Skip to main content
Cybersecurity

OpenAI Bolsters Ukraine's Defenses with AI-Powered Cybersecurity Tools

OpenAI Bolsters Ukraine's Defenses with AI-Powered Cybersecurity Tools

“This is really not about protecting computers, it is about actually keeping our country running,” said Dmytro Kushneruk, setting the stakes for a new cybersecurity partnership between OpenAI and the Ukrainian government.

The Daybreak partnership and the $1 billion pledge

OpenAI and Ukraine on Wednesday announced a collaboration under the company’s Daybreak program that will give Ukrainian cybersecurity officials access to advanced AI models and subsidized computing resources. OpenAI said it is pledging over $1 billion in subsidized tokens to support the initiative. The announcement was made at OpenAI’s New York office.

What Ukrainian defenders plan to do with Daybreak

On a panel, Kushneruk, consul general of Ukraine in San Francisco, outlined specific uses for the tools: incident response, threat triaging, login analysis, inventorying systems, code analysis and validating vulnerabilities. He emphasized that the principal advantage is speed—AI can process “thousands and thousands” of logs at machine speed, surfacing what is important so human defenders can act faster. “This is why the object is not to replace the cyber defender with AI, but to make sure the cyber defender acts faster,” Kushneruk said.

Kushneruk framed the work in operational terms: these capabilities are intended to keep vital services functioning. He said Ukraine faces approximately 6,000 cyberattacks per year—about 15 per day—placing continual pressure on defenders and driving demand for automation that can triage, analyze, and validate at scale.

Context: a dozen years of attacks and evolving resilience

The partnership arrives against a long-running backdrop of attacks on Ukraine’s critical infrastructure. The source traces sustained cyberattacks and physical strikes over the past twelve years, and notes that since Russia’s 2022 invasion, Ukraine’s critical infrastructure “has been under constant threat.” While missiles remain a primary concern, preparations for cyber incidents date back further—Kushneruk pointed to the 2015 shutdown of Ukraine’s power grid by actors the source identified as the Russian GRU as a turning point. He said the country was “maybe not so much prepared” in 2015 but has improved, citing resilience in 2025 when trains kept running after an attack on the railway system.

U.S. conversations, congressional attention, and OpenAI’s public posture

National security voices in the U.S. have taken note. Naz Durakoğlu, minority staff director of the U.S. Senate Foreign Relations Committee, said there is “pretty much across the board” agreement for similar defensive AI adoption by U.S. critical infrastructure operators, though she added that regulatory issues remain sticking points. “This is something that’s already happening, and frankly, it’s just kind of a basic duty of government to make sure that when you turn the tap on, water comes out, the electricity doesn’t go out, and hospitals keep running and treating patients,” Durakoğlu said. She added that observing Ukraine’s daily experience provides a bipartisan wake-up call for lawmakers.

OpenAI has been publicly advocating for AI’s use in defensive cybersecurity. Company president and co-founder Greg Brockman signed an open letter earlier this year calling for “collective action” and widespread use of AI models to find and fix vulnerabilities before foreign governments and cybercriminals get access to the same capabilities. Politico reported that OpenAI CEO Sam Altman met with U.S. power companies in July to discuss using AI to protect electrical grids.

Sasha Baker, OpenAI’s national security policy head, described a sense of urgency inside the company to replicate the Ukrainian agreement with other governments and industries. “There’s this period of time where we’re really rushing to get [these tools] in the hands of critical infrastructure operators, of governments around the world, of people who want to patch systems, defend their networks, remediate vulnerabilities because we know as these tools proliferate out there in the ecosystems, there are going to be bad guys out there that also try to use them,” Baker said. “So, we have this window of time to take action and we’re really motivated by the idea that we need to act with some urgency.”

What this means for technologists, policymakers, and adversaries

  • Technologists and security teams: expect to integrate AI into routine defensive tasks—triage, log analysis, code review and vulnerability validation—where Kushneruk said AI’s speed could alter defenders’ operational tempo.
  • Policymakers and regulators: will weigh the “across the board” appetite for defensive AI that Durakoğlu described against outstanding regulatory questions about deployment and oversight.
  • Adversaries and threat actors: OpenAI’s own remarks acknowledge a narrow window to field defensive capabilities before similar tools become available to malicious actors, framing the partnership as an attempt to get protective AI into trusted hands first.

OpenAI’s Daybreak deal with Ukraine is thus both a practical security toolset for a country under sustained attack and a statement of intent by a major AI vendor about where it believes those tools should be deployed first. The company has signaled plans to pursue similar agreements elsewhere; the practical test will be whether that urgency turns into widespread, governed adoption by other governments and critical infrastructure operators.

Source: CyberScoop