OpenAI is expanding its Daybreak program with two new access tiers and a dedicated cybersecurity model, GPT-5.6-Cyber, as the company warns that defenders face a narrowing window to prepare for AI-powered attacks. The announcement, made on August 10, 2026, introduces Daybreak Blue and Daybreak Red, designed to give approved defenders controlled access to frontier models with reduced guardrails for authorized security work OpenAI announcement.
Daybreak Blue provides access to frontier general-purpose models, including GPT-5.6 Sol, with safeguards tailored to authorized defensive security work. It supports vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. Daybreak Red grants access to purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing, including the new GPT-5.6-Cyber.
GPT-5.6-Cyber is built on GPT-5.6 Sol and trained to improve performance on specialized cybersecurity tasks while reducing refusals for higher-risk dual-use cyber tasks. According to OpenAI’s internal Advanced Cybersecurity Completion Rate evaluation, GPT-5.6-Cyber completes 95.0% of advanced cyber requests, compared with 1.5% for GPT-5.6 Sol and 2.0% for GPT-5.6 Sol with Daybreak Blue access OpenAI announcement. The company says the model also outperforms GPT-5.5-Cyber, which completes only 57.3% of requests.
OpenAI reports that GPT-5.6-Cyber shows measurable gains on public benchmarks. On ExploitGym, which evaluates whether agents can turn known vulnerabilities into working exploits in controlled environments, GPT-5.6-Cyber outperforms both GPT-5.6 Sol and GPT-5.5-Cyber OpenAI announcement. On ExploitBench, a harder exploitation task with the V8 sandbox still enabled, OpenAI says GPT-5.6 Sol with Daybreak Blue access performs best in the standard 300-turn setting, though the gap narrows at 600 turns.
OpenAI also reported real-world findings from its own use of GPT-5.6-Cyber: the model uncovered two previously unknown vulnerabilities in V8, Chrome’s JavaScript engine, which were reported to Google through coordinated disclosure and assigned CVE-2026-15903 OpenAI announcement. The company says the model has also identified at least five vulnerabilities in a popular mobile operating system, three critical vulnerabilities in a popular database, and over 400 privilege-escalation vulnerabilities in a popular operating system kernel.
Access controls remain strict. OpenAI requires individual Daybreak accounts to adopt hardware security keys beginning September 1, 2026, and is encouraging Codex users to switch from full-access mode to auto-review mode OpenAI announcement. Auto-review evaluates actions requiring elevated permissions before execution and can block requests that pose a significant risk of destructive behavior Auto-review documentation.
For teams already using AI-assisted security tooling, the expansion means verified access to a model trained explicitly for exploit-chain development and zero-day analysis, rather than a general model with prompt-level workarounds. The practical takeaway is that authorized defenders can now request reduced refusals on dual-use cyber tasks without leaving the governed Trusted Access environment, while OpenAI maintains Preparedness Framework oversight: GPT-5.6-Cyber reaches the High cybersecurity capability threshold but remains below Critical OpenAI announcement.
For ongoing coverage of AI security policy and defensive tools, see our OpenAI Expands Daybreak AI Patching Tools for Global Defense and Fable 5 Export Controls Undermine US Cyber Defense.
