Put offensive AI capability on your risk register this quarter. A risk register is the standing record of material risks, their owners, and required action. This entry needs a named executive owner and quarterly reporting from security leadership. That is not a prediction about when an attack will occur. It recognizes that the available evidence now warrants structured oversight.

Two lines of evidence, from organizations with different incentives, point to the same planning conclusion. [1] [3]

What OpenAI's Own Evaluation Found

OpenAI conducted preliminary internal assessments of a model it calls Astra and found it could not rule out what its Preparedness Framework defines as the "Critical" cybersecurity threshold. [1]

That threshold describes a model capable of identifying and developing functional zero-day exploits—working attacks against software flaws that defenders do not yet know how to patch—across many hardened systems without human intervention at each step, or of devising and executing novel cyberattacks against hardened targets end to end. OpenAI's previous models were assessed at the level below this one, which the framework labels "High." The gap between those levels is significant because the Critical threshold specifically describes a model that operates without a human directing the hardest steps. Earlier OpenAI models had not been assessed at that line. [1]

OpenAI's response was to pause Astra-related activities until stronger controls were in place, and to temporarily slow its scaling work. That included a pause in reinforcement-learning training on deployment-intended models—training that shapes a model's behavior through feedback on its actions—while the company hardened testing environments and expanded monitoring. These are vendor-reported actions and assessments. [1] [2]

This does not mean Astra definitely crosses the Critical threshold, that it has been released, or that any specific release is imminent. The assessment is preliminary and vendor-reported. The same organization surfacing the concern has a commercial interest in how the story reads. Hold it with appropriate skepticism, and note that OpenAI paused activities anyway. [1]

What a Government Evaluator Found

Separately, NIST assessed an open-weight model—one whose core parameters can be downloaded and run on private infrastructure—and found its cyber capability similar to a closed frontier model at the time of release. [3]

NIST's finding on safeguards deserves executive attention. When the model's safeguards were intact, they still allowed assistance with agentic exploit development, meaning multi-step work toward an exploit. NIST also states that safeguards for open-weight models can be circumvented when the model is self-hosted. Once downloaded, the model's safeguards no longer depend on the creator's hosted controls. [3]

The practical consequence is narrower but still important. A capable tool can be downloaded and operated outside the creator's hosted controls. That allows a threat actor to augment skilled human work without depending on the model provider's continued permission. It does not remove the need for technical skill or prove that attacks will succeed. [3]

Where the Sources Converge

The convergence matters because the incentives differ. A commercial vendor slowed its own model-development work over capability concerns it surfaced internally. An independent government evaluator found an already downloadable model could assist exploit development when self-hosted. Neither source claims that attacks have increased in frequency or volume. The evidence does not support that claim. [1] [3]

The evidence means offensive AI is a present planning input, not a scenario for a future review cycle. Security teams have always operated against an exposure interval, the gap between when a vulnerability becomes fixable and when the organization closes it. AI tools that may lower the cost of reconnaissance and exploitation make that interval more important because attackers may move faster through the early stages of an intrusion. The question for your organization is how well current detection and response capacity holds up if attacker costs fall. [1] [3]

Four Governance Decisions for This Quarter

These steps use existing governance machinery, though the reporting and exercise require staff time.

Name an executive owner. Offensive AI risk needs a single accountable person at the C-suite level, typically the chief information security officer or chief risk officer, who reports on it in the same cadence as other material risks. Without a named owner, this category stays on a watch list without consequence.

Add it to the risk register this quarter. The risk is not "AI" in the abstract. The specific risk is this: AI tools may reduce the cost and skill threshold for offensive cyber operations, shortening the time attackers need to identify and reach exploitable systems relative to your team's ability to detect and respond. That language is precise enough to drive action and to measure against each quarter.

Require bounded reporting from security leadership. Ask for two things before your next board security review: the current exposure interval for your internet-facing systems—the average time between a fix becoming available and your team applying it—and the backlog of validated but unpatched findings from your most recent penetration test or security exercise. Those data show where AI-assisted reconnaissance could have the most leverage on your environment because they reveal where your organization is slowest to close known gaps. [4]

Sponsor a tabletop exercise. The OpenAI president specifically urged organizations to run tabletop exercises for AI-accelerated intrusion scenarios. [4] A tabletop exercise tests your incident response playbook against a simulated attack without live stakes. The scenario worth rehearsing is an attacker using AI assistance to identify and chain exploits faster than your team's normal detection cycle. The goal is not to predict the exact attack but to confirm that your team knows its decision tree when the pressure arrives.

The Risk-Register Decision

This quarter, instruct your risk committee to add AI-assisted offensive cyber capability as a named risk entry with an executive owner. Direct security leadership to report, before the next board security review, your exposure interval for internet-facing systems and the current backlog of validated unpatched findings. Schedule one tabletop exercise on an AI-accelerated intrusion scenario before that same review.

The evidence does not call for emergency procurement or a restructured security budget. It calls for the structured attention your organization already gives to risks that deserve recurring review and named ownership.