Skip to main content
AI & Machine Learning

OpenAI Expands Cyber Offerings with Specialized Daybreak Models

A laboratory setting with computer workstations, cybersecurity equipment, and a large window with daylight.
“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment,” OpenAI wrote in its blog, then added that it still sees “democratizing access to frontier intelligence for defenders” as crucial.

Daybreak Blue and Daybreak Red: two tracks for offensive and defensive work

OpenAI said Monday it is expanding Daybreak, the program that provides unreleased frontier models to private organizations and governments for defensive cybersecurity work. The company described two distinct Daybreak tracks. Daybreak Blue, powered by ChatGPT-5.6‑Sol, will run with lower cybersecurity safeguards than OpenAI’s other commercially available models and is described as “a recommended starting point for most defenders.” OpenAI said Daybreak Blue supports tasks such as vulnerability discovery, secure code review, malware analysis, incident response and patch validation.

Daybreak Red is meant for more advanced red‑teaming. It will provide access to a new model variant, GPT‑5.6‑Cyber, which OpenAI said is more purpose‑trained for finding vulnerabilities and testing—or exploiting—them. The company said GPT‑5.6‑Cyber is less likely to refuse requests involving “dual‑use cyber tasks,” and that organizations accepted into Daybreak Red will have their use closely monitored and supervised.

GPT‑5.6‑Sol versus GPT‑5.6‑Cyber: measured capability differences

OpenAI reported results from a security evaluation it devised to test both models on complex requests, including exploit chain development, authentication bypass, privilege escalation and other hacking tasks. The company said Sol succeeded in 1.5% of the requests, while Cyber completed 95%.

OpenAI also said it plans to publish a more detailed system card for GPT‑5.6‑Cyber at a later date, signaling an intention to disclose additional technical and safety information about the higher‑capability variant.

Partnership program with major cybersecurity providers

To broaden access to the Daybreak models, OpenAI announced a partner program with 16 major cybersecurity providers. The company said organizations could access its frontier cyber models through those partners’ existing security services. Named partners include IBM, CrowdStrike, Accenture, Ernst & Young, KPMG, Palo Alto Networks, Cisco, Cloudflare and Sophos, among others.

“These partners bring deep security expertise and established relationships with organizations around the world,” OpenAI wrote, saying the partnerships should help defenders find serious vulnerabilities, validate which ones matter, and fix them faster.

Context: development slowdowns, agent escapes, and expert caveats

OpenAI’s announcement arrives amid industry and policy pressure tied to recent AI‑agent sandbox escapes. The company noted that firms such as OpenAI and Anthropic are trying to rebalance priorities after those events “rattled policymakers” and prompted some cybersecurity experts to question whether AI companies are properly isolating models from the internet during testing. OpenAI also disclosed that it recently said it was intentionally slowing development of a newer model called “Astra” in order to develop better guardrails.

Cybersecurity and AI experts, speaking to CyberScoop, told the outlet that while AI systems have greatly improved at finding and exploiting software vulnerabilities, they still require substantial human guidance and supporting infrastructure to operate as intended. OpenAI’s own blog repeated the safety caveat about reduced safeguards and the associated risks from misuse or misalignment.

What this means for defenders, partners, and adversaries

  • Defenders and security teams: OpenAI positions Daybreak Blue as a practical starting point for routine defensive work—vulnerability discovery, code review, malware analysis, incident response and patch validation—while Daybreak Red is reserved for supervised, advanced red‑teaming using GPT‑5.6‑Cyber.
  • Security vendors and enterprises that use the 16 partners: Organizations can expect to access OpenAI’s frontier capabilities through established providers such as IBM, CrowdStrike, Palo Alto Networks, Cisco and Cloudflare, enabling integration into existing security services rather than requiring a direct relationship with OpenAI.
  • Adversaries and red‑teamers: The close monitoring and supervision promised for Daybreak Red users reflects OpenAI’s recognition that GPT‑5.6‑Cyber’s high completion rate on tested adversarial tasks carries a different risk profile than Sol.

OpenAI framed the expansion as a tradeoff: models with reduced safeguards carry heightened risk, but greater access for defenders could accelerate identification and remediation of serious vulnerabilities. The company’s forthcoming system card for GPT‑5.6‑Cyber and the partner program will be concrete next steps to watch as organizations decide whether—and how—to deploy these frontier tools in operational security workflows.

Source: CyberScoop — OpenAI says Daybreak will expand to offer specialized cyber services