← Back to the blog AI Consulting · Toledo, Ohio

OpenAI's Newest Model Breaks Into Computers On Its Own. Being Small Won't Hide You.

Jayson Hines · September 3, 2026 · 4 min read

A guy at a session I ran out in Perrysburg last spring told me he wasn't worried about any of this because, his words, nobody's coming after a four truck plumbing company. I've heard some version of that line in almost every room I've stood in around here. And for a long time it wasn't a bad bet.

OpenAI put out a post Tuesday about a model they're calling Astra. They say it's the first one they've built that crosses what they call their critical cybersecurity threshold, which is their own internal line for a model capable enough that it needs extra handling before anybody gets it. In their testing, Astra found security flaws nobody knew about and exploited them without a person walking it through the steps. It scored a perfect 100 on a test called ExploitBench. On a harder version their own engineers built, it found two brand new holes on its own. They say it's going out soon, with the strongest parts limited to a smaller group.

Worth saying out loud: nobody outside OpenAI has checked any of this yet. They graded their own homework, and they didn't say who the outside testers are. But Anthropic said close to the same thing about one of their models earlier this year, so it's not one company talking itself up.

What actually changes for a small shop

The math is what's protected you up to now. A person had to sit down, look at your business, and decide you were worth a few hours of their time. You weren't. That's the whole reason a four truck plumbing company has gone twenty years without an incident.

Those hours are about to go to almost nothing. When finding a hole costs nobody anything, being small stops helping, because nobody has to pick you on purpose anymore. They point the thing at everything with an IP address and see what falls out.

So the way in isn't going to be some clever scheme aimed at you by name. It's going to be the thing on your network you forgot existed. The camera system the last guy installed in 2019. The router the cable company dropped off and nobody has touched since. The scheduling plugin on your website your nephew put in and then went off to college.

The afternoon list

None of this takes an IT budget. 1: Walk the building and write down every single thing that connects to the internet and has a login. Cameras, thermostats, the point of sale, the router, the printer, the door system. Most owners get to eight or nine items and realize they hadn't thought about half of them in years. 2: Turn on automatic updates for every one that offers it. That's the boring step and it's the one that matters most, because the automated stuff goes after known holes that already have a patch sitting there. 3: Anything on that list you don't actually use anymore, unplug it. An old camera server nobody watches is a free door. 4: Change the default passwords, which are still sitting right there on more Toledo shops than you'd want to know about.

That's an afternoon. It won't stop somebody who really wants into your business specifically, and I'm not going to pretend it does. What it does is take you out of the pile that gets swept up automatically, and for a small business that's most of the fight right there.

I'd rather people hear this now than after. Tools that work like Astra are going to end up behind a normal login screen inside a year or two, same as every other AI thing has gone. The shops that spent one afternoon on the boring list will be fine. The ones still running a 2019 camera server on the factory password are the ones calling me in a panic.

I run AI workshops and one-on-one AI consultations for companies around Toledo, Northwest Ohio, and Southeast Michigan, and walking a team through what's actually connected to their network is usually where we start. If you want a second set of eyes on your list, send it over.

Email Jayson