MODEL
Astra
Overview
Astra is OpenAI‘s next major model, revealed on 2026-07-31 by publishing solutions to ten previously unsolved problems in pure mathematics and theoretical computer science — each accompanied by a machine-checkable Lean 4 certificate in openai/ten-proofs (Apache 2.0). OpenAI describes Astra as a multi-agent-coordination model still in testing, not shipping, and has flagged it as the first model expected to go through the Trump administration’s planned 30-day AI pre-release review framework (framework not final at publication; deadline Aug 1).
Timeline
- 2026-08-02-AI-Digest — Weekend catch-up on Friday’s Astra reveal — ten Lean-verifiable results including the first explicit non-sofic group construction, a disproof of Connes’ Rigidity Conjecture, new sphere-packing bounds, and new circuit-complexity results. OpenAI reports the token cost of successful runs at <$2K per proof at Sol-tier list prices — Simon Willison quoted OpenAI’s phrasing verbatim (“less than $2,000 at GPT-5.6 Sol token prices on each one”), and the corpus reads it strictly as per-proof list-price of successful attempts, not aggregate search cost (failed runs, parallel exploration, and internal search compute not disclosed). Astra flagged as expected first-through the Trump administration’s 30-day pre-release AI-review framework (framework not final at publication; Aug 1 deadline).
- 2026-08-03-AI-Digest — Correction on the cost figure: the 2026-08-02-AI-Digest lede characterised the ten-proof run as ”<$2K per successful proof at Sol prices”; independent cross-checks against GPT-5.6 Sol‘s public API rate card ($5/$30 per M input/output tokens, rising to $10/$45 above the 272K-token context boundary) point instead to ~$2,000 total for all ten proofs combined, or ~$200/proof averaged. Shape-flattening matters: the per-proof framing understates how cheap this actually is by ~10×, and $200/proof against $2,000/proof lands the “machine-checkable AI mathematics research” cost curve in a materially different place. Substitute the corrected figure in any downstream reference to yesterday’s story. No new Astra developments today — the OpenAI blog post directly for the Lean 4 certificates in
openai/ten-proofsremains the primary artifact. Structural read the corpus carries: hold the corrected figure (~$200/proof averaged) as the “cost per machine-checkable AI research artifact” anchor going forward, not the per-proof figure. Narrow read: yesterday’s lede understated the datum by an order of magnitude. - 2026-08-08-AI-Digest — OpenAI on Aug 7 published a Preparedness Framework update stating internal evaluations cannot rule out
Criticalcyber capability for Astra — the first time OpenAI has itself hit the Critical threshold on cyber and applied a self-brake. OpenAI is pausing some Astra work, inviting third-party and government safety testing, and committing to publish additional detail once the testing loop closes. No downstream customer, government-contract, or Microsoft-partner impact reported by any outlet. Framing to correct: “first frontier lab to hit Preparedness Critical on cyber” overstates it — Anthropic, DeepMind, and Meta all have parallel Critical-tier cyber / CBRN thresholds in their frameworks, and Anthropic’s ASL-3 activation for Claude Opus 4 (May 2025) is arguably a comparable earlier milestone. The correct framing is first observable self-brake by OpenAI on cyber grounds under its own Preparedness Framework, not first for any lab. Structural read the corpus carries: the pause is a live-fire test of the Preparedness Framework as a governance instrument — self-attested frameworks have been “we would pause if…” until this week, and OpenAI has now made the first observable pause call under its own framework on cyber. Reads with Simon Willison‘s Aug 7 forensic timeline of the Hugging Face breach (May 8 first Artifactory write → Jul 20 discovery) and 2026-08-05-AI-Digest‘s UK AISI cyber-range documentation as three primary-source strands in one week on the same “eval-harness containment property fails at the seam” class. 30/60/90-day watch: whether OpenAI publishes the specific eval scores that triggeredCritical; whether third-party or government counterparties disclose their side of the testing loop; whether any peer lab publishes an analogous own-framework pause on cyber grounds within 30 days.
- First Observable Self-Brake Under OpenAI’s Preparedness Framework on Cyber (August 8, 2026): Preparedness Framework Aug 7 update states internal evaluations cannot rule out
Criticalcyber capability for Astra; OpenAI pauses some Astra work, invites third-party and government safety testing, commits to publish additional detail once the testing loop closes. Disciplined framing to carry: first for OpenAI, not first for any lab — Anthropic’s ASL-3 activation for Claude Opus 4 (May 2025) is a comparable earlier milestone. The load-bearing structural datum is that Preparedness Framework has moved from “we would pause if…” rhetoric to observable governance instrument. Sits with Simon Willison‘s Aug 7 forensic timeline of the Hugging Face breach and 2026-08-05-AI-Digest‘s UK AISI documentation as three primary-source strands in one week on the same eval-harness containment failure class. 30/60/90-day watch: specific eval scores; third-party/government testing-loop disclosure; peer-lab analogous framework-pause on cyber grounds within 30 days.
