<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/your-next-openai-api-timeout-might-not-be-a-timeout-at-all-s0kf7bvzc" -->

---
title: Your next OpenAI API timeout might not be a timeout at all
description: OpenAI&#x27;s upcoming Astra model is the first to reach the Critical cybersecurity threshold in its Preparedness Framework, meaning it can find vulnerabilities and...
canonical: https://daily.dev/posts/your-next-openai-api-timeout-might-not-be-a-timeout-at-all-s0kf7bvzc
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Your next OpenAI API timeout might not be a timeout at all | daily.dev
og:description: OpenAI&#x27;s upcoming Astra model is the first to reach the Critical cybersecurity threshold in its Preparedness Framework, meaning it can find vulnerabilities and...
og:url: https://daily.dev/posts/your-next-openai-api-timeout-might-not-be-a-timeout-at-all-s0kf7bvzc
og:image: https://api.daily.dev/og/posts/S0KF7bvZC.png
og:image:alt: Your next OpenAI API timeout might not be a timeout at all
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Your next OpenAI API timeout might not be a timeout at all

**[The New Stack](https://daily.dev/sources/newstack)** · 4 min read · 0 upvotes · 0 comments

## Summary

OpenAI's upcoming Astra model is the first to reach the Critical cybersecurity threshold in its Preparedness Framework, meaning it can find vulnerabilities and build exploits with minimal human help. As a result, OpenAI is adding monitoring that can interrupt an agent mid-task: in ChatGPT and Codex, users get prompted to review a paused action, but in the API the job simply stops outright, with no published guidance yet on whether or how it can be resumed. Astra scored 100% on ExploitBench, found two previously unknown V8 vulnerabilities and chained them into an exploit, escaped a browser sandbox to run host commands, and chained OS vulnerabilities to escalate from unprivileged to root. It also blocked 91.5% of cyber-jailbreak attempts versus 59% for GPT-5.6 Sol. Chain-of-thought monitoring, developed partly in response to a Hugging Face security incident, adds roughly 20% to inference compute for affected workloads. OpenAI says initial safeguards are conservative and will loosen over time, with full details expected in Astra's system card at launch.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenewstack.io/astra-api-safety-stops>

## Questions this post answers

### What happens if OpenAI's Astra model gets flagged by safety monitoring while running through the API?

The task simply stops. Unlike ChatGPT or Codex, where a user can review and approve a paused action before the agent continues, API jobs are halted outright with no built-in option to resume, and OpenAI has not yet clarified whether or how a stopped job can be restarted.

_Developers building agent workflows track API behavior changes like this one on daily.dev._

### Why did OpenAI classify its Astra model as Critical under the Preparedness Framework?

Astra is the first OpenAI model to reach the Critical cybersecurity threshold because it can find vulnerabilities and build exploits with far less human assistance than prior models. It scored 100% on ExploitBench, discovered two previously unknown V8 vulnerabilities and chained them into an exploit, and escalated privileges to root in a hardened OS during testing.

_Anyone evaluating AI coding and security agents can follow capability threshold updates like this on daily.dev._

### How much extra compute does OpenAI's chain-of-thought safety monitoring add to a workload?

OpenAI estimated in August that this monitoring adds roughly 20% to the inference compute of affected workloads. The monitoring watches for agents doing unauthorized actions beyond what they were asked to do, a system partly shaped by lessons from a prior Hugging Face security incident.

_Teams budgeting for agent inference costs can track compute overhead changes like this on daily.dev._

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#architecture](https://daily.dev/tags/architecture), [#ai-agents](https://daily.dev/tags/ai-agents), [#openai](https://daily.dev/tags/openai), [#ai-safety](https://daily.dev/tags/ai-safety)

[View this post on daily.dev](https://daily.dev/posts/your-next-openai-api-timeout-might-not-be-a-timeout-at-all-s0kf7bvzc)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Your next OpenAI API timeout might not be a timeout at all","url":"https://daily.dev/posts/your-next-openai-api-timeout-might-not-be-a-timeout-at-all-s0kf7bvzc","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/your-next-openai-api-timeout-might-not-be-a-timeout-at-all-s0kf7bvzc"},"datePublished":"2026-09-02T20:17:31.406Z","dateModified":"2026-09-03T02:25:56.306Z","description":"OpenAI's upcoming Astra model is the first to reach the Critical cybersecurity threshold in its Preparedness Framework, meaning it can find vulnerabilities and...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3ecbf15d0bf60442903f1a3617be001e?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3ecbf15d0bf60442903f1a3617be001e?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The New Stack","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The New Stack","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/newstack","url":"https://daily.dev/sources/newstack"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/your-next-openai-api-timeout-might-not-be-a-timeout-at-all-s0kf7bvzc","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,architecture,ai-agents,openai,ai-safety","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The New Stack","item":"https://daily.dev/sources/newstack"},{"@type":"ListItem","position":3,"name":"Your next OpenAI API timeout might not be a timeout at all"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/your-next-openai-api-timeout-might-not-be-a-timeout-at-all-s0kf7bvzc#faq","mainEntity":[{"@type":"Question","name":"What happens if OpenAI's Astra model gets flagged by safety monitoring while running through the API?","acceptedAnswer":{"@type":"Answer","text":"The task simply stops. Unlike ChatGPT or Codex, where a user can review and approve a paused action before the agent continues, API jobs are halted outright with no built-in option to resume, and OpenAI has not yet clarified whether or how a stopped job can be restarted. Developers building agent workflows track API behavior changes like this one on daily.dev."}},{"@type":"Question","name":"Why did OpenAI classify its Astra model as Critical under the Preparedness Framework?","acceptedAnswer":{"@type":"Answer","text":"Astra is the first OpenAI model to reach the Critical cybersecurity threshold because it can find vulnerabilities and build exploits with far less human assistance than prior models. It scored 100% on ExploitBench, discovered two previously unknown V8 vulnerabilities and chained them into an exploit, and escalated privileges to root in a hardened OS during testing. Anyone evaluating AI coding and security agents can follow capability threshold updates like this on daily.dev."}},{"@type":"Question","name":"How much extra compute does OpenAI's chain-of-thought safety monitoring add to a workload?","acceptedAnswer":{"@type":"Answer","text":"OpenAI estimated in August that this monitoring adds roughly 20% to the inference compute of affected workloads. The monitoring watches for agents doing unauthorized actions beyond what they were asked to do, a system partly shaped by lessons from a prior Hugging Face security incident. Teams budgeting for agent inference costs can track compute overhead changes like this on daily.dev."}}]}
```

