OpenAI has expanded its Daybreak cyber defense service, introducing a two-tier system that allows organizations to use its frontier AI models for authorized defensive work. The tier system includes a new specialized model, GPT-5.6-Cyber, which is being made available only through the service’s higher-access Red tier.
Access to Daybreak and its models is limited to vetted users and organizations, with the model program structured around controls intended to prevent its use in unauthorized attacks.
OpenAI’s decision to put more advanced tools into controlled security environments reflects a growing effort across the industry to give defenders stronger capabilities as the cybersecurity industry is rocked by the emerging threat of autonomous attacks.
Blue and Red Tiers Separate Defensive Workflows From Higher-Risk Testing
OpenAI positions Daybreak Blue as the entry point for most enterprise security teams. It provides access to frontier general-purpose models, including GPT-5.6 Sol, with safeguards designed for authorized defensive workflows. Those uses include vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.
The more restricted Daybreak Red tier is only available to “trusted customer partners” and is designed for specialist cybersecurity work, including penetration testing, exploit validation, and vulnerability research. It is aimed at approved organizations working within defined scopes, where AI can be used to test systems and identify weaknesses before malicious actors find them.
GPT-5.6-Cyber sits within that Red tier. Built on GPT-5.6 Sol, the model has been tuned for specialized cyber tasks and is intended to be less likely to refuse legitimate but higher-risk requests associated with defensive testing. OpenAI said the model has demonstrated stronger performance on exploit-chain development, authentication bypass, and privilege-escalation tasks than its broader models.
In its testing, OpenAI reported that GPT-5.6-Cyber completed 95% of requests involving those advanced tasks, compared with 1.5% for GPT-5.6 Sol and 2% for Daybreak Blue. The company also said the model had identified vulnerabilities across a range of software environments, including a high-severity V8 memory corruption issue and hundreds of kernel vulnerabilities.
The access model is as important as the technology itself. Partners can use the models in managed services, security products, and customer engagements, but underlying model access remains with the approved provider rather than being handed directly to customers. Identity checks, monitoring, legal attestations, defined testing boundaries, and human oversight form part of the program’s controls.
AI Labs Respond to Fears Over Autonomous Cyber Activity
The case for controlled access to frontier cyber models has become more urgent as AI agents have shown what can happen when they operate beyond tightly limited environments. Recent incidents involving major AI companies have raised concerns about models accessing third-party systems during testing, while real-world examples have demonstrated how quickly an apparently routine instruction can turn into unauthorized activity.




