In Focus
- OpenAI added Daybreak Blue and Daybreak Red tiers to its Cybersecurity Initiative
- Daybreak Red includes the newly-launched GPT-5.6-Cyber AI model
- Daybreak Blue gives trusted defenders access to general-purpose frontier models
OpenAI has expanded its Daybreak cybersecurity initiative and launched GPT-5.6-Cyber. Through the Daybreak initiative, OpenAI offers trusted defenders limited access to its cybersecurity-focused AI models, tools, and workflows. The AI firm said GPT-5.6-Cyber has previously identified vulnerabilities in Chrome’s V8 engine, mobile operating systems, databases, and kernels.
Why has OpenAI Expanded Daybreak?
Attackers are increasingly using AI to speed up cyberattacks, leaving defenders with little or no time to prepare and act. OpenAI believes that putting frontier intelligence in the hands of trusted defenders can help them prepare before attackers deploy offensive AI capabilities at scale.
Expanding Daybreak is one of the strategies that OpenAI is using to make cybersecurity tools accessible to defenders. OpenAI added two tiers to its Daybreak initiative on August 10. The two tiers are Daybreak Red and Daybreak Blue.
The AI firm recommended Daybreak Blue as the starting point for most defenders. This tier gives cybersecurity experts access to general-purpose frontier models, including the recently launched GPT-5.6 Sol. The tier also supports incident response, vulnerability discovery, malware analysis, code review, and patch validation.
Daybreak Red, on the other hand, offers trusted defenders access to purpose-trained cybersecurity models. These models support authorized vulnerability, security testing, and exploit validation. In both tiers, approved customers can use OpenAI’s frontier cyber models whose access is still limited.
GPT-5.6-Cyber is Available in Daybreak Red
Daybreak Red includes the newly launched GPT-5.6-Cyber. Built on GPT-5.6 Sol, OpenAI said GPT-5.6-Cyber has been trained to “improve capabilities on several specialized cybersecurity tasks”, including locating zero-day vulnerabilities and developing exploit chains.
The cybersecurity-focused AI model is capable of reducing refusals for specific “higher-risk, dual-use cyber tasks”. OpenAI said GPT-5.6-Cyber performed better in its Advanced Cybersecurity Completion Rate evaluation compared to GPT-5.6 Sol. The evaluation checks how often AI models respond to requests involving authentication bypass, exploit chain development, privilege escalation, and other advanced cybersecurity scenarios.
In this test, GPT-5.6-Cyber completed 95% of requests, compared to 1.5% for GPT-5.6 Sol and 2% for GPT-5.6 Sol with Daybreak Blue access. Overall, GPT-5.5-Cyber recorded a 57.3% completion rate. Currently, GPT-5.6-Cyber is only accessible to trusted partners, which reportedly include Cloudflare, Crowdstrike, and IBM.
OpenAI’s new cybersecurity model comes at a time when reports of frontier models escaping testing environments have been increasing. Last month, an OpenAI AI agent hacked Hugging Face’s infrastructure in a bid to complete a cybersecurity capability task.
What Expanded Daybreak Means for OpenAI
As AI-driven attacks become more sophisticated, OpenAI’s Daybreak initiative could help defenders to identify and address threats faster. The move will likely make specialized cyber models more accessible to security teams in enterprises and governments. However, OpenAI could face growing pressure to ensure these capabilities remain in trusted hands without limiting their usefulness to security teams.


.webp&w=750&q=75)
.webp&w=750&q=75)
.webp&w=750&q=75)
.webp&w=750&q=75)