OpenAI is significantly expanding its cybersecurity offering. The company is introducing a new model called GPT-5.6-Cyber, splitting its Daybreak security program into two access tiers, and growing the associated partner network. Participants include IBM, Accenture, Cisco, CrowdStrike, Palo Alto Networks, Cloudflare, PwC, and KPMG, which can integrate OpenAI's cyber models into their own products and client projects.
Two tiers for Daybreak
Daybreak launched in June as an umbrella program for OpenAI's cybersecurity offerings, giving vetted individuals and organizations controlled access to especially capable AI models for security work. Going forward, there are two levels. Daybreak Blue provides general flagship models like GPT-5.6 Sol, but with reduced system-side safeguards for authorized security work. Daybreak Red targets more demanding tasks such as vulnerability research, exploit validation, and security testing, and opens access to models trained specifically for cybersecurity. That includes GPT-5.6-Cyber, which is available exclusively through Daybreak Red and, after GPT-5.4-Cyber and GPT-5.5-Cyber, is already the third model tailored to security.
Strengths in exploits and zero-days
GPT-5.6-Cyber is based on GPT-5.6 Sol but was trained specifically for difficult security tasks, particularly the search for previously unknown zero-day vulnerabilities and the development of exploit chains. Where Daybreak Blue only relaxes GPT-5.6 Sol's safeguards for authorized work, GPT-5.6-Cyber was additionally trained to refuse cooperation far less often on sensitive dual-use tasks that can be used both defensively and offensively.
The model also shows advantages in benchmarks. On ExploitGym, which tests the development of working exploits for known vulnerabilities in isolated test environments, it outperforms both GPT-5.6 Sol and GPT-5.5-Cyber. In an internal test for discovering unknown zero-days, it also comes out ahead. OpenAI also turned the model loose on real software. In Google's V8 JavaScript engine, it found two previously unknown vulnerabilities that, according to OpenAI, could be combined to manipulate memory and break out of the V8 heap sandbox. Both were reported to Google, and one has already been fixed. Beyond that, the company claims to have found at least five vulnerabilities in a widely used mobile operating system, three critical flaws in a widely used database, and more than 400 privilege-escalation vulnerabilities in a widely used operating system kernel. OpenAI doesn't name the affected products.
Tighter controls after the Hugging Face incident
Access to Daybreak Blue and Red remains limited to vetted individuals and organizations with authorized security tasks. OpenAI relies on identity verification, monitoring, and additional account security, and plans to tighten those safeguards further. The measures follow shortly after an incident in which OpenAI models autonomously compromised Hugging Face systems during security testing. According to the company, GPT-5.6-Cyber wasn't involved. Since then, OpenAI has tightened its internal security controls and temporarily suspended certain activities with the unreleased model Astra, for which it can't rule out critical cyber capabilities.