OpenAI Launches Legal Astra AI While Flagging Critical Cybersecurity Capabilities in GPT-6

Astra for Law’s legal index spans more than 230 million URLs, with sources added daily; its case-law content is supplied by the nonprofit Free Law Project’s CourtListener database.
On OpenAI’s reported validation set, Astra for Law answered 54% of 200 legal-research questions correctly, compared with 38.7% for GPT-6 Astra using general web search. OpenAI also said the legal configuration found 24% more relevant cases and retrieved up to 54% more target passages from the correct opinions on a separate audited set.
OpenAI said it developed and tested legal applications with Sullivan & Cromwell, Ropes & Gray, Cooley, Latham & Watkins and Wachtell Lipton, in addition to naming Harvey and Legora as legal-AI companies able to build products on the platform.
In supervised cybersecurity testing, GPT-6 Astra found previously unknown vulnerabilities in a browser and an operating-system kernel. It reportedly built a browser exploit chain that achieved unsandboxed code execution in 29 hours, adapted it to the official stable release within another 12 hours, and developed a local privilege-escalation exploit against the kernel within 12 hours.
OpenAI’s Preparedness Framework defines the Critical cybersecurity threshold as either the ability to identify and develop functional zero-day exploits across many hardened real-world critical systems without human intervention, or the ability to execute end-to-end novel attacks against hardened targets from only a high-level goal.
OpenAI launched Astra for Law, a specialized version of its GPT-6 Astra model designed for legal research and document drafting. The platform combines the AI model with an index of more than 230 million URLs of U.S. legal materials, including case law from the nonprofit Free Law Project's CourtListener database Benzinga. On OpenAI's tests, Astra for Law answered 54% of legal questions correctly, compared with just 38.7% for the general GPT-6 Astra TipRanks.
OpenAI also announced that GPT-6 Astra reached its "Critical" cybersecurity tier — the highest level on its safety framework. In supervised testing, the model found unknown vulnerabilities in web browsers and operating systems, then built working exploit chains to attack them SiliconAngle. The company restricted these advanced cyber capabilities to selected users due to their potential risks.
Astra for Law pulls from a massive database spanning more than 230 million URLs of legal documents, statutes, regulations, and case law. New sources are added daily to keep the index current NDTV. The legal configuration dramatically outperforms the general GPT-6 Astra model on legal tasks.
On OpenAI's validation test of 200 legal-research questions, Astra for Law found 24% more relevant cases than the standard model. It also retrieved up to 54% more target passages from the correct legal opinions TipRanks. Selected law firms including Sullivan & Cromwell, Cooley, and Wachtell Lipton tested the platform before launch.
OpenAI is rolling out Astra for Law only to selected law firms and legal-technology companies in the early phase. Initial access is restricted as the company manages demand and refines the platform Benzinga. Integrations with legal software like Relativity, Clio, and Thomson Reuters allow firms to embed the AI into their existing workflows.
The platform includes strong privacy defaults. API data is not retained by OpenAI, and enterprise data is excluded from human review by default SiliconAngle. These safeguards address customer concerns about confidentiality and data handling — critical issues for law firms managing sensitive client information.
GPT-6 Astra became the first model OpenAI classified as reaching "Critical" on its cybersecurity scale. In supervised evaluations, the model identified previously unknown vulnerabilities in a major web browser and an operating-system kernel NewsBytes. It then built functional exploit chains — step-by-step attack sequences — to compromise both systems.
The model developed a browser exploit that achieved unsandboxed code execution in 29 hours, adapted it to the stable release in 12 more hours, and created a kernel privilege-escalation exploit in 12 hours SiliconAngle. OpenAI's Preparedness Framework defines "Critical" as the ability to identify and develop zero-day exploits independently across hardened systems. These capabilities remain restricted to vetted users only.
Publishers
27
Articles
16
Reach
43