AI GlossaryㅈSafety and controversy
Zero-day Exploit
An attack method that finds and actually breaks into a software security hole nobody knows about yet
In plain words
A zero-day exploit is an attack method that finds a security hole in software that even the developer doesn't know about yet, and uses it to actually break in. It's like someone discovering a hidden door in your house that nobody knew existed, and quietly slipping in through it before anyone else finds out. The term "zero-day" comes from the fact that once the hole becomes known, the defending team has had zero days to fix it.
What matters here is that "finding" a hole and "actually making it usable" are two different things. There's a big gap between knowing a hole exists and building the key (the attack code) that can actually get through it. That's why the security industry treats the ability to simply discover a vulnerability separately from the ability to turn it into something that actually works.
The current question is whether AI models can now do both steps on their own, without human help. If an AI can find, in a much shorter time and at much greater scale, holes that used to take skilled security experts weeks to uncover — and immediately turn them into working attack code — then defenders end up with that much less time to prepare.
How it shows up in the news
The article reports that OpenAI rated the risk level of its upcoming model, Astra, based on whether it "can identify and develop functional zero-day exploits of all severity levels across a range of real-world critical systems without human intervention." A common misunderstanding here is that this isn't about AI creating new flaws — it's a benchmark for how quickly AI can find holes that already existed in the software and turn them into actual working attack tools.
See also
Stories using this term
- OpenAI's Astra Nears Launch Carrying 'Critical' Cyber RatingAI · 2026.09.02
- OpenAI unveils GPT-5.6-Cyber, a model dedicated to cybersecurityAI · 2026.08.11
- OpenAI disbands catastrophic-risk team, scatters its work across departmentsBusiness · 2026.08.16
- GPT-6 Astra's first 48 hours bring real-world use from architecture to roboticsThe Lab · 2026.09.06
- Open Secure AI Alliance Proposes SAFE GuidelinesBusiness · 2026.08.09
- OpenAI's Upcoming Model Astra Flags Potential 'Critical' Cyber CapabilityAI · 2026.08.08
