Palo Alto Networks puts OpenAI cyber models inside customer networks
The frontier cyber-capability story moved from the lab to the enterprise today: OpenAI's most capable defensive AI is about to run inside real corporate networks, under the direction of a security vendor's consultants.
Palo Alto Networks' Unit 42 consulting arm will deploy OpenAI's frontier cyber models inside customer environments, expanding the Frontier AI Exposure Analysis service it launched earlier this year. The models hunt for vulnerabilities, misconfigurations, leaked credentials and unmanaged attack surfaces across applications and network assets, then Unit 42 runs adversary simulation against the findings to establish whether an exposure is actually exploitable — and how far an attacker could travel once inside. The numbers explain why the approach matters: 36% of the exposures Unit 42 has identified map to no known CVE, and many only become dangerous when several gaps are chained together. That is exactly the kind of multi-step reasoning frontier models are being trained to do.
The models reach Unit 42 through OpenAI's Daybreak program, which the lab expanded on Aug. 10 with two access tiers. The higher tier, Daybreak Red, runs GPT-5.6-Cyber, a purpose-trained model for authorized vulnerability research, exploit validation and penetration testing. The capability jump is stark: GPT-5.6-Cyber completes 95% of OpenAI's advanced cybersecurity requests — exploit-chain development, authentication bypass, privilege escalation — versus 1.5% for the general-purpose GPT-5.6 Sol, and it already has real-world scalps, including two chained vulnerabilities in Chrome's V8 engine (tracked as CVE-2026-15903) and hundreds of privilege-escalation flaws in a popular operating system kernel. OpenAI's own Preparedness Framework rates the model High for cyber capability, below the Critical threshold that triggered August's Astra pause — a contrast worth noting after OpenAI pauses Astra over possible 'Critical' cyber capability.
Unit 42 deliberately keeps humans in the loop: a multi-model harness assigns each task to whichever model handles it best, consultants validate results against Palo Alto telemetry and Unit 42 threat intelligence, and remediation plans are ranked by which fixes break the most attack paths before findings flow into existing IT and security workflows. The service is one of three under the firm's Frontier AI Defense umbrella, alongside a benchmarking engagement and an agentic defense transformation program; Palo Alto says more than 1,000 security teams have been briefed since launch. It is also not OpenAI's only frontier-model tie-up — Palo Alto is among the ~50 organizations in Anthropic's Project Glasswing, which gives defenders early access to Claude Mythos Preview, a model held back from general release because of how well it finds and chains software flaws. As Unit 42's Sam Rubin put it: "The window is still closing."
What to watch: whether the same models that find flaws faster than human researchers start getting asked to fix them autonomously — and how OpenAI's access controls (hardware security keys for individual Daybreak users from September 1) hold up as cyber models spread into enterprise operations.
OpenAI's most capable cyber model is about to run inside enterprise networks — is that the defense we need, or the attack we're inviting? Tell us in the comments.
Sources: OpenAI · Palo Alto Networks · SiliconANGLE