachefz/status/2094951090282274837)

> @sama I feel this is the thing you really wanted to say, "For the models after that, we have been slowing things". Will Anthropic also? Does this mean that OS will catch up and/or surpasses frontier?
> — [alphastack1 on x](https://x.com/alphastack1/status/2094948018781143516)

**Source threads**

- [x](https://x.com/scaling01/status/2094955482330919130) · 0 points · 0 comments
- [x](https://x.com/sama/status/2094933808071966926) · 0 points · 0 comments
- [x](https://x.com/rohanpaul_ai/status/2094919201836458219) · 0 points · 0 comments
- [x](https://x.com/sama/status/2094934592062959832) · 0 points · 100 comments

---

Tags: [#llm](https://daily.dev/tags/llm), [#ai-agents](https://daily.dev/tags/ai-agents), [#openai](https://daily.dev/tags/openai), [#gpt](https://daily.dev/tags/gpt), [#ai-safety](https://daily.dev/tags/ai-safety)

[View this post on daily.dev](https://daily.dev/posts/openai-s-astra-paused-for-safety-leaked-anyway-and-priced-like-a-luxury-car-rql9isr7d)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"OpenAI's Astra: paused for safety, leaked anyway, and priced like a luxury car","url":"https://daily.dev/posts/openai-s-astra-paused-for-safety-leaked-anyway-and-priced-like-a-luxury-car-rql9isr7d","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/openai-s-astra-paused-for-safety-leaked-anyway-and-priced-like-a-luxury-car-rql9isr7d"},"datePublished":"2026-08-30T01:40:33.092Z","dateModified":"2026-09-02T01:09:00.319Z","description":"OpenAI reportedly paused training on an internal model codenamed Astra over cited cybersecurity risks, but leaked outputs from a checkpoint labeled...","image":"https://pbs.twimg.com/media/HQ7xeBMXUAAx7rq.jpg","thumbnailUrl":"https://pbs.twimg.com/media/HQ7xeBMXUAAx7rq.jpg","isAccessibleForFree":true,"articleSection":"Trends","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Trends","logo":"https://media.daily.dev/image/upload/s--ZfSp3asX--/f_auto,q_auto/v1780996004/logos/trends?_a=BAMAMiWQ0","url":"https://daily.dev/sources/trends"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/openai-s-astra-paused-for-safety-leaked-anyway-and-priced-like-a-luxury-car-rql9isr7d","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"llm,ai-agents,openai,gpt,ai-safety","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Trends","item":"https://daily.dev/sources/trends"},{"@type":"ListItem","position":3,"name":"OpenAI's Astra: paused for safety, leaked anyway, and priced like a luxury car"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/openai-s-astra-paused-for-safety-leaked-anyway-and-priced-like-a-luxury-car-rql9isr7d#faq","mainEntity":[{"@type":"Question","name":"What is OpenAI's Astra model and why was it paused?","acceptedAnswer":{"@type":"Answer","text":"Astra is an internal OpenAI model reportedly paused during training due to flagged critical cybersecurity risks. Despite the official pause, leaked outputs from a checkpoint labeled mozaik-alpha-fdm have already circulated via Discord, including image renders described as impressive, undercutting the containment claim. Some developers argue the safety framing is more about narrative control than actual risk management. Developers weighing frontier model risk claims can follow verified coverage of Astra's status on daily.dev."}},{"@type":"Question","name":"How much might a 10 trillion parameter OpenAI model cost per million tokens?","acceptedAnswer":{"@type":"Answer","text":"Extrapolating from GPT-5's pricing of $20 per million output tokens at an estimated 2-3 trillion parameters, a full 10 trillion parameter model could cost roughly $66 to $100 per million output tokens. That pricing would put it well outside typical developer tool budgets and into enterprise procurement territory rather than everyday API use. Teams budgeting for frontier model access can track pricing shifts like this on daily.dev."}},{"@type":"Question","name":"What makes OpenAI's rumored Astra model different from existing agent architectures?","acceptedAnswer":{"@type":"Answer","text":"Astra is reportedly designed to run continuously for weeks, with a planned variant intended to run indefinitely, functioning less like a traditional request-response app and more like a persistent background process. OpenAI is said to be building a new interface specifically for these continuously running agents, which critics describe as effectively 'agent employees' rebranded. Developers exploring long-running AI agent designs can follow how this architecture unfolds on daily.dev."}}]}
```

