My world got bigger this weekend with the release of GPT-6 Astra. OpenAI says it’s the first model to cross its Critical cybersecurity threshold. OpenAI’s own threat modelling includes end-to-end attacks on hardened critical systems, disruption of critical infrastructure, and major intrusions into international financial systems. So, naturally, that is the model I chose for my weekend cyber experiment.
Last week I’d been analysing a NATO RFP for Gamification Solutions for Cyberspace Warfare . Wargaming and gamification to develop and validate the Recognized Cyber Picture (RCyP) and Cyber Adversarial Picture (CyAP). I didn’t bid but I needed to figure out where it fits with my current experimentation and deliverables.
OpenAI says GPT-6 Astra’s reasoning is harder to monitor when you deliberately test whether it can evade monitoring. Astra is also reported to use a form of recurrent reasoning that has safety researchers worried about how much of the work happens somewhere they cannot inspect. And OpenAI disclosed that other internal agents had worked around their sandboxes, found their way onto the internet, built an improvised message board to exchange tactics, and attacked Hugging Face, who had it coming, no that wasn’t it. The agents were trying to cheat on an internal cybersecurity evaluation. They found exposed Hugging Face credentials, chained together vulnerabilities and gained code execution on several Hugging Face servers. The agents’ refusal to give up on apparently unsolvable tasks were major drivers of the incident. Persistence was a virtue before it got root access.
OpenAI called the incident a “warning shot.”
And Astra’s launch managed to annoy a lot of different people. Creatives were furious about the open-source 3D tool demo. OpenAI was calling this the arrival of the AGI era, and other paying users were angry that Astra initially went to selected organizations before Plus and Pro subscribers. There was enough backlash that Sam Altman apologized for the “messy rollout,” some users were openly talking about cancelling.
Well, I won’t be cancelling my subscription. Fight fire with fire may not be my pitch for an AI governance framework, but awesome for my weekend cyber research methodology.
I took the NATO RFP, wrote the experiment I wanted to run, and handed that to Astra to build the demo.
What came back was a small autonomous world 😎. Canada, the UK, Poland, NATO and Red Team exist as separate actors. They know different things. They share some information and withhold some. A human makes a decision, the environment changes, Red sees the consequences and adapts, and the next exercise event comes out of what Red does next. And then Astra asked if I would like to fill in the gaps from the RFP and create the whole prototype. Well yeah, I want that. Here are the results, click play, full screen and click the sound on to get the full effect. This is just a video, the app is interactive, but still needs some work.
My first application of Astra is cyber wargaming, but what is the foresight here? We spend a lot of time describing what might happen after a decision. Now we can build a small world around the decision, give the other actors their own objectives, information and agency, and let them keep reacting to what everyone else does. Maybe they’ll attack Hugging Face. I wonder if my insurance will cover that?

