8/11/2026, 1:04:24 PM · defense-government

OpenAI Expands Daybreak With GPT-5.6-Cyber Model for Advanced Security Tasks

OpenAI restructured its Daybreak cybersecurity program into two access tiers and introduced GPT-5.6-Cyber, a purpose-trained model built to help vetted defenders conduct exploit validation and vulnerability research before threat actors deploy offensive AI at scale.

OpenAI on August 10, 2026, announced an expansion of its Daybreak cybersecurity program, restructuring it into two access tiers and releasing a new purpose-built Large Language Model (LLM), GPT-5.6-Cyber, designed for authorized vulnerability research, exploit validation, and advanced security testing.

Program Structure

<cite index="2-1">OpenAI expanded its Daybreak program to give vetted security defenders deeper access to frontier AI models, introducing two access tiers—Daybreak Blue and Daybreak Red—alongside GPT-5.6-Cyber, purpose-built for exploit validation, vulnerability research, and red teaming.</cite> <cite index="2-3">Daybreak Blue is designed as the recommended entry point for most defenders, offering access to GPT-5.6 Sol with safeguards tailored for authorized defensive work such as vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.</cite> <cite index="2-4">Daybreak Red goes further, unlocking purpose-trained cybersecurity models for advanced vulnerability research, exploit validation, and security testing under stricter vetting.</cite>

<cite index="5-2">OpenAI is also expanding how program members can use its tools, allowing companies like Accenture, IBM, CrowdStrike, Cisco, and Palo Alto Networks to incorporate the models into security products, managed services, and work with customers.</cite>

Model Capabilities and Benchmarks

<cite index="7-14">GPT-5.6-Cyber is based on GPT-5.6 Sol and was specifically trained to perform better on tasks like finding zero-day vulnerabilities and building exploit chains.</cite> <cite index="2-5">OpenAI's internal Advanced Cybersecurity Completion Rate (ACCR) benchmark, which measures willingness to assist with exploit-chain development, authentication bypass, and privilege escalation tasks, shows GPT-5.6-Cyber completing 95% of such requests compared to just 1.5% for the standard safeguarded GPT-5.6 Sol and 2% under Daybreak Blue access.</cite> <cite index="2-6">That marks a substantial jump from its predecessor, GPT-5.5-Cyber, which completed only 57.3% of comparable requests, addressing persistent complaints from security researchers about excessive model refusals during legitimate work.</cite>

<cite index="3-9">On ExploitGym2, which evaluates whether agents can turn known vulnerabilities into working exploits that achieve arbitrary code execution in controlled environments, GPT-5.6-Cyber outperforms both GPT-5.6 Sol and GPT-5.5-Cyber.</cite>

Real-World Vulnerability Findings

<cite index="23-3,23-4,23-5,23-6,23-7">Since GPT-5.6-Cyber finished training, OpenAI used it to investigate V8, the JavaScript engine used by Chrome, uncovering two previously unknown vulnerabilities that could be chained to corrupt memory and escape the V8 heap sandbox. Researchers validated the findings and reported them to Google through coordinated vulnerability disclosure. Google fixed the vulnerability, assigning it CVE-2026-15903.</cite> <cite index="22-5">Additional findings include five vulnerabilities in a major mobile operating system (including a privilege-escalation chain from untrusted apps), three critical remote code execution issues in a widely used database, and over 400 privilege-escalation flaws in a popular operating system kernel.</cite>

Safety Classification and Access Controls

<cite index="23-1,23-2">Under OpenAI's Preparedness Framework, GPT-5.6 Sol was assessed as "High" for cybersecurity capability and below the "Critical" threshold. Before launching GPT-5.6-Cyber, OpenAI also evaluated its frontier cyber capabilities and determined it similarly reaches the "High" threshold but not the "Critical" threshold.</cite> <cite index="24-8">The "High" threshold means a model can remove existing bottlenecks to scaling cyber operations, automate end-to-end operations against reasonably hardened targets, or automate the discovery and exploitation of operationally relevant vulnerabilities.</cite>

<cite index="20-5,20-6">To mitigate misuse risks tied to reduced safeguards, OpenAI is mandating hardware security keys for all individual Daybreak accounts starting September 1, 2026, pushing Codex users toward auto-review mode instead of full-access mode, and rolling out enhanced monitoring in the coming weeks. Access to Daybreak Blue and Red is restricted to approved individuals and organizations conducting authorized security work, gated by identity verification, monitoring, and legal attestations.</cite>

Public-Private Defense Context

<cite index="2-2">The move is a direct response to a widening gap between attacker and defender capabilities, as OpenAI warns that threat actors will increasingly use AI to launch cyberattacks at unprecedented speed and scale, including fully autonomous operations.</cite> The Daybreak expansion builds on a broader pattern of OpenAI deepening its government and defense partnerships. <cite index="9-3">In May, Accenture Federal Services and OpenAI announced a collaboration to help U.S. federal agencies move AI from experimentation to production-ready deployment, including through the launch of an agentic lab and FedRAMP-aligned implementation pathways.</cite> <cite index="11-7">OpenAI has stated it believes democratic societies should be able to use AI to protect people, defend critical infrastructure, deliver public services, and respond to emerging threats, including in areas like cyber defense where AI can meaningfully advantage defenders.</cite>

Cross-references

Sources

  1. [1]
    OpenAI launches GPT-5.6 Cyber for advanced security research | Digital Watch Observatory
  2. [2]
    OpenAI Expands Daybreak Cyber with GPT-5.6 for Exploit Validation, Pentesting, and Red Teaming
  3. [3]
    Expanding Daybreak as the Cyber Defense Window Narrows | OpenAI
  4. [4]
    OpenAI launches GPT-5.6-Cyber and expands Daybreak with Red and Blue access tiers - Neowin
  5. [5]
    OpenAI unveils GPT-5.6-Cyber to help prepare for AI cyberattacks
  6. [6]
    Daybreak: Tools for securing every organization in the world | OpenAI
  7. [7]
    OpenAI launches GPT-5.6-Cyber to help defenders find vulnerabilities before attackers do
  8. [8]
    Introducing OpenAI for Government | OpenAI
  9. [9]
    Booz Allen Hamilton, OpenAI Team Up to Accelerate Secure AI for National Security Missions – ExecutiveBiz
  10. [10]
    Working with US CAISI and UK AISI to build more secure AI systems | OpenAI
  11. [11]
    Our approach to government and national security partnerships | OpenAI
  12. [12]
    aihzn.substack.com
  13. [13]
    bizwire 2025 2 28 openteams proudly partners with the open source ai foundation o saif to promote safety and transparency of ai in us government
  14. [14]
    OpenAI partners with U.S. National Laboratories on scientific research, nuclear weapons security
  15. [15]
    OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window | CSO Online
  16. [16]
    OpenAI Expands Daybreak With Two Tiers and a New Cybersecurity Model – Unite.AI
  17. [17]
    OpenAI Expands Daybreak With GPT-5.6-Cyber for Trusted Offensive Security Research
  18. [18]
    OpenAI Expands Daybreak With GPT-5.6-Cyber, Its Most Permissive Cybersecurity Model Yet — Glitchwire