OpenAI has expanded its cybersecurity effort "Daybreak" and released the full version of GPT-5.5-Cyber, a new model aimed at defenders[1]. The goal is to move beyond the vulnerability discovery that AI already excels at and toward rapidly automating the creation of fixes. The company also announced an update to its Codex Security plugin for code analysis, along with Patch the Planet, an initiative to support open-source maintainers.

Daybreak Aims to Shift From Finding to Fixing

According to OpenAI, AI is fundamentally changing the premises of cybersecurity[1]. Finding serious vulnerabilities used to require rare expertise, time, and deep familiarity with complex systems. Now, frontier models can navigate large codebases, reason through attack paths, and surface issues that might otherwise stay hidden.

As a result, the bottleneck has shifted from discovery to remediation. A vulnerability report alone protects no one. Real value emerges only when the issue is validated, its impact understood, a patch developed and tested, disclosure coordinated, and the fix deployed. Daybreak is positioned as an effort to strengthen these later stages through collaboration between AI and human experts, converting model capability into real-world risk reduction[1].

OpenAI also argues that frontier defensive capabilities should not be concentrated in the hands of a few. Because software touches everything from critical infrastructure to business applications and government networks, defenders everywhere need democratized access to these tools so they can fix flaws before attackers exploit them[1].

What GPT-5.5-Cyber Can Do

At the center of the announcement is the full version of GPT-5.5-Cyber, a model specialized for defensive work. While the initial preview focused mainly on reducing unnecessary refusals in specialized workflows, this update goes further by strengthening the model's ability to find and help patch vulnerabilities[1]. It can sustain analysis across large codebases, trace whether vulnerable code is reachable, validate likely issues in controlled environments, develop and test patches, and prepare evidence for human review.

The performance is shown across several benchmarks. On CyberGym, which measures whether an agent can reproduce known vulnerabilities, the updated GPT-5.5-Cyber reached 85.6 percent in single-model evaluations, compared with 81.8 percent for GPT-5.5. OpenAI says this is the highest CyberGym score it has measured from a single model[1].

It also outperformed GPT-5.5 on two demanding real-world benchmarks: 39.5 percent versus 25.95 percent on ExploitGym, which tests turning known vulnerabilities into working exploits, and 69.8 percent versus 63.1 percent on SEC-bench Pro, which evaluates long-horizon vulnerability discovery and proof-of-concept generation[1].

That said, OpenAI cautions that benchmarks are only part of the story. What matters in practice is whether a model can find real vulnerabilities, separate actionable issues from noise, and help land fixes safely, and the company says it continues to evaluate the model as coordinated disclosures conclude[1]. Because GPT-5.5-Cyber allows more permissive behavior, access is limited to verified defenders and paired with stronger verification, monitoring, scoped controls, and review. For most defenders, OpenAI says GPT-5.5 with Trusted Access for Cyber and Codex Security remains the right starting point[1].

Codex Security and the Open-Source-Focused Patch the Planet

For developers, OpenAI announced an update to its Codex Security plugin for code analysis. Designed to place the equivalent of a security engineer next to every developer, it understands a team's code and threat model, identifies plausible vulnerabilities, determines whether affected code is reachable, gathers validation evidence, develops a targeted patch, and verifies the result[1]. Humans remain in control of which findings to investigate, which changes to apply, and what to share.

The scale is described in concrete numbers. Since launching as a research preview in March, Codex Security cloud has scanned more than 30 million commits across more than 30,000 codebases. Human reviewers have manually marked more than 70,000 findings as fixed, and more than 500,000 findings have been automatically determined to be fixed[1]. OpenAI says this is the scale at which patching must now happen.

Patch the Planet, an initiative to support open-source maintainers, has also launched. Founded with security firm Trail of Bits and in collaboration with HackerOne and Calif, it funds expert researchers and equips them with Codex Security and advanced models to work directly with maintainers[1]. More than 30 projects, including cURL, Go, Python, Sigstore, and pyca/cryptography, have committed to participate.

Behind this is the reality that widely used software is often sustained by very small teams. Research from the Linux Foundation and Harvard found that 94 percent of the widely used projects studied had fewer than 10 developers responsible for more than 90 percent of the code added in a year[1]. Because AI accelerating discovery also increases the burden on maintainers, Patch the Planet is built around expert human review, validating and deduplicating vulnerabilities and patches before they reach maintainers. Participating projects receive ChatGPT Pro, conditional access to Codex Security, and API credits for development and automation[1].

Partnerships With Governments, Including Japan

OpenAI is also working with governments and institutions worldwide to strengthen defensive capabilities. In the past month it has established Trusted Access for Cyber partnerships with Australia, Canada, France, Germany, Japan, the Republic of Korea, and EU institutions such as ENISA, the EU Agency for Cybersecurity[1]. It also notes a growing partnership with the UK government on cyber and evaluation; Japan's inclusion in the framework is notable for domestic defenders.

With the U.S. government, OpenAI says it is conducting pre-deployment testing of GPT-5.5 and 5.5-Cyber with the Center for AI Standards and Innovation (CAISI), and collaborating with the Office of the National Cyber Director (ONCD) and the Office of Science and Technology Policy (OSTP) on implementation of a recent Executive Order and associated industry standards[1]. It plans to work directly with critical-infrastructure operators to develop safeguards tailored to their systems.

Summary

OpenAI's Daybreak expansion is an attempt to shift the center of gravity of AI-driven cyber defense from "finding more vulnerabilities" to "landing fixes safely." The full version of GPT-5.5-Cyber set a record 85.6 percent on CyberGym, and together with Codex Security, Patch the Planet, and government partnerships, it builds an end-to-end system that supports the path from discovery to remediation. As AI capabilities grow on both the offensive and defensive sides, how well defenders can wield that power looks set to become the key issue going forward.

Source: https://openai.com/index/daybreak-securing-the-world/