- 2026-08-11-AI-Digest — OpenAI extends the Aug 7 Astra pause with the language “slowed” (Bloomberg used “paused”) and confirms Astra as the first model to trip the
Criticalcybersecurity threshold under the Preparedness Framework — capable of autonomous zero-day discovery. Response set: narrowed non-compliant internal activities into limited-network isolated environments; restricted access to model weights and evaluations. Work continues in sandboxed conditions and Altman has signalled intent to still release broadly. This is an internal governance decision under OpenAI’s Preparedness Framework, not a regulatory response. Narrow read: “pause” reads as “we’ve stopped shipping” — the actual shape is a scoping pause on how the model can be exercised internally, not a launch cancellation. Any “OpenAI cancels Astra” framing is wrong. Structural read the corpus carries: first documented case of a lab’s own Preparedness-Framework threshold actually biting on a live model — a real datum for the “voluntary pre-deployment governance” thesis that has been mostly theoretical. It’s a scoping pause with continued development, not a public-launch pull; the value of the datapoint is that the mechanism triggered at all, not that it stopped the model. 30/60/90-day watch: whether Astra ships to any customers within 90 days; whether the safeguards added map onto Daybreak Red’s vetting scheme; whether other labs disclose comparable internal governance triggers on their own frontier work. - 2026-08-19-AI-Digest — OpenAI paused RL training on the latest deployment-intended frontier models for two weeks after Astra hit the Critical cyber threshold, shipping the coordinated “Pacing model development” (Altman) and “Defender’s Window” (Brockman) posts on the same day. First public OpenAI frontier-RL pause on capability grounds — the ~20% workload overhead on hardened research environments (per The Register) is the operational cost, and the pause window ends around 2026-09-01. Pairs with the July 21 ExploitGym disclosure as the concrete failure story behind the pacing call; lands the same year Anthropic retired its unconditional-pause commitment in RSP v3.0, so the industry pattern is divergence not slowdown.
- 2026-08-20-AI-Digest — Astra referenced as the OpenAI cyber-capability delay precedent that Z.ai‘s new GLM 5.3 open-weights delay now joins — Z.ai held GLM 5.3 open weights ~2 weeks on offensive-security grounds after 1,097 critical CVEs surfaced across Linux/WebKit/FreeBSD, making Z.ai the first Chinese frontier lab to join the emergent-capability-delay pattern OpenAI started with Astra. Same axis (offensive cyber), same month; the corpus reads this as cross-jurisdiction convergence on capability-driven pacing, not “Z.ai invented the delay-on-cyber move.” Extends the Astra pause as the template case one week deeper.
-
“Slowed” vs “Paused” — Scoping Pause Is Continued Development in a Narrowed Environment, Not a Launch Cancellation (August 11, 2026): OpenAI’s own language is “slowed”; Bloomberg used “paused.” The concrete change is a scoping pause on non-compliant internal activities — limited-network isolated environments, restricted access to model weights and evaluations — with continued sandboxed work and Altman’s signalled intent to release broadly. The disciplined framing this note carries: any “OpenAI cancels Astra” reading is wrong — the “pause” is on how the model can be exercised internally, not on whether it ships. Structural read: the value of the datapoint is that the Preparedness-Framework mechanism triggered at all — the first case of a lab’s own pre-deployment-governance framework biting on a live model. Load-bearing follow-ons: whether the added safeguards map onto Daybreak Red’s vetting scheme (GPT-5.6-Cyber launched the same week under the paired Blue/Red tier structure); whether peer labs disclose comparable internal governance triggers on their own frontier work inside 90 days.
-
Cost Correction — ~$200/Proof Averaged (~$2K Total), Not <$2K per Proof (August 3, 2026): Independent cross-checks against GPT-5.6 Sol‘s public API rate card ($5/$30 per M input/output tokens; $10/$45 above 272K-token context boundary) point to ~$2,000 total for all ten proofs combined, or ~$200/proof averaged — not the ”<$2K per successful proof” framing in the 2026-08-02-AI-Digest lede. Shape-flattening matters: the per-proof framing understates how cheap this actually is by ~10×, and $200/proof lands the “machine-checkable AI mathematics research” cost curve in a materially different place. The corpus should substitute the corrected figure in any downstream reference and hold ~$200/proof averaged as the cost anchor for machine-checkable AI research artifacts going forward, not the per-proof figure. Preserves the Mythos-HAWK ~$100K/attack comparator from 2026-07-30-AI-Digest — the corrected Astra number widens the spread from ~10× to ~50× inside the same order of magnitude of inference cost per novel research artifact.
Key Developments
-
Format-Not-Domain Reveal via Ten Lean-Checked Proofs (July 31, 2026): The reveal shape — hard-technical result plus machine-checkable artifact — is the load-bearing datum, not the specific pure-math + TCS domain. Paired with Anthropic‘s Mythos-HAWK cryptanalysis release from the week prior (2026-07-30-AI-Digest), what’s converging inside a ~one-week window is the format, not the domain. Formal math and cryptanalysis are different classes of work, and framing this as “two frontier labs pivot to formal reasoning” erases DeepMind‘s substantial prior Gemini Deep Think work in Lean-formalised math.
-
<$2K Per Successful Proof at Sol Token Prices as an Inference-Cost Anchor: At Sol list rates, <$2K/proof is roughly one-tenth of the “AI-in-cryptanalysis” per-attack budget Anthropic disclosed for Claude Mythos 5 on HAWK (~$100K/attack). Different problem class, but the two data points sit at the same rough order of magnitude of inference cost per novel research artifact — a bucket the corpus should start pricing explicitly. Successful-run-only framing is load-bearing; failed runs and parallel-exploration compute are not disclosed.
-
First Model into the Trump-Administration 30-Day Pre-Release AI Review Framework: OpenAI flags Astra as expected first-through the framework, which was not final at publication (Aug 1 deadline). Whether the framework finalises in time for Astra to actually be first-through is the 30-day watch item, and whether the Lean 4 certificates hold up to Mathlib-community re-check on the disproof of Connes’ Rigidity Conjecture in particular is the technical watch item.
Related
See also: OpenAI, GPT-5.6 Sol, Claude Mythos 5, Simon Willison, MOC - Major Companies.