OpenAI ships GPT-5.6-Cyber to vetted defenders under Daybreak
Three days after OpenAI said it could not rule out "Critical" cyber capabilities in its next model, it is doing the opposite of slamming the door: shipping a more permissive cyber model to a vetted circle of defenders — and framing it as the only way to close a narrowing defense window.
OpenAI released GPT-5.6-Cyber, a cybersecurity-tuned variant of GPT-5.6 Sol, and expanded its Daybreak program with two access tiers that put frontier cyber models in approved defenders' hands. The model is built on GPT-5.6 Sol and trained to find zero-day vulnerabilities, develop exploit chains, and refuse far fewer legitimate-but-dual-use requests than the base model. OpenAI's internal evaluation puts its completion rate on advanced cyber requests at 95 percent, versus 1.5 percent for GPT-5.6 Sol and 57.3 percent for the previous GPT-5.5-Cyber. Access flows through two new tiers: Daybreak Blue, which gives defenders GPT-5.6 Sol with reduced guardrails for broad defensive work like vulnerability discovery, malware analysis and incident response, and Daybreak Red, the more tightly governed lane for the purpose-trained model in authorized vulnerability research, exploit validation and red teaming.
The timing is the story. On August 7, OpenAI said internal evaluations of its upcoming Astra model "cannot rule out" the Critical threshold under its Preparedness Framework — the first time it has flagged one of its own models at that level — and paused work that lacked stricter controls (we covered that decision in a deep dive — OpenAI pauses Astra over possible 'Critical' cyber capability). Three days later it is pushing permissive capability out the door, with vetting as the answer to the risk: identity verification, legal attestations, monitoring, and hardware security keys required for individual Daybreak accounts from September 1. OpenAI says GPT-5.6-Cyber was itself assessed as High, below Critical, and that a full system card is coming.
The capability claims are concrete. OpenAI says GPT-5.6-Cyber uncovered two previously unknown vulnerabilities in Chrome's V8 engine that chain into a heap-sandbox escape — patched as CVE-2026-15903 after coordinated disclosure with Google — plus at least five flaws in a popular mobile OS, three critical vulnerabilities in a popular database with a remote code-execution path, and more than 400 privilege-escalation issues in a popular operating system kernel. The partner roster reads like the security industry's board of directors: Accenture, IBM, CrowdStrike, Palo Alto Networks' Unit 42, Cisco, Sophos and Cloudflare, among others.
The tension is worth sitting with. OpenAI's own framing admits that "models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment" — and its answer is fences, not fewer capabilities. That is a bet that vetted defenders plus monitoring beats withholding the model, and it is the same reasoning, in reverse, that justified pausing Astra three days ago. It is also a distribution play: putting frontier cyber models inside Accenture's managed services and CrowdStrike's Falcon platform is how OpenAI makes permissive models a product, not just a policy.
What to watch: whether the promised system card holds up under outside scrutiny, and whether the "High, not Critical" assessment survives independent evaluation — the same claim that proved hard to defend with Astra.
Should permissive cyber models go to vetted defenders — or does the Astra pause suggest OpenAI is moving too fast in both directions? Tell us in the comments.
Sources: OpenAI — Expanding Daybreak as the Cyber Defense Window Narrows · OpenAI — Putting frontier cyber models in more trusted hands · Axios · Techmeme · OpenAI — Responding to the next frontier of critical cyber capabilities · Engadget · AI Midday — OpenAI pauses Astra over possible 'Critical' cyber capability