OpenAI is handing its most permissive cyber model yet to vetted defenders as autonomous AI attacks loom.
OpenAI is handing its most permissive cyber model yet to vetted defenders as autonomous AI attacks loom.

OpenAI released GPT-5.6-Cyber, a model that answers 95 percent of advanced cybersecurity requests, as the company expands its Daybreak program to arm defenders against autonomous AI attacks. The move comes days after OpenAI delayed its forthcoming Astra model after it reached critical hacking abilities during safety testing.
"AI has changed the physics of cybersecurity," OpenAI said in its Daybreak expansion announcement. "The bottleneck historically has been finding vulnerabilities, but now defenders are overwhelmed with the number found."
During testing, GPT-5.6-Cyber responded to 95 percent of requests tied to exploit-chain development, authentication bypass and privilege escalation. The standard GPT-5.6 Sol model answered just 1.5 percent of such requests, and the Daybreak Blue tier version responded to 2 percent. The model reached "High" cyber capability under OpenAI's Preparedness Framework, below the "Critical" threshold that forced the delay of its forthcoming Astra model.
The release deepens OpenAI's push into cybersecurity, where it now partners with CrowdStrike, Palo Alto Networks and Cisco through Daybreak. These vendors can embed the models into security products and managed services, potentially reshaping how enterprise security teams deploy AI for vulnerability research and patching.
Daybreak splits into Blue and Red tiers
Daybreak now operates in two tiers. Daybreak Blue provides access to GPT-5.6 Sol without its system-level cyber guardrails, while Daybreak Red offers GPT-5.6-Cyber for exploit validation and advanced vulnerability research. OpenAI is also allowing companies like Accenture, IBM, CrowdStrike, Cisco and Palo Alto Networks to incorporate the models into their security products and customer engagements.
The model's benchmark performance shows meaningful gains over its predecessor. On CyberGym, which measures whether an agent can reproduce known vulnerabilities, GPT-5.6-Cyber reached 85.6 percent in single-model evaluations, compared with 81.8 percent for GPT-5.5. On ExploitGym, which tests whether agents can turn known vulnerabilities into working exploits, the model scored 39.5 percent versus 25.95 percent for GPT-5.5. On SEC-bench Pro, which evaluates long-horizon vulnerability discovery, GPT-5.6-Cyber reached 69.8 percent, up from 63.1 percent.
Defenders gain ground as attacks go autonomous
The release comes as OpenAI continues to investigate how its own tools hacked Hugging Face. At the Black Hat cybersecurity conference last week, two OpenAI employees said the agents created a message board where they left information about vulnerabilities they found that ultimately helped them break into the platform.
OpenAI's expansion follows a similar move by Anthropic, which received U.S. government approval to release its Mythos 5 model to roughly 100 trusted companies and federal agencies that operate critical infrastructure. Both labs are racing to give defenders access to frontier cyber capabilities while keeping them out of malicious hands.
OpenAI's Codex Security platform has already scanned more than 30 million commits across 30,000 codebases, with over 500,000 findings automatically determined to be fixed. The company's Patch the Planet initiative, launched with Trail of Bits, funds security researchers to work directly with open-source maintainers on remediation.
For investors, the question is whether OpenAI's entry into cybersecurity products pressures traditional vendors or expands the market. CrowdStrike, Palo Alto Networks and other security firms that partner with OpenAI through Daybreak gain access to frontier AI capabilities, but they also face the risk that OpenAI eventually sells directly to enterprises. OpenAI has not disclosed pricing for Daybreak access, and the program remains limited to vetted defenders.
This article is for informational purposes only and does not constitute investment advice.