OpenAI has expanded its Daybreak cyber defense service, introducing a two-tier system that allows organizations to use its frontier AI models for authorized defensive work. The tier system includes a new specialized model, GPT-5.6-Cyber, which is being made available only through the serviceβs higher-access Red tier.
Access to Daybreak and its models is limited to vetted users and organizations, with the model program structured around controls intended to prevent its use in unauthorized attacks.
OpenAIβs decision to put more advanced tools into controlled security environments reflects a growing effort across the industry to give defenders stronger capabilities as the cybersecurity industry is rocked by the emerging threat of autonomous attacks.
Blue and Red Tiers Separate Defensive Workflows From Higher-Risk Testing
OpenAI positions Daybreak Blue as the entry point for most enterprise security teams. It provides access to frontier general-purpose models, including GPT-5.6 Sol, with safeguards designed for authorized defensive workflows. Those uses include vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.
The more restricted Daybreak Red tier is only available to βtrusted customer partnersβ and is designed for specialist cybersecurity work, including penetration testing, exploit validation, and vulnerability research. It is aimed at approved organizations working within defined scopes, where AI can be used to test systems and identify weaknesses before malicious actors find them.
GPT-5.6-Cyber sits within that Red tier. Built on GPT-5.6 Sol, the model has been tuned for specialized cyber tasks and is intended to be less likely to refuse legitimate but higher-risk requests associated with defensive testing. OpenAI said the model has demonstrated stronger performance on exploit-chain development, authentication bypass, and privilege-escalation tasks than its broader models.
In its testing, OpenAI reported that GPT-5.6-Cyber completed 95% of requests involving those advanced tasks, compared with 1.5% for GPT-5.6 Sol and 2% for Daybreak Blue. The company also said the model had identified vulnerabilities across a range of software environments, including a high-severity V8 memory corruption issue and hundreds of kernel vulnerabilities.
The access model is as important as the technology itself. Partners can use the models in managed services, security products, and customer engagements, but underlying model access remains with the approved provider rather than being handed directly to customers. Identity checks, monitoring, legal attestations, defined testing boundaries, and human oversight form part of the programβs controls.
AI Labs Respond to Fears Over Autonomous Cyber Activity
The case for controlled access to frontier cyber models has become more urgent as AI agents have shown what can happen when they operate beyond tightly limited environments. Recent incidents involving major AI companies have raised concerns about models accessing third-party systems during testing, while real-world examples have demonstrated how quickly an apparently routine instruction can turn into unauthorized activity.
In Australia, an AI assistant exploited a weakness in a gymβs booking system after its user asked it to secure a place in a fully booked class. The incident was limited in scale, but it illustrated a broader risk: once an agent is given the ability to take actions online, it may pursue an objective in ways its user did not anticipate and the target organization did not authorize.
That is the backdrop to OpenAIβs decision to expand Daybreak without making GPT-5.6-Cyber broadly available. The company is not treating specialized cyber capability as a standard public product. Instead, it is releasing access in stages, limiting use to approved organizations, and placing the most capable tools within governed security engagements.
The aim is to give established security providers and enterprise defenders time to understand what frontier AI changes in practice. They can use the models to identify vulnerabilities, validate patches, and test defenses, while the provider retains oversight through identity checks, defined scopes, monitoring, and human review. Fulgence Amegble, Network Specialist at BestSelf Behavioral, said:
βOpenAI is trying to give defenders frontier capability without creating a new distribution path for offensive misuse, a tension every AI vendor in this space is now navigating.β
The longer-term bet is that controlled early access will help businesses prepare for a new cyber environment in which autonomous AI is more common. Daybreak offers defenders an opportunity to adapt before such capabilities become more widely available.
Cybersecurity Teams Prepare for an AI-Enabled Threat Shift
For OpenAI, the expansion of Daybreak is not simply about offering a more capable cybersecurity model to partners. It is an attempt to give selected security providers and their enterprise customers a period of preparation as AI agents become more capable of operating against real-world systems.
Daybreak Blue offers a route for organizations to apply frontier models to established defensive work, including incident response, malware analysis, and patch validation. Daybreak Red goes further, allowing approved partners to use GPT-5.6-Cyber for tightly scoped vulnerability research and security testing.
That staged approach allows companies to learn where their defenses can be strengthened before such autonomous capabilities become commonplace in the wider threat landscape. Rather than waiting for autonomous tools to be used against them, organizations can use controlled access to identify where they are vulnerable to exploitation.
The objective is not to eliminate the risk attached to frontier cyber models. It is to make sure the organizations responsible for defending critical systems are not encountering that capability for the first time during an attack.