Preparedness Framework
Also known as: AI preparedness framework, capability threshold framework, OpenAI Preparedness Framework
The Preparedness Framework is a structured risk-evaluation methodology OpenAI first published in 2023. It defines capability tiers, High and Critical, for categories of potential harm: cybersecurity, biological threats, nuclear and radiological risks, and autonomous agent behavior. A model reaches High if it could significantly amplify existing pathways to serious harm. It reaches Critical if it could introduce genuinely new pathways to harm that didn't exist before.
The framework came into sharp focus in August and September 2026 when OpenAI determined that its upcoming Astra model had crossed the Critical cybersecurity threshold. The designation meant Astra could identify previously unknown security vulnerabilities and develop working exploits across hardened systems without step-by-step human guidance. OpenAI responded by pausing some internal development activities, scaling up safety testing, and committing to limit access to Astra's most advanced cybersecurity capabilities at release.
For builders, the Preparedness Framework matters for two reasons. First, it sets precedent for how other labs and regulators may evaluate and gate access to powerful models. Google and Anthropic have comparable internal frameworks, and the EU AI Act points in a similar direction for high-risk AI systems. Second, the Critical designation on a model creates a real access question: some capabilities may be gated to vetted partners, government programs, or defenders-only programs rather than available through a standard API. Knowing what tier a model sits in helps builders plan around what they can actually access.