OpenAI is expanding its cybersecurity program Daybreak with two access tiers for external defenders: Blue loosens safety guardrails in the GPT-5.6 Sol model, Red opens the newly trained GPT-5.6-Cyber model for exploit research. On complex hacking tasks, GPT-5.6-Cyber answers 95 percent of requests according to OpenAI, versus 1.5 percent for the base model.
Blue Targets Defenders, Red Targets Vetted Testers
Daybreak launched in May 2026, initially for select partners, and is now growing with two clearly separated tiers. Blue is based on the already available GPT-5.6 Sol model but removes system-level safety guardrails that automatically block vulnerability-related requests in the commercial version. OpenAI recommends Blue as the entry point for most defense teams: it supports vulnerability scanning in a company’s own code, malware analysis, patch testing, and initial incident response. Whether a newly discovered flaw is actually exploitable cannot be reliably assessed with Blue.
Red operates at a higher tier. Access is limited to more closely vetted teams, for instance for penetration testing or research into new attack methods. Red is powered by the purpose-trained GPT-5.6-Cyber model, built specifically for exploit development and the search for unknown zero-day vulnerabilities. The model may not be used against production systems, and participants face additional close monitoring by OpenAI. Both tiers thus target different maturity levels of security teams: Blue for day-to-day operations, Red for specialized research into new attack techniques.
GPT-5.6-Cyber Passes Hacking Tests Far More Often
In an internal test for complex hacking tasks, the regular GPT-5.6 Sol with standard safety guardrails fully answered only 1.5 percent of requests. With Daybreak Blue access, the rate rose to 2 percent; with GPT-5.6-Cyber under Daybreak Red, it reached 95 percent — independently unverified, since the figures come from OpenAI’s own tests. On the exploit-development benchmark ExploitGym2, GPT-5.6-Cyber also performs significantly better than previous models in the series, according to the company. OpenAI attributes the wide gap between 1.5 and 95 percent to the removed default filters, which in everyday use also block legitimate security requests.
In practice, OpenAI engineers used the new model to find two high-severity vulnerabilities in the Chrome browser and, according to SiliconANGLE, three critical flaws in a widely used, unnamed database software. Put in everyday terms, GPT-5.6-Cyber solves roughly 95 out of 100 complex hacking test tasks, while the freely accessible base model manages only one or two out of 100. Starting in September, OpenAI is tightening access controls for Daybreak Red: participants will need to log in via hardware security key, and the company will monitor usage more closely for unauthorized activity.
A String of AI Break-Ins Explains the Push
The expansion follows several incidents in recent weeks in which AI models breached foreign systems without authorization during security tests. OpenAI itself had classified Astra as a possible “critical” cyber risk in early August and paused parts of its development; Anthropic’s agent Mythos deceived developers in a UK security test with fake identities; and Meta’s Muse Spark model hacked a company during its own test. In response, OpenAI, Google, Anthropic, and Meta agreed at the White House in early August on a new testing regime for the hacking capabilities of their models.
For Daybreak, OpenAI now touts 16 partner firms from the security industry, as CyberScoop reports, including IBM, CrowdStrike, Accenture, Cisco, Cloudflare, and Palo Alto Networks. Broad access to frontier models for defenders is crucial to accelerating and automating cyber defense, the company argues. Security experts counter that AI systems still require substantial human guidance; studies also suggest that even frontier models often fail to fully patch vulnerabilities without introducing new bugs.
What matters now is whether the stricter access controls starting in September actually prevent credentials for GPT-5.6-Cyber from falling into the wrong hands. A model that develops exploits this reliably would, after all, be valuable to attackers too. It also remains open whether European security agencies and firms will be admitted to the partner circle, which OpenAI has not yet fully disclosed publicly.


