OpenAI released its latest model, GPT-6 Astra, this week, and buried inside the announcement is a genuinely significant milestone: it’s the first AI system to cross OpenAI’s own “Critical” threshold for cybersecurity capability. In testing, Astra scored 100% on a benchmark of real-world exploit development tasks and discovered two previously unknown zero-day vulnerabilities on its own. It can write working privilege-escalation exploits and achieve code execution against hardened, patched systems. OpenAI has restricted the public version to defensive tasks only, refusing to generate proof-of-concept exploits, with fuller offensive capability reserved for vetted security researchers through a new program called Daybreak.
This matters to UK SMEs for a simple reason: the same underlying capability eventually filters down, gets replicated by competing labs, or turns up in a jailbroken or open-source form. The gap between “an AI that can find and patch a vulnerability for defenders” and “an AI that criminals use to find and exploit one” is a policy decision inside one company, not a technical barrier. Security researchers are already warning that this kind of capability compresses the time between a vulnerability being disclosed and it being actively exploited in the wild, from weeks down to days or hours.
Why “critical” doesn’t mean “irrelevant to me”
It’s tempting to read a story about frontier AI models and zero-day exploits as something for enterprise security teams, not a five-person consultancy or a local retailer. But the pattern with every previous leap in attacker capability, automated phishing kits, ransomware-as-a-service, AI-written scam emails, has been the same: it reaches small businesses faster than defenders adapt, because attackers automate their tooling and go after the largest possible number of targets, not just high-value ones. An AI that can find and exploit an unpatched vulnerability doesn’t care whether the server it’s attacking belongs to a FTSE 100 company or a ten-person accountancy firm. It just needs the vulnerability to be there.
What actually reduces your exposure
The uncomfortable truth is that faster, AI-assisted attacks make the basics matter more, not less. Unpatched software is the single biggest target for exactly this kind of automated exploitation, and it’s also the cheapest thing to fix. If your business runs any public-facing system, a booking portal, a customer login, an old admin panel, patching cadence needs to move from “when we get round to it” to a scheduled, owned responsibility. The NCSC’s free scanning service, launched only days ago, is one useful early-warning layer, but it won’t catch everything, and it’s reactive by nature.
For businesses without the internal expertise to judge what’s actually exposed and how urgently it needs attention, this is a reasonable moment to bring in outside help rather than guess. CoolCoding can audit what your public-facing systems are actually running and get anything out of date patched before an automated attacker finds it first, and KeepSafe provides the ongoing monitoring that catches exposure between audits, which matters more as the tools attackers use get faster.
The other side of the same coin
It’s worth remembering that this same capability is being built, first and primarily, as a defensive tool. AI that can find your own vulnerabilities before an attacker does is a genuine advantage for smaller businesses that could never afford a full-time penetration testing team. The businesses that benefit are the ones that treat AI-assisted security scanning as a new, affordable layer of defence, not the ones that assume a scarier-sounding headline means there’s nothing to be done.
The takeaway
A model that can write its own exploits is a real shift in the threat landscape, but it doesn’t change the fundamentals of good security, it just raises the cost of skipping them. Patch promptly, know what’s exposed to the public internet, and treat AI-assisted scanning tools, defensive ones aimed at you, not just the offensive ones aimed at everyone else, as worth adopting now rather than later.