"By bringing our frontier cyber models into their services, we can help more defenders find serious vulnerabilities, validate which ones matter, and fix them faster," OpenAI wrote in a blog post.
What GPT 5.6 Cyber is designed to do
OpenAI has produced a model it calls GPT 5.6 Cyber, explicitly described as a tool for vulnerability research, penetration testing, and incident response. OpenAI says the models can assist security teams by identifying vulnerabilities, determining whether a weakness can actually be exploited, identifying affected systems, developing fixes, and helping move those fixes into production.
Who will have access: consultancies and security vendors
OpenAI is not releasing the underlying models to regular users; instead, access is limited to a list of approved partners and selected security vendors. Named professional services and consultancies that OpenAI says will have access include Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps. Supported security vendors on the rollout list include Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare.
OpenAI says approved partners will use the models inside existing security products, managed services, and customer engagements rather than delivering the raw model directly to customers. Organizations interested in using the technology are invited to access it through participating security providers, and cybersecurity providers and consultancies can apply to join the Daybreak Cyber Partner program.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildDaybreak Blue and Daybreak Red: two tracks for different work
OpenAI is offering partners two versions of ChatGPT's cyber capabilities through what it calls Daybreak Access. Daybreak Blue is described as designed for a broad range of defensive security workloads. Daybreak Red is intended for "more specialized and closely governed work." The two tracks are positioned as separate paths for different operational needs, with partners able to choose the version that aligns with specific engagements such as vulnerability discovery and validation, red teaming, penetration testing, incident response, and remediation across enterprise environments.
Safeguards, partner responsibilities, and limits on model transfer
OpenAI says it will restrict direct model transfers to customers and keep access with approved partners. "Access to the underlying models remains with the approved partner and is not transferred directly to the customer," OpenAI explained. The company also pointed to safeguards partners may deploy, which can include identity verification, clearly defined testing scopes, logging, monitoring, and human oversight.
OpenAI additionally says partners will work with organizations to define the boundaries of each engagement, review findings, and apply their expertise before action is taken. OpenAI framed the access model as a way to provide enterprises with advanced AI security capabilities without requiring them to build their own specialized cyber AI infrastructure.
What this means for security teams, procurement leaders, and adversaries
- Security teams and technologists: They can expect to see GPT 5.6 Cyber’s capabilities surface inside services from named consultancies and security vendors rather than as a standalone product. That route gives teams the option to use AI-driven vulnerability discovery and validation integrated into existing tooling and managed services.
- Enterprises and procurement leaders: According to OpenAI, the approach lets organizations access advanced cyber AI through participating providers without building bespoke AI infrastructure. Partners, not customers, will retain model access and define the scope of engagements.
- Adversaries and threat actors: OpenAI cited the history of model abuse to justify restricting direct access for regular users; the company says models have been abused to launch security attacks, and that risk underpins the tightly controlled Daybreak Access model.
OpenAI’s rollout frames GPT 5.6 Cyber as a capability aimed at improving defensive outcomes while keeping the most powerful model access inside a circle of vetted providers. The company has paired the release with procedural controls—identity checks, scoped testing, logging, monitoring, and human oversight—and an explicit promise that partners will review and act on findings rather than passing raw model outputs straight to customers.
The gap Daybreak aims to close is not only technical but operational: a channel for advanced AI-assisted security work that remains under partner control. Whether that arrangement reduces misuse while accelerating remediation will be measured in the deployments that follow.
Source: OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users — BleepingComputer




