OpenAI slowed development of its Astra model after the system reached what the company calls a critical cybersecurity threshold. Translation: the model got good enough at hacking that its creators got scared. Meanwhile, security researchers scanning the Polish public web found courts, hospitals, and airports running on vulnerable content management software. The threat Astra could theoretically pose is already latent in the infrastructure we built before anyone thought to worry about it.

The Gap Between AI Capability and Infrastructure Readiness

This is not a coincidence, it is a structural condition. Governments digitized their operations on the cheap, layering CMS software on top of legacy systems without hardening anything underneath. A 2022 paper in IEEE Security and Privacy by Baki and colleagues found that public sector entities consistently underinvest in patch management relative to private-sector counterparts by a factor of nearly three. Now Cloudflare has launched Kitesurf, a browser built specifically for AI agents to navigate the web autonomously. We are handing AI a vehicle optimized for a road network full of potholes and no guardrails.

Slowdowns as Policy Proxies

The deeper issue is governance by internal memo. OpenAI's decision to pump the brakes is commendable in isolation, but it exposes just how much critical infrastructure security currently depends on the voluntary restraint of private labs rather than enforceable standards. The Polish vulnerability story is a preview of what happens when that restraint ends, or when a less scrupulous lab doesn't bother applying it. The question isn't whether Astra can hack a hospital. It's whether any hospital will be ready when something like Astra eventually does.