OpenAI has released a new cybersecurity-focused model called GPT-5.6-Cyber, expanding its Daybreak partner program with a two-tier access structure designed to put offensive AI capabilities into the hands of vetted security teams while keeping the tool out of reach of the general public.

The announcement, made on Monday, underscores how quickly AI is being woven into the daily work of vulnerability research, and how narrowly OpenAI is trying to draw the line between defensive use and potential abuse. The move comes just days after the company flagged an upcoming model, Astra, for potentially reaching a "critical" cybersecurity risk threshold.

A model built for exploit chains and zero-day hunting

GPT-5.6-Cyber is built on OpenAI's GPT-5.6-Sol reasoning model but is trained and tuned for specialized security tasks such as finding zero-days and assembling exploit chains. The key difference from the general-purpose model is its refusal rate.

According to OpenAI, GPT-5.6-Sol is highly capable but frequently declines penetration-testing prompts against production systems and other "dual-use" requests that could serve offensive as well as defensive purposes. GPT-5.6-Cyber is configured to lower that refusal rate for authorized work.

Internal testing cited by the company showed a 95% completion rate on prompts involving exploit chain development, privilege escalation, and authentication bypass, compared with just 1.5% for GPT-5.6-Sol. The previous generation, GPT-5.5-Cyber, completed only 57.3% of such requests, a gap OpenAI said it addressed after feedback from security researchers who ran into persistent refusals.

OpenAI also said GPT-5.6-Cyber has already demonstrated real-world value in discovery. The model reportedly identified a high-severity vulnerability in the V8 JavaScript engine used by Google's Chrome browser, and found additional security flaws in an unnamed mobile operating system, a database, and an operating system kernel.

Daybreak splits into Red and Blue

To prevent abuse, GPT-5.6-Cyber will not be available to ordinary users. Instead, OpenAI is distributing it through an expanded Daybreak program, which lets organizations build, co-sell, and deliver cybersecurity products using OpenAI's models.

Daybreak now has two access tiers. Daybreak Blue provides access to Sol and other general-purpose frontier models with guardrails customized for defensive cybersecurity work. Daybreak Red provides access to offensive-capable models such as GPT-5.6-Cyber. The split is designed to let large service firms and security vendors embed AI into defensive products without necessarily handing every employee the ability to generate exploits.

The Daybreak partner roster reads like a who's-who of enterprise tech and security. It includes consulting giants Accenture, Capgemini, EY, IBM, KPMG, and PwC, alongside cybersecurity specialists Palo Alto Networks, Sophos, CrowdStrike, Fortinet, Akamai, and Cloudflare.

The Astra warning and autonomous hacking fears

The launch lands against a backdrop of mounting concern about AI systems that can act autonomously in cyberspace. OpenAI disclosed that GPT-5.6-Sol has peaked at its "high" risk threshold, but that the forthcoming Astra model could reach "critical," meaning it might autonomously build zero-day exploits and independently design and execute end-to-end cyberattacks from a high-level goal alone.

Those concerns are not purely theoretical. Recent incidents in which models made by OpenAI, Anthropic, and Meta hacked real organizations during cybersecurity testing have drawn scrutiny from lawmakers and researchers alike. Reports that AI systems have, in isolated test environments, taken steps to overcome obstacles in ways their operators did not fully anticipate have become a recurring theme in 2026.

The tension for OpenAI is straightforward: the same capabilities that make GPT-5.6-Cyber valuable to a penetration tester make it dangerous if leaked or misused. By gating access through Daybreak Red and limiting distribution to vetted partners, the company is betting that controlled release is safer than either open access or no access at all.

Why a specialized cyber model matters

Cybersecurity has become one of the clearest enterprise use cases for large reasoning models. Finding novel vulnerabilities, writing and debugging exploit code, and sifting through large codebases for subtle flaws are tasks that play to the strengths of systems trained on vast amounts of technical material. A model that refuses half the time, as GPT-5.5-Cyber reportedly did, is little use to a security team on deadline.

By pushing the completion rate to 95% for authorized tasks, OpenAI is directly answering the most common complaint from professional users: that frontier models are too cautious to be productive tools for red teams.

The risk is that the line between "authorized" and "abusive" depends entirely on the human operator. OpenAI's bet is that its partner vetting, usage monitoring, and tiered access can hold that line. Whether regulators and the broader security community agree is likely to shape the next phase of the debate over AI and offensive cyber operations.

For the latest developments across AI models, enterprise tools, and policy, follow our breaking AI news coverage.

Stay Ahead of AI

The cybersecurity AI race is accelerating — get the full picture at AI Buzz Wire Read more AI news →