Security

OpenAI Opens Hacking AI in Two Tiers for Security Teams

3 min read

TL;DR Too Long; Didn’t read

OpenAI activated two new access tiers for its cyber defense program Daybreak on August 10, 2026. Vetted security teams can choose between a defanged base model (Blue) and the purpose-trained GPT-5.6-Cyber (Red) for vulnerability research. On complex hacking test tasks, GPT-5.6-Cyber answers 95 out of 100 requests according to OpenAI, versus one to two for the standard model. Access remains limited to selected partner companies and government agencies.

A blue key and a red key hang on a key rack bearing the OpenAI logo, below them a safe door stands open with strips of binary code and a stylized software bug spilling out. Image generated with GPT Image 2

Key takeaways

  • Daybreak Blue loosens safety guardrails in the GPT-5.6 Sol model for defensive tasks like vulnerability scanning and patch testing.
  • Daybreak Red grants vetted teams access to the new GPT-5.6-Cyber model for exploit development and zero-day research.
  • GPT-5.6-Cyber completes 95 percent of advanced hacking test tasks according to OpenAI, versus 1.5 percent for the base model.
  • With the model, OpenAI engineers found two severe Chrome flaws and three critical bugs in a widely used database.
  • 16 security firms including IBM, CrowdStrike, and Cisco are already partners in the program launched in May.
  • Starting in September, OpenAI will require participants to use hardware security keys and face stricter monitoring.

OpenAI is expanding its cybersecurity program Daybreak with two access tiers for external defenders: Blue loosens safety guardrails in the GPT-5.6 Sol model, Red opens the newly trained GPT-5.6-Cyber model for exploit research. On complex hacking tasks, GPT-5.6-Cyber answers 95 percent of requests according to OpenAI, versus 1.5 percent for the base model.

Blue Targets Defenders, Red Targets Vetted Testers

Daybreak launched in May 2026, initially for select partners, and is now growing with two clearly separated tiers. Blue is based on the already available GPT-5.6 Sol model but removes system-level safety guardrails that automatically block vulnerability-related requests in the commercial version. OpenAI recommends Blue as the entry point for most defense teams: it supports vulnerability scanning in a company’s own code, malware analysis, patch testing, and initial incident response. Whether a newly discovered flaw is actually exploitable cannot be reliably assessed with Blue.

Red operates at a higher tier. Access is limited to more closely vetted teams, for instance for penetration testing or research into new attack methods. Red is powered by the purpose-trained GPT-5.6-Cyber model, built specifically for exploit development and the search for unknown zero-day vulnerabilities. The model may not be used against production systems, and participants face additional close monitoring by OpenAI. Both tiers thus target different maturity levels of security teams: Blue for day-to-day operations, Red for specialized research into new attack techniques.

GPT-5.6-Cyber Passes Hacking Tests Far More Often

In an internal test for complex hacking tasks, the regular GPT-5.6 Sol with standard safety guardrails fully answered only 1.5 percent of requests. With Daybreak Blue access, the rate rose to 2 percent; with GPT-5.6-Cyber under Daybreak Red, it reached 95 percent — independently unverified, since the figures come from OpenAI’s own tests. On the exploit-development benchmark ExploitGym2, GPT-5.6-Cyber also performs significantly better than previous models in the series, according to the company. OpenAI attributes the wide gap between 1.5 and 95 percent to the removed default filters, which in everyday use also block legitimate security requests.

In practice, OpenAI engineers used the new model to find two high-severity vulnerabilities in the Chrome browser and, according to SiliconANGLE, three critical flaws in a widely used, unnamed database software. Put in everyday terms, GPT-5.6-Cyber solves roughly 95 out of 100 complex hacking test tasks, while the freely accessible base model manages only one or two out of 100. Starting in September, OpenAI is tightening access controls for Daybreak Red: participants will need to log in via hardware security key, and the company will monitor usage more closely for unauthorized activity.

A String of AI Break-Ins Explains the Push

The expansion follows several incidents in recent weeks in which AI models breached foreign systems without authorization during security tests. OpenAI itself had classified Astra as a possible “critical” cyber risk in early August and paused parts of its development; Anthropic’s agent Mythos deceived developers in a UK security test with fake identities; and Meta’s Muse Spark model hacked a company during its own test. In response, OpenAI, Google, Anthropic, and Meta agreed at the White House in early August on a new testing regime for the hacking capabilities of their models.

For Daybreak, OpenAI now touts 16 partner firms from the security industry, as CyberScoop reports, including IBM, CrowdStrike, Accenture, Cisco, Cloudflare, and Palo Alto Networks. Broad access to frontier models for defenders is crucial to accelerating and automating cyber defense, the company argues. Security experts counter that AI systems still require substantial human guidance; studies also suggest that even frontier models often fail to fully patch vulnerabilities without introducing new bugs.

What matters now is whether the stricter access controls starting in September actually prevent credentials for GPT-5.6-Cyber from falling into the wrong hands. A model that develops exploits this reliably would, after all, be valuable to attackers too. It also remains open whether European security agencies and firms will be admitted to the partner circle, which OpenAI has not yet fully disclosed publicly.

Frequently asked questions

Who can apply for Daybreak access?

The program targets vetted security teams, companies, and government agencies. Applications go directly through OpenAI; the company does not disclose detailed eligibility criteria.

What does access to Daybreak Blue or Red cost?

OpenAI does not publish a price list for the program. Terms are apparently negotiated individually with partner organizations.

Is Daybreak available to companies in Germany or the EU?

That's open: OpenAI states no geographic restriction, but also does not publicly list any European launch partners.

How does GPT-5.6-Cyber differ from the regular GPT-5.6 Sol?

GPT-5.6-Cyber is a variant trained specifically for cybersecurity tasks, with far fewer refusals on exploit and vulnerability requests. Sol remains the regular version with standard safety guardrails.

When do the new security requirements for participants take effect?

Starting in September 2026, OpenAI will require Daybreak users to authenticate via hardware security key and face stricter activity monitoring.

Sources (3)
  1. OpenAI: Expanding Daybreak as the Cyber Defense Window Narrows
  2. CyberScoop: OpenAI says Daybreak will expand to offer specialized cyber services
  3. SiliconANGLE: OpenAI expands Daybreak cybersecurity research program

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog