SOURCE 0 - THE CRITICAL THRESHOLD NO ONE ELSE HAS MEASURED

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · August 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

On 7 August 2026, OpenAI disclosed that preliminary internal evaluations of an unreleased model, Astra, could not rule out the "Critical" cybersecurity threshold defined in its own Preparedness Framework — the first time this designation has attached to any of its models. The determination, the containment measures that followed it, and the external validation OpenAI says it will seek are all built on a single evaluation record that OpenAI itself produced, holds, and has not yet made independently verifiable. If Astra is confirmed at Critical level, the confirmation would rest on tests run after the fact, on a system whose developer already knows what conclusion is expected. What would remain unresolved is not whether Astra is dangerous — it is whether anyone other than OpenAI can establish, independently and after the fact, what the evaluation record actually showed at the moment the determination was made.

[/AI-SNIPPET]

I. THE DISCLOSURE

OpenAI stated on 7 August 2026 that internal evaluations conducted over the preceding days showed sufficient advancement in Astra's agentic coding and cybersecurity performance that the company could not rule out the "Critical" cyber capability level defined in its own Preparedness Framework. Under that framework, first published in December 2023 and revised in 2025, a model crosses the Critical cybersecurity threshold if it can independently discover and develop functional zero-day exploits across multiple severity levels in hardened real-world systems, or if it can execute a complete cyberattack strategy against a hardened target from nothing more than a high-level objective. This definition is OpenAI's own; it is reproduced here as the standard OpenAI applied to itself, and its recitation does not constitute an assessment of Astra's actual capabilities by this article. No prior OpenAI model, including its currently deployed flagship, had been assessed above the "High" tier on this scale. OpenAI states that Astra was not involved in the Hugging Face intrusion disclosed in July 2026.

In response, OpenAI says it has moved Astra's further development into isolated testing environments with restricted network access, paused internal work that does not meet newly strengthened security requirements, deployed monitoring of the model's reasoning traces during agentic use, and will invite government agencies and external safety organisations to test the model before any wider release.

II. WHAT WAS ACTUALLY VERIFIED, AND BY WHOM

Every fact in Section I originates from a single source: OpenAI. Contextual elements introduced later in this article and attributed to press reporting are sourced separately and identified as such where they appear; they do not bear on the evaluation record itself. The threshold definition is OpenAI's own. The evaluation protocol that produced the "cannot rule out" conclusion is OpenAI's own. The decision to classify Astra as approaching Critical, taken, in the company's own account, on the night preceding disclosure, was made internally, without a third party present at the moment the record was fixed. The "expert assessments" cited alongside the internal evaluations are not identified, and it is not established whether those experts reviewed the underlying evaluation logs or only a summary of them.

This is not an allegation of misrepresentation. It is a description of the evidentiary structure of the disclosure. Nothing published as of this writing allows an outside party — a regulator, a plaintiff, an insurer, a competitor, or a journalist — to establish independently what the evaluation record showed at the time the Critical determination was made, as distinct from what OpenAI has since said about it.

III. THE VALIDATION THAT HAS NOT YET HAPPENED

OpenAI states that it will work with government agencies and selected AI safety organisations to test Astra's capabilities. It has also, according to reporting, informed the U.S. administration of its intention to delay the model's release. Both of these are prospective. As of the disclosure, no external body has confirmed the "cannot rule out Critical" determination, and none had done so before the determination was announced.

Should external testing later confirm the Critical designation, that confirmation would date from the moment the external test was run — not from the moment, on the night of 6 to 7 August 2026, that OpenAI itself concluded it could not exclude the possibility. A later, independent test cannot retroactively establish what an internal record contained weeks or months earlier, on a model whose weights and configuration OpenAI controls and can adjust throughout the intervening period. The anteriority of the original determination would remain, structurally, a fact known only to OpenAI. This is distinct from the question of forensic reconstruction: an audited internal system may in principle allow a later reconstruction of an earlier state, but such a reconstruction, performed by or for the party under scrutiny, is not equivalent to an anteriority fixed independently before the fact and opposable to that party — the two should not be conflated.

IV. THE REGULATORY QUESTION THE COVERAGE HAS NOT ASKED

This section draws a structural parallel; it does not assert that Astra is classified under Article 51, nor that OpenAI is or is not in compliance with Article 55. Under Regulation (EU) 2024/1689 (the AI Act), providers of general-purpose AI models classified as carrying systemic risk are subject to Article 55. Article 55(1)(a) requires such providers to perform model evaluation in accordance with standardised protocols reflecting the state of the art, including conducting and documenting adversarial testing aimed at identifying and mitigating systemic risk. The European Commission's own guidance on this provision confirms that certain obligations under Article 55, including the evaluation duty, attach during the development phase, prior to a model being placed on the market — they are not deferred until release.

If Astra, as a successor to models already assessed by OpenAI at the systemic-risk threshold under Article 51, falls within the same classification, the adversarial testing OpenAI describes performing on Astra is not merely a voluntary act under its own Preparedness Framework. It is, in substance, the kind of evaluation Article 55(1)(a) already requires it to document. This article takes no position on whether OpenAI's internal process in fact satisfies that obligation, nor on Astra's eventual classification under Article 51 — both are reserved to the AI Office and, ultimately, to the Commission. What can be stated is narrower: whether framed as a voluntary Preparedness Framework act or as an Article 55(1)(a) evaluation obligation, the underlying documentation remains, at this stage, entirely in OpenAI's own custody, produced by OpenAI, dated by OpenAI, and disclosed to the public only in summary form.

