OpenAI declares Astra its first “Critical” cyber model
OpenAI said on 1 September that Astra meets the Critical cybersecurity threshold under its Preparedness Framework — the first model it has designated at that level. The threshold is met if a model can find and build working zero-day exploits of all severity levels across many hardened real-world critical systems without a human guiding each step, or run an end-to-end novel attack against a hardened target from only a high-level goal. The evidence OpenAI published: a perfect 100% on ExploitBench, and on a private port built from 20 high-severity V8 vulnerabilities disclosed between June and August, much higher arbitrary-code-execution rates than GPT‑5.6 Sol using far fewer tokens. During that evaluation the model found and chained two zero-days, which OpenAI says it is now disclosing to maintainers. In expert-led tests it built a full browser-compromise chain that escaped the sandbox and ran commands on the host when the browser opened an HTML file, and a local privilege-escalation chain to root on a hardened operating system. OpenAI notes these results reflect Daybreak Blue access, not the default production configuration.
The part that changes procurement is the deployment shape. OpenAI delayed parts of Astra’s development and release to harden safeguards, and restarted a large frontier reinforcement-learning run only on 28 August. OpenAI says Astra refuses 91.5% of prompts in its own internal cyber jailbreak set, against 59% for GPT‑5.6 Sol. It ships with chain-of-thought misalignment monitoring that can stop a running task, and OpenAI says plainly that legitimate work will sometimes be flagged — including work unrelated to security, and long-running agent jobs. In ChatGPT or Codex the user may be asked to review the action before continuing; on non-interactive surfaces such as the API, the task simply stops. Advanced cyber workflows go to a small group of alpha testers first, then widen through Daybreak Blue. If you are building an agent on a frontier API, the vendor’s safety monitor is now a runtime dependency with its own failure mode, and it is worth knowing whether your fallback route exists before it fires.
Brussels makes ChatGPT a search engine in law
The European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act on 31 August, alongside Reddit and Roblox as Very Large Online Platforms. It is the first AI assistant to appear on the DSA list. The trigger is mechanical: the services declared they reach at least 45 million average monthly users in the EU. The Commission’s reasoning is that ChatGPT is a hybrid service that qualifies as a search engine because it responds to user prompts and queries, including by searching the web. The three services have four months — until January 2027 — to meet the extra VLOP/VLOSE duties: assessing and mitigating systemic risks from the service and its algorithmic systems, covering illegal content, harm to minors, users’ physical and mental wellbeing, fundamental rights, electoral processes and public security.
This is the DSA, not the AI Act, and the distinction matters for anyone mapping obligations. The AI Act regulates the model and its provider; this designation regulates the assistant as a distribution channel, and brings independent audits and vetted-researcher data access with it. The practical read for European buyers is that a general-purpose assistant embedded in a customer-facing product is starting to be treated the way a platform is — and the risk-assessment questions that land on OpenAI in January tend to travel downstream to whoever built on top.
Anthropic books about $90bn of compute in under a month
Anthropic signed a $35bn, six-year cloud agreement with Lambda on 31 August, covering roughly 350MW at a Nueces County, Texas site being developed by Hut 8. The interesting part is the chain: Hut 8 builds the data centre and leases it to Nvidia, Lambda pays Nvidia for access and sells the resulting capacity, and Anthropic buys it. Nvidia is also an equity backer of Lambda. One vendor sits in three positions in a single transaction, which is why the deal is being read as much as a financing structure as a hosting contract.
It is also not an isolated purchase. Anthropic committed $45bn to Nscale on 26 August for about 460MW in West Virginia on Nvidia’s Vera Rubin architecture, expected online at the end of 2027, and $10bn to Volta on 4 August for roughly 133MW gross at a hydro-powered site in Tydal, Norway operated by Bitdeer. That is around $90bn of compute commitments in under a month, booked ahead of a widely reported IPO. The Norwegian line is the one worth noting from here: European capacity is being pre-sold on long leases to US labs before the racks are installed, and “the data centre is in Europe” says nothing about who holds the contract.
Quick Hits
- Europe’s next AI supercomputer is an AMD machine. The EuroHPC Joint Undertaking signed a €387.8M contract with Bull on 31 August to deploy LUMI-AI at CSC’s Kajaani data centre in Finland — AMD Instinct MI430X GPUs and 6th Gen EPYC 256-core CPUs, and a tenfold increase in AI capacity over the current LUMI. EuroHPC expects it installed and available to users in 2027.
- Tencent open-sourced a 770B flagship under plain Apache 2.0. Hy4 preview landed on 28 August: a mixture-of-experts model with roughly 49B active parameters and a context window over 1M tokens, with weights and an FP8 variant on Hugging Face alongside official vLLM and SGLang images. At a moment when several large open-weight releases ship under bespoke licences, the standard licence is the rarer thing.
- The AI Office is staffing its enforcement team. The Commission’s call covers approximately 40 contract-agent posts over 2027 — technology specialist, legal officer, operations specialist and paralegal — and applications close on 8 September at 12:00 Brussels time. The number is an estimate contingent on budget approval, which is itself the thing to watch: supervision capacity arrives on a budget cycle, not an enforcement date.
