Hackers are getting better at finding weak spots in computer systems, and OpenAI says the people defending those systems need stronger tools to keep up.
OpenAI announced this week that it has created a new model that “might” be better at doing cybersecurity tasks, and it is granting access only to approved defenders.

Download the Straight Arrow app today to get the stories that matter free from manipulation, bias or agenda.™
Point phone camera here
In OpenAI’s own testing, GPT-5.6-Cyber completed 95% of advanced security requests, compared with 1.5% for GPT-5.6 Sol with its normal safeguards. The release comes as AI models get better at finding and exploiting vulnerabilities. Recent AI testing incidents have exposed the difficulty of containing increasingly capable systems.
Cybersecurity companies, including CrowdStrike, Palo Alto Networks, Cisco and IBM, are among 16 partners given access to the technology for their security products, managed services and customer work. The underlying models remain restricted.
The requests other models refuse
GPT-5.6-Cyber is based on GPT-5.6 Sol but was trained specifically for advanced cybersecurity work and refuses fewer requests involving tasks for defense or abuse.
OpenAI’s internal Advanced Cybersecurity Completion Rate measured how often models responded to requests involving activities such as exploit development and bypassing security controls. GPT-5.5-Cyber completed 57.3% of requests, while GPT-5.6 Sol through Daybreak Blue completed 2%.
OpenAI
The line between defense and abuse
The difference comes down to how far a model is allowed to go.
Routine defensive work can include reviewing code for flaws, analyzing malware, helping with incident response and checking whether vulnerability patches work
Advanced requests go further. OpenAI’s tests measured whether models would answer higher-risk requests, including prompts about finding ways to exploit systems, getting around login protections and gaining deeper system access.
That kind of work can help approved defenders prove a weakness is real and fix it. However, many of those requests are described as dual-use, meaning the same kind of information could also be misused.
Who gets access
OpenAI has divided Daybreak into two levels.
Daybreak Blue uses frontier general-purpose models, including GPT-5.6 Sol, for authorized work such as malware analysis, incident response, vulnerability discovery, code review and patch testing.
Daybreak Red is reserved for more advanced research and provides access to specialized models including GPT-5.6-Cyber.
OpenAI said individuals and organizations must be approved via identity verification, account protections, monitoring, restrictions on permitted work and legal attestations. Individual Daybreak users will also be required to use hardware security keys beginning Sept. 1.
Those partnerships provide another route to the technology. Participating cybersecurity companies can incorporate the models into their products and services while keeping control of the underlying model access.
Putting the model to work
OpenAI said it has also used GPT-5.6-Cyber to examine real software projects for vulnerabilities.
Testing involving V8, the JavaScript engine used by Chrome, produced two previously unknown vulnerabilities that researchers determined could be combined to corrupt memory and escape V8’s testing environment. OpenAI reported the findings to Google, which fixed one vulnerability.
The company also said the model identified at least five vulnerabilities in a popular mobile operating system, three critical vulnerabilities in a popular database and more than 400 potential flaws that could give attackers higher-level access to a system.
OpenAI said it is working with partners and open-source communities to disclose and fix those findings.
When cyber agents break the boundaries
OpenAI says it is expanding access because it expects threat actors to increasingly use AI for cyberattacks at greater speed and scale, even tasking it with autonomously hacking systems at scale.
But the company also acknowledges that reducing normal safeguards increases the risk of misuse or models acting outside their intended boundaries.
That risk is no longer hypothetical.
Straight Arrow previously reported that AI agents using OpenAI cyber models escaped a training environment and hacked Hugging Face, another AI format. OpenAI said GPT-5.6-Cyber was not involved in that incident.
Anthropic later said Claude models gained unauthorized access to internal systems at three organizations. CNBC also reported an incident involving Meta models and another involving an open-weight model from China’s Moonshot AI that escaped a testing sandbox.
At the Black Hat cybersecurity conference, industry executives described autonomous AI as an increasingly important security problem as companies develop new ways to monitor networks, sensitive data and AI agents.
“In the near future, we should expect that threat actors will intentionally deploy, optimize, weaponize, and use offensive agent collectives in the manner that we have just described here,” Michael Dalton, OpenAI technical researcher, said during the conference.
Keeping the model inside the lines
OpenAI rated GPT-5.6-Cyber at its “High” capability threshold, but below its “Critical” threshold, meaning the company considers it advanced but not at its highest level of cyber capability.
The company said it is developing additional monitoring and prioritizing testing meant to keep future Daybreak releases acting within their limits. It also recommends isolating cyber agents from sensitive production systems and the open internet, closely monitoring their actions and limiting them to explicitly authorized systems.
OpenAI plans to publish a more detailed system card for GPT-5.6-Cyber at a later date.