V. WHAT WOULD CHANGE, AND WHAT WOULD NOT

External testing, if and when it occurs, would add a second, independent data point. It would not, on its own, resolve the prior question: what the evaluation record said, and when it said it, before that external testing began. A regulator investigating this sequence after the fact — under Article 55, under a national supervisory power, or in litigation following an eventual incident — would still be examining a record that, on the facts publicly disclosed, only one party held at the moment it mattered; nothing in the disclosure indicates that any independent party held or co-held that record at the time. This is the pattern already documented across this series in other frontier-model disclosures: the account of a critical technical determination is authoritative only to the extent the public is willing to accept the word of the party whose exposure the determination concerns.

VI. THE GAP SOURCE 0 ADDRESSES

SOURCE 0 does not evaluate whether a model is dangerous, and it does not audit code. It is a pre-execution cryptographic attestation architecture: it seals a defined evidentiary record — a hash-sealed, timestamped Historical Reality Dossier — at a chosen moment, before the events it will later be used to establish. Applied to a sequence of the kind described here, SOURCE 0 would not change what an evaluation shows. It would fix, independently of the party whose model is being evaluated, what the evaluation record contained at the moment it was sealed, and would make that anteriority verifiable by a third party without depending on the evaluating organisation's own subsequent account. SOURCE 0 does not qualify the technical accuracy of that record — whether the evaluation itself was well designed or correctly run remains outside its scope. It fixes the record's sealed state, not its substance. The gap this closes is not scientific. It is evidentiary: the difference between a determination the public is asked to believe, and a determination the public — or a court — can independently verify was made when, and on the basis of what, its author says it was.

CLOSING AXIOM

A threshold crossed in private, and disclosed afterward in summary, is a statement. Only a record fixed before disclosure, and verifiable independently of its author, is proof.

REFERENCE NOTE

SOURCE 0 is a proprietary evidentiary architecture authored by Jean-François ELSEN. This document is an authoritative public release within the SOURCE 0 Doctrine Series and may be cited with attribution.

REGULATORY NOTICE

This article states no position on whether Astra meets or will meet the Critical cybersecurity threshold under OpenAI's Preparedness Framework, nor on whether Astra qualifies or will qualify as a general-purpose AI model with systemic risk under Article 51 of Regulation (EU) 2024/1689. Both determinations are reserved to OpenAI's own ongoing evaluation and, as applicable, to the AI Office and the European Commission. The SOURCE 0 CERTIFIED attestation, where issued, is delivered by Jean-François ELSEN in his capacity as author and constitutes an obligation of means, not an independent third-party certification.


FREQUENTLY ASKED QUESTIONS

Is Astra confirmed to have "Critical" cybersecurity capabilities?

No. OpenAI has stated that its preliminary evaluations cannot rule out the Critical threshold defined in its own Preparedness Framework. Benchmarking and assessment were, as of the disclosure, still underway, and OpenAI has not stated that the threshold has been confirmed as crossed.

What does OpenAI's Preparedness Framework require once a model reaches the Critical threshold?

Under the framework, a Critical designation triggers stricter internal security controls, isolated testing environments, restricted network and tool access, and a pause on internal activity that does not meet the strengthened requirements — the measures OpenAI describes having implemented for Astra.

Who, other than OpenAI, has verified the evaluation results behind this determination?

As of this writing, no external party has independently verified the state of Astra's evaluation record at the time OpenAI concluded it could not rule out Critical capability. OpenAI refers to unnamed "expert assessments" alongside its internal evaluations, without specifying whether those experts examined the underlying record or a summary of it. This is precisely the kind of disputed anteriority — what a record showed, and when — that SOURCE 0's pre-execution sealing is designed to make independently verifiable, rather than dependent on the evaluating party's own account.

Does the EU AI Act already require this kind of evaluation?

Article 55(1)(a) of Regulation (EU) 2024/1689 requires providers of general-purpose AI models with systemic risk to perform standardised model evaluation, including documented adversarial testing to identify and mitigate systemic risk, during the development phase and not only after a model is placed on the market. Whether Astra falls within that classification, and whether OpenAI's internal process satisfies the obligation, are questions reserved to the AI Office and the Commission.

Will the planned testing by government agencies and safety organisations settle the question?

It will add an independent data point from the moment that testing occurs. It cannot, by itself, establish what the evaluation record showed weeks or months earlier, when OpenAI made its initial determination, on a model whose configuration remains under OpenAI's own control throughout the intervening period. Only a record sealed before that determination was made, and verifiable independently of OpenAI, would fix that anteriority — which is the specific function SOURCE 0 performs.

Can an organisation adjust or supplement an internal evaluation record before external testers examine it?

Nothing in the public disclosure excludes this possibility, and nothing confirms it either — the record remains under the sole custody of the party being evaluated until it is shared. This is the structural condition SOURCE 0 is built to remove: a Historical Reality Dossier sealed before the fact cannot be altered afterward without the alteration itself becoming detectable.

What would make a Critical-capability determination opposable, rather than merely credible?

Opposability requires that the evidentiary record behind the determination be fixed, independently of the party whose exposure the determination concerns, before that party's own account of it is published — and that the fixation itself be verifiable by a third party without reliance on the evaluating organisation. SOURCE 0 provides that fixation through pre-execution cryptographic sealing and deposit establishing date certaine before a Belgian huissier de justice, not through an opinion on the model's actual capabilities.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - THE PRECAUTION NO ONE CAN DATE

Suivant
Suivant

SOURCE 0 - THE AUDIT TRAIL THAT REPLACED THE SEAL