OpenAI has introduced a new large language model (LLM) specifically trained for cybersecurity tasks, GPT-5.6-Cyber, alongside a revised two-tier access program called Daybreak. The announcement, made in a company blog post on August 10, details how the new model and access tiers aim to balance advanced cybersecurity capabilities with safety measures.
The Daybreak program now consists of two tiers: Daybreak Blue and Daybreak Red. Daybreak Blue provides access to frontier general-purpose models, including the latest GPT-5.6 Sol, for authorized defensive security work. This tier removes some "system-level safeguards" that are present for general users of GPT-5.6 Sol, which OpenAI noted could otherwise impede legitimate defensive tasks. Permitted activities for Daybreak Blue members include vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.
For more advanced cybersecurity operations, Daybreak Red members gain access to purpose-trained cybersecurity models like GPT-5.5-Cyber and the newly launched GPT-5.6-Cyber. This tier is intended for tasks such as vulnerability research, exploit validation, and security testing. OpenAI stated that even without the general guardrails, GPT-5.6 Sol with Daybreak Blue access would still refuse highly dual-use prompts, such as those related to pentesting production systems. GPT-5.6-Cyber, exclusively available through Daybreak Red, is designed to further reduce these refusals and enhance performance on sensitive security tasks.
OpenAI claims that GPT-5.6-Cyber significantly outperforms its other models in cybersecurity scenarios. In a set of sensitive requests involving exploit-chain development, authentication bypass, and privilege escalation, GPT-5.6-Cyber completed 95% of the tasks. In contrast, general-access GPT-5.6 Sol completed only 1.5% of these tasks, and with Daybreak Blue access, it completed 2.0%. The previous cyber-focused model, GPT-5.5-Cyber, completed 57.3% of the same requests.
The company also reported that GPT-5.6-Cyber demonstrated superior performance across various cybersecurity-specific AI benchmarks, including ExploitGym and ExploitBench, and in tasks like zero-day vulnerability discovery evaluation and vulnerability reporting. As an example of its capabilities, OpenAI stated that its researchers used GPT-5.6-Cyber to identify CVE-2026-15903, a high-severity vulnerability in V8, Chrome’s JavaScript engine. This finding was validated and reported to Google through coordinated vulnerability disclosure, and Google subsequently fixed the issue.
The introduction of the two-tier system is seen as an initial step by OpenAI to address concerns regarding the potential misuse of powerful AI models while enabling their application in cybersecurity defense. The Daybreak Red tier specifically restricts access to models capable of more advanced and potentially harmful actions, while Daybreak Blue aims to bridge gaps where previous models with stringent guardrails proved insufficient for defensive operations. However, it is noted that AI model guardrails alone are not a complete control plane for defense, emphasizing the need for visibility, segmentation, and adherence to zero-trust principles within an organization's own infrastructure to manage AI agent actions and contain potential risks.






