OpenAI Launches GPT-5.6-Cyber for Advanced Security Work

OpenAI has introduced GPT-5.6-Cyber, a new cybersecurity-focused model designed to help authorized security researchers find vulnerabilities, validate exploits, and investigate complex security issues. The model is available through OpenAI’s expanded Daybreak program, which now offers two access tiers for approved defenders.

The launch comes as OpenAI argues that AI is accelerating both cyberattacks and defensive research. Daybreak is designed to give trusted security teams access to more capable models while maintaining controls around how those models are used.

OpenAI

 

What Is GPT-5.6-Cyber?

GPT-5.6-Cyber is built on GPT-5.6 Sol and has been specifically trained for advanced cybersecurity tasks. OpenAI says its specialized training improves performance on areas such as vulnerability discovery, exploit validation, and complex security research while reducing refusals on certain higher-risk, dual-use cybersecurity requests.

The model is available through Daybreak Red, the higher-access tier intended for approved vulnerability researchers, red teams, and security testing. OpenAI says Daybreak access is restricted through measures including identity verification, monitoring, approved-use requirements, and legal attestations.

OpenAI’s internal testing found a major difference in how often the models completed advanced cybersecurity requests. GPT-5.6-Cyber completed 95% of requests in its Advanced Cybersecurity Completion Rate evaluation, compared with 57.3% for GPT-5.5-Cyber. GPT-5.6 Sol completed 1.5% with its standard safeguards and 2% through Daybreak Blue.

GPT-5.6-Cyber

The results are not uniformly better across every benchmark. OpenAI says GPT-5.6-Cyber outperformed GPT-5.6 Sol on its zero-day discovery evaluation and ExploitGym, while GPT-5.6 Sol performed better on its vulnerability discovery and report-writing evaluation and the standard 300-turn ExploitBench test.

How OpenAI’s Daybreak Tiers Work

OpenAI is also expanding Daybreak with two different access levels for cybersecurity work.

  • Daybreak Blue: Provides access to general-purpose frontier models such as GPT-5.6 Sol with safeguards tailored for authorized defensive security work. OpenAI recommends this tier for most defenders working on vulnerability discovery, secure code review, malware analysis, incident response, and security assessments.
  • Daybreak Red: Provides access to specialized cybersecurity models such as GPT-5.6-Cyber for more advanced vulnerability research, exploit validation, and security testing.

GPT-5.6-Cyber

Daybreak Blue is intended to reduce unnecessary restrictions that can interfere with legitimate defensive work, while Daybreak Red goes further for specialized research that requires more advanced cyber capabilities.

OpenAI says GPT-5.6-Cyber has already been used internally to investigate real-world software. Its researchers say the model helped uncover two previously unknown vulnerabilities in V8, the JavaScript engine used by Chrome. The vulnerabilities were reported to Google through coordinated disclosure, with one receiving the designation CVE-2026-15903.

The company also says GPT-5.6-Cyber identified vulnerabilities across other software, including mobile operating systems, databases, and operating system kernels. OpenAI is working with Daybreak partners and the open-source community to disclose and address those issues.

OpenAI Is Keeping Human Oversight in Place

Despite the higher capabilities, OpenAI says GPT-5.6-Cyber has not reached its Critical threshold under the company’s Preparedness Framework. It was assessed at the High level for cybersecurity capability, similar to GPT-5.6 Sol.

OpenAI is also adding additional controls around Daybreak. Individual users will be required to use hardware security keys beginning September 1, while the company is expanding monitoring and security measures for the program.

For Codex users, OpenAI is encouraging Daybreak customers to use auto-review mode rather than full-access mode. The company says this can review higher-risk actions before they execute and block actions that pose significant risks.

OpenAI recommends that security teams use isolated environments, monitor agent actions, clearly define authorized systems and actions, and maintain human oversight for higher-risk workflows.

GPT-5.6-Cyber is currently available only to approved Daybreak users and organizations conducting authorized cybersecurity work. OpenAI says it plans to publish a system card with additional evaluations of the model later.

(via OpenAI)

About the Author

Asma Hussain is an editor at iThinkDifferent, where she covers Apple news, streaming services, mobile gaming, and app reviews, with a particular focus on social media and consumer tech. She writes hands-on guides and app coverage drawn from day-to-day use across iPhone, iPad, and Mac. Outside of writing, she's interested in digital illustration, internet culture, and the small design decisions that shape how people use technology.

Leave a Reply