Blog

Claude vs OpenAI: What 'Critical Cyber Capabilities' in Frontier AI Means for AU Business Security

August 2026 · 4 min read · AI Strategy

A terracotta shield beside a magnifying glass, representing AI vendor security diligence
← Back to all posts

OpenAI disclosed on 7 August that Preparedness Framework evaluations of an upcoming model could no longer rule out what it calls critical cyber capabilities, meaning the model may be capable enough at offensive cyber tasks that it needs additional safeguards before wider release. This is a formal safety-framework disclosure from the lab itself, not a leak or a rumour, and it's worth an AU business actually reading rather than skimming past as background AI news.

What OpenAI actually said

Frontier labs publish safety frameworks that define capability thresholds, points at which a model is judged capable enough at a specific dangerous task, like offensive cyber operations, biological weapons uplift, or autonomous replication, that it needs extra safeguards before release. OpenAI's disclosure is that an upcoming model's cyber capability evaluation came back close enough to that threshold that they can't confidently rule it out, triggering additional review rather than a straightforward release.

Why this is worth AU businesses paying attention to

  • It's a signal that frontier AI capability is genuinely approaching thresholds labs themselves consider risk-relevant, not just marketing language about "powerful new models"

  • It's exactly the kind of disclosure that should prompt a business to ask any AI vendor what safety framework and red-teaming underpins the specific model being deployed

  • It applies to vendor evaluation broadly, this isn't unique to one lab or one model, and the right response is a better vendor-diligence habit, not vendor-switching based on one headline

  • Businesses adopting AI for anything security-adjacent, code review, infrastructure management, access-control decisions, have a direct reason to ask these questions before deployment, not after

Where Anthropic's approach sits as a parallel, not a guarantee

Anthropic publishes its own Responsible Scaling Policy, a comparable framework defining capability thresholds and the safeguards that kick in as models approach them. That's a genuinely relevant parallel to OpenAI's disclosure, evidence that formal capability-threshold evaluation is now standard practice among frontier labs, not evidence that any specific model, Claude included, is risk-free. No credible AI safety framework, from any lab, claims to eliminate risk entirely; they're built to manage and disclose it as capability increases.

The questions worth asking any AI vendor

Before deploying any frontier model for security-adjacent work, code review, infrastructure access, data handling with real compliance stakes, ask what safety framework the vendor publishes, what red-teaming has been done on the specific model version you'd deploy, and what safeguards apply as capability increases. These aren't gotcha questions, they're the same due-diligence questions any AU business should ask about any vendor with access to sensitive systems, AI or otherwise.

What this means in practice for a deployment decision

A model's raw capability score on a benchmark tells you less than how the vendor's own safety process treats that capability. A lab that discloses when it can't rule out a risk threshold, as OpenAI did here, is at minimum demonstrating the kind of formal evaluation process worth expecting from any vendor. Treat the disclosure itself as a data point about process maturity, not primarily as a reason to avoid that specific vendor.

Keeping this in proportion

This disclosure concerns an upcoming model under evaluation, not a claim that currently deployed, widely used models pose an active undisclosed risk. The appropriate response for most AU businesses is a better vendor-diligence checklist for future deployments, not a re-evaluation of every AI tool currently in production based on a single disclosure about a different, not-yet-released model.

What a proper diligence pass actually costs

A structured AI vendor security review, safety framework check, deployment scoping, access-control design, typically runs a fraction of what a single security incident costs an AU business to remediate; incident response and breach-notification costs for a mid-market business routinely run past $80,000 once legal, technical and reputational costs are counted. Treat the diligence step as cheap insurance against a genuinely expensive outcome, not an optional extra step slowing down adoption.

What this isn't

This isn't a claim that Claude is safer than OpenAI's models in some verifiable, measured sense, that comparison isn't something we can responsibly make from public disclosures alone, and any vendor claiming otherwise should be treated with real scepticism. It's also not a suggestion that frontier AI is broadly unsafe for business use, it's a reminder that capability-threshold disclosures are becoming a normal part of the landscape and deserve a normal vendor-diligence response, not panic and not indifference.

Getting started

  • Add safety-framework and red-teaming questions to your standard AI vendor evaluation checklist

  • Ask specifically about the model version you'd actually deploy, not the vendor's general safety marketing

  • Keep human review on anything genuinely security-adjacent, code with production access, infrastructure changes, regardless of vendor

  • Revisit vendor evaluations periodically as models and disclosures evolve, this isn't a one-time check

If you want a genuinely independent look at what safety and security diligence actually applies to your specific AI deployment, that's a conversation we have with AU businesses regularly. Get in touch: https://www.automataai.com.au/contact

Ready to move from AI pilot to production?

We help mid-market Australian businesses deploy AI automations that actually reach production and deliver measurable ROI.