← Back to glossary
+Suggest a term
Concept·AI Models & Capabilities·Added today

Cyber-capable AI

Also known as: cyber AI, cybersecurity-capable model, offensive AI, critical cyber model

AI models capable of autonomously finding and exploiting security vulnerabilities in real systems, without step-by-step human direction. A distinct capability tier from general-purpose models, now triggering gated access and new regulatory attention.

Cyber-capable AI refers to models whose security skills go well beyond helping developers write safe code or explaining known vulnerabilities. A cyber-capable model can discover previously unknown flaws, develop working exploit code, chain multiple vulnerabilities together, and in some cases escape a sandboxed environment, all without a human guiding each step. That combination of autonomy and offensive skill is qualitatively different from a code assistant that answers questions about security.

The term entered builder vocabulary seriously in 2026 as Google and OpenAI began releasing specialized cybersecurity model variants. Google's Gemini Flash Cyber series targets defenders, giving security teams tools to find vulnerabilities before attackers do. OpenAI's Astra became the first model the company classified at its Critical cybersecurity threshold, meaning it could find zero-day exploits across hardened production systems autonomously. Both labs framed the capability as dual-use: powerful for defenders, dangerous if misused.

The practical consequence for builders is access gating. Labs are creating tiered release programs where the most capable cyber features are available only to vetted security researchers, government partners, or organizations with specific defensive use cases. Builders building security tooling need to understand which tier of capability they are building with, and what guardrails the model provider has applied. The broader concern, which regulators are now tracking, is that a model with autonomous offensive cyber capability represents a qualitatively new kind of infrastructure risk if it is misused, stolen, or exposed via a jailbreak.

This definition is AI-generated and refreshed weekly. It may contain inaccuracies. Use your own judgment, especially for production decisions.
Related terms
Preparedness FrameworkAI Red TeamerAI pentest agentAlignmentModel safety evaluation