← All posts

AI Can Now Build Its Own Weapons — And Regulators Just Started the Clock

On September 3, OpenAI released GPT-6 Astra — the first AI model the company has ever rated "Critical" under its own Preparedness Framework. In plain language: Astra can find zero-day vulnerabilities in hardened, real-world systems and write working exploits without a human guiding each step. During pre-release testing it scored 100% on ExploitBench, the industry benchmark for exploit development, and discovered two previously unknown vulnerabilities on its own.

Four days from now, on September 11, the EU Cyber Resilience Act's mandatory vulnerability reporting obligations go live. Every manufacturer that ships a product with digital elements into the EU — software, IoT devices, networking gear, medical equipment — must report actively exploited vulnerabilities to ENISA within 24 hours of becoming aware.

These two events are not a coincidence. They are a collision. And if you sit on a board or run a company, the question is no longer whether AI changes your cyber risk profile. It is whether your organization can move fast enough to keep up.

The Threat Just Got Autonomous

Let's be specific about what Astra represents. Previous AI models could assist a skilled attacker — suggesting techniques, writing snippets of code, accelerating research. Astra is different. OpenAI's own testing found it can autonomously discover previously unknown security weaknesses and build functional exploits against well-defended systems. It scored 39% on novel vulnerabilities from the prior three months — meaning it could independently find and exploit bugs that human researchers had only just discovered.

OpenAI delayed the release to strengthen safeguards. Astra refuses 91.5% of malicious cyber requests in jailbreak evaluations, up from 59% for its predecessor GPT-5.6 Sol. That improvement matters. But here is the board-level takeaway: if the safety-tuned version of this model can find zero-days, what can a fine-tuned open-source equivalent do in six months? The capability is out of the bottle.

This is the scenario I describe in Cyber Risk Is Business Risk when I talk about the speed asymmetry between attackers and defenders. AI compresses the timeline between discovery and exploitation, making every attack faster. Your security team's patching window just got shorter. Your incident response playbook just got more urgent. And the board's oversight responsibility just got heavier.

The Regulatory Pincer

While the threat accelerates, regulators are tightening the other side of the vise. The EU Cyber Resilience Act's reporting obligations, effective September 11, require manufacturers to file an early warning within 24 hours of learning about an actively exploited vulnerability, a full notification within 72 hours, and a final report within 14 days of deploying a fix. Reports go through ENISA's new Single Reporting Platform, which launches the same day the mandate takes effect.

This is not a narrow regulation. It covers every product with digital elements sold in the EU — including legacy products already on the market. If you do not have a Software Bill of Materials and a vulnerability management process in place today, you cannot comply on Thursday.

Meanwhile, in the U.S., board oversight of cybersecurity is now nearly universal among large-cap companies — approximately nine in ten Russell 1000 companies disclosed cybersecurity oversight through June 2026, according to Glass Lewis proxy season data. But AI governance lags behind: only about 21% of those same companies have a formal AI policy, up from roughly 15% in 2025. Beginning with the 2026 proxy season, BlackRock, ISS, and Glass Lewis expect companies to demonstrate how their boards oversee both AI and cyber risk in proxy disclosures.

The gap between cybersecurity oversight and AI governance is exactly where risk accumulates. A board that can explain its firewall strategy but cannot articulate its position on autonomous AI capabilities is a board that has not caught up to the threat.

Three Questions for Your Next Board Meeting

In Cyber Risk Is Business Risk, I outline the Three Questions framework — the essential questions every board member should be able to answer about their organization's cyber posture. This week's news sharpens all three:

1. What is our exposure? If your products ship into the EU, your exposure now includes a 24-hour reporting clock that starts the moment you learn of an exploited vulnerability. If your development teams use AI coding assistants, your exposure includes the possibility that AI-generated code introduces novel attack surfaces. Ask your CISO: do we have an inventory of every product subject to the CRA, and do we have SBOMs for each one?

2. What are we doing about it? Patching cycles built for a world where human researchers find vulnerabilities over weeks are not adequate when AI can find and weaponize them in hours. Ask your CISO: what is our mean time to patch for critical vulnerabilities, and what would it need to be in a world of AI-accelerated exploitation?

3. How do we know it is working? Compliance is not security, but non-compliance is now a measurable liability. The CRA carries penalties of up to 15 million euros or 2.5% of global annual turnover, whichever is higher. Ask your CISO: can we demonstrate — to regulators, to insurers, to shareholders — that our vulnerability management process meets the new reporting timelines?

What to Do This Week

If the EU CRA applies to your organization, September 11 is not a future problem — it is this Thursday. Confirm that your legal and security teams have registered on the ENISA Single Reporting Platform. Verify that you have an internal process that can triage, validate, and escalate an exploited vulnerability within a single business day. And make sure the board knows that this obligation exists, because if a reportable incident occurs and the company misses the 24-hour window, the question will not be "why didn't IT know?" It will be "why didn't the board ensure we were ready?"

On the AI side, the conversation is longer but equally urgent. GPT-6 Astra is not the last model that will cross this threshold — it is the first. Every organization needs a position on how it will defend against AI-powered attacks, how it will govern its own use of AI, and how it will communicate that position to investors, regulators, and customers. The 79% of Russell 1000 boards without a formal AI policy are running out of runway.

The collision of autonomous AI capability and mandatory reporting is the new normal. The organizations that treat this week as the starting gun — not a one-time compliance exercise — will be the ones still standing when the next model drops.