On August 10, OpenAI expanded its cybersecurity initiative Daybreak and released GPT-5.6-Cyber, a new model built specifically for security work[1]. Access is now divided into two tiers, Daybreak Blue and Daybreak Red, so that only vetted organizations and individuals can reach the most advanced cyber capabilities. The thinking behind it is to hand frontier capability to defenders before attackers start deploying offensive AI at scale.
Getting ahead of attackers who run on AI
The premise behind the announcement is that threat actors will increasingly use AI to run cyberattacks at unprecedented speed and scale, including in fully autonomous ways[1]. As those capabilities spread, the window defenders have to prepare keeps narrowing. OpenAI's answer is to put frontier intelligence in the hands of trusted defenders first[1].
Daybreak itself has been running for a while, but this release reorganizes the way people get in.
Daybreak Blue and Daybreak Red
The expanded Daybreak now offers two access tiers matched to the kind of authorized defensive work being done[1].
Daybreak Blue provides access to frontier general-purpose models, including GPT-5.6 Sol, with safeguards tailored to authorized defensive security work. It covers vulnerability discovery, secure code review, malware analysis, incident response, and patch validation, and OpenAI describes it as the recommended starting point for most defenders[1].
Daybreak Red goes a step further, opening access to purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing[1]. GPT-5.6-Cyber is available only through Red.
What the refusal numbers actually measure
GPT-5.6-Cyber is built on GPT-5.6 Sol and trained to improve performance on specialized tasks such as finding zero-day vulnerabilities and developing exploit chains, while reducing refusals on higher-risk dual-use requests[1].
The gap shows up clearly in the numbers. OpenAI created an internal evaluation, the Advanced Cybersecurity Completion Rate, that measures how often a model responds to advanced requests involving exploit-chain development, authentication bypass, and privilege escalation[1]. GPT-5.6-Cyber completes 95.0 percent of these requests, against 1.5 percent for standard GPT-5.6 Sol and 2.0 percent when accessed through Daybreak Blue[1]. The previous GPT-5.5-Cyber sat at 57.3 percent, and the improvement responds to feedback from security researchers who kept running into refusals on legitimate work[1].
It is worth noting that this figure measures whether the model responds, not how capable it is. Capability is evaluated separately. On ExploitGym, which tests whether an agent can turn a known vulnerability into a working exploit, GPT-5.6-Cyber outperformed both GPT-5.6 Sol and GPT-5.5-Cyber[1]. On an internal vulnerability discovery and report writing evaluation, however, GPT-5.6 Sol scored higher, which OpenAI attributes to the specialized model sometimes producing shorter, less detailed reports[1]. On the harder ExploitBench, where protections such as the V8 sandbox stay enabled, GPT-5.6 Sol solved tasks more token-efficiently in the standard 300-turn setting[1]. The specialized model is not uniformly stronger, and the results say so plainly.
Two unknown V8 flaws found, and Chrome has patched them
More concrete than the benchmarks is what the model found in real software. After training finished, OpenAI used GPT-5.6-Cyber to investigate V8, the JavaScript engine used by Chrome[1]. It uncovered two previously unknown vulnerabilities that could be chained together to corrupt memory and escape the V8 heap sandbox[1].
OpenAI researchers validated the findings and reported them to Google through coordinated vulnerability disclosure, and Google fixed the issue. It was assigned CVE-2026-15903[1]. The NVD entry classifies it as an out-of-bounds read and write in V8, with the fix landing in Chrome 150.0.7871.128[2]. The root cause was an optimizing compiler that incorrectly skipped a safety check when converting values to integers[1].
Beyond V8, OpenAI says the model identified at least five vulnerabilities in a popular mobile operating system, three critical vulnerabilities in a popular database, and more than 400 privilege-escalation issues in a widely used OS kernel[1]. Those are being disclosed and remediated in coordination with Daybreak partners and the open-source community[1].
Conditions placed on users
Handing out a model with reduced safeguards comes with tighter operational requirements. Access is controlled through identity verification, account security, monitoring, approved-use restrictions, and legal attestations, and is limited to individuals and organizations conducting authorized work[1].
Specific measures include strongly encouraging Daybreak customers using Codex to switch from full-access mode to auto-review mode, and requiring hardware security keys for all individual Daybreak accounts starting September 1, 2026[1]. Improved monitoring is due to roll out over the coming weeks[1].
Recommended practice comes down to three points: run security workflows in sandboxed environments cut off from production systems and the open internet, review agent actions through auto-review mode, and define authorized scope using scoped permission profiles[1].
Under the Preparedness Framework, GPT-5.6-Cyber was assessed as reaching the High threshold for cyber capability but not the Critical threshold[1]. A system card with fuller evaluations is planned for a later date[1]. Applications are handled through the Daybreak partners page[3].
Summary
OpenAI has reorganized Daybreak into Blue and Red tiers and released GPT-5.6-Cyber as the specialized model behind Red. Its completion rate on advanced cyber requests is 95.0 percent, far above the 1.5 percent of standard GPT-5.6 Sol. In practice it found two unknown vulnerabilities in Chrome's V8, now patched as CVE-2026-15903. At the same time, the general-purpose model still scored higher on report writing and part of the exploit evaluations, so the specialized model is not a universal upgrade. Tighter operating conditions, including mandatory hardware keys, landed alongside it.
Source[1]: https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows
Source[2]: https://nvd.nist.gov/vuln/detail/CVE-2026-15903
Source[3]: https://openai.com/daybreak/partners/
