OpenAI has made the models offered through Daybreak, its cyber defense initiative, available via Amazon Bedrock[1]. AWS announced the rollout on August 13[2]. Approved organizations can now call frontier models tuned for defensive work from inside the AWS environments they already use. What changed here is not the models themselves but how they are delivered.

Callable From Existing AWS Environments

Earlier this year, OpenAI frontier models and Codex became generally available on AWS[1]. This announcement is the next step: Daybreak capabilities now run on Amazon Bedrock. Defenders enrolled in Daybreak Access can use frontier cyber models within the AWS environments they already build, secure, and operate[1].

The stated use cases are vulnerability research, detection engineering, and incident response. The goal is to speed up the path from initial discovery through a validated fix[1]. Labor-intensive workflows such as exploit reproduction and mitigation development are also in scope[1].

Blue and Red Handle Different Jobs

Daybreak access is split into two levels, and both are available on Bedrock[1].

Daybreak Blue provides access to frontier general-purpose models, including GPT-5.6 Sol, with safeguards tailored to authorized defensive security work[1]. It centers on defensive tasks such as vulnerability discovery, detection engineering, and incident response, and AWS describes it as the starting point for most security teams[2].

Daybreak Red goes a step further, opening access to purpose-trained cybersecurity models, specifically GPT-5.6 Cyber[2]. It covers authorized vulnerability research, exploit validation, and security testing[1]. AWS explains that at this level a lower refusal threshold is matched by stronger identity verification, monitoring, and access controls, which improves the speed and depth of an investigation[2]. What is loosened on the model side is tightened on the operational side.

Model Performance Alone Does Not Get You Deployed

The point OpenAI emphasizes in this announcement is that adopting specialized cybersecurity capabilities requires more than model performance[1]. Security review, governance, procurement, access controls, and an operating model the team can actually support all have to line up before the capability reaches production[1].

Going through Bedrock lets much of that ride on existing AWS security, governance, and operational workflows[1]. Not adding a new procurement path or a new audit surface presumably makes approvals easier to clear.

Data handling is spelled out as well. Both models run on Bedrock's next-generation inference engine with zero-operator access (ZOA) enforced at the chip[2]. Inference data is not used for model training, and neither model requires opting into sharing data with OpenAI[2]. When you are handing over vulnerability data and source code, ambiguity here stops the conversation.

Regions and Enrollment Requirements

Availability is currently limited to US East (N. Virginia)[2]. Use requires enrollment in Daybreak access from OpenAI, after which customers work with their AWS account team[2].

Once approved, Daybreak Red and Daybreak Blue can be used from the Amazon Bedrock console, or called through the Responses API using the bedrock-mantle endpoint[1].

Summary

OpenAI has made Daybreak Blue and Daybreak Red available on Amazon Bedrock. Blue is GPT-5.6 Sol with safeguards calibrated for defensive work, Red is the purpose-trained GPT-5.6 Cyber, and Red carries heavier identity verification and monitoring requirements in exchange. Both enforce ZOA at the chip, and inference data is not used for training. Availability is limited to US East (N. Virginia), and enrollment in OpenAI's Daybreak access is a prerequisite. This is less an announcement about capability than about fitting that capability into existing procurement and operations.

Source [1]: https://openai.com/index/daybreak-models-are-now-available-on-aws

Source [2]: https://aws.amazon.com/about-aws/whats-new/2026/08/openai-daybreak-red-and-blue-on-amazon-bedrock/