OpenAI said on Aug. 11 that it has expanded its cybersecurity defense program, Daybreak, and launched GPT-5.6-Cyber, a model built for cybersecurity work. The company said the model is meant to help authorized security researchers and defense teams improve vulnerability discovery, threat analysis, and security testing.
OpenAI said attackers are increasingly using AI to launch cyberattacks that are faster and larger in scale, and that defenders need earlier access to advanced AI capabilities.
Daybreak adds Blue and Red access tracks
The expanded Daybreak program offers two types of access.
- Daybreak Blue is aimed at most defense teams and provides general-purpose models including GPT-5.6 Sol. OpenAI said these models can be used for vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.
- Daybreak Red is aimed at advanced security research and provides GPT-5.6-Cyber for authorized vulnerability research, vulnerability validation, and security testing.
GPT-5.6-Cyber is tuned for cybersecurity tasks
OpenAI said GPT-5.6-Cyber is trained on GPT-5.6 Sol and optimized for cybersecurity tasks, including finding zero-day vulnerabilities and analyzing exploit chains.
The company said the model has already been used in real vulnerability research and has identified high-severity software flaws, including issues in the Chrome V8 JavaScript engine.
OpenAI also said GPT-5.6-Cyber helped uncover high-severity vulnerabilities across several areas, including privilege escalation flaws in mobile operating systems, remote code execution flaws in databases, and hundreds of privilege escalation vulnerabilities in operating system kernels.
OpenAI says Daybreak Red access will be controlled
OpenAI said Daybreak Red will be available only to approved individuals and organizations. Access controls will include identity verification, account security measures, monitoring, usage restrictions, and legal declarations.
The company said it will continue to strengthen security monitoring, permission management, and model safety testing to reduce the risk that advanced cybersecurity models are misused.

