OpenAI released GPT-5.6-Cyber on Monday. It is a model built on GPT-5.6 Sol and trained for zero-day discovery and exploit-chain development, and the company says it was also trained to refuse fewer higher-risk dual-use cyber requests.
Access runs only through Daybreak, the vetted cybersecurity programme OpenAI is now expanding. Axios’ Sam Sabin reported it first.
Three days earlier, OpenAI had delayed Astra because it could not rule out critical cyber capability. The sequence looks like a reversal. It is not, and the reason it is not tells you where the industry has actually drawn its line.
Two doors, one programme
Daybreak now splits in two. Daybreak Blue carries general-purpose frontier models, including GPT-5.6 Sol, with system-level cyber guardrails removed. OpenAI recommends it as the starting point for defensive work: vulnerability discovery, secure code review, malware analysis, incident response and patch validation.
Daybreak Red carries the purpose-trained cyber models. GPT-5.6-Cyber sits there, for authorised vulnerability research, exploit validation and security testing.
Sol itself arrived in June, handed to 20 government-approved partners and nobody else. The pattern has held all year. Capability goes out through a gate, not a download page.
The number that matters is a refusal rate
OpenAI publishes an internal measure it calls the Advanced Cybersecurity Completion Rate. It tracks how often a model completes requests in categories such as exploit-chain development, authentication bypass and privilege escalation.
GPT-5.6-Cyber scores 95.0%. GPT-5.5-Cyber, its predecessor, managed 57.3%. Sol through Daybreak Blue reaches 2.0%. Sol with its standard safeguards in place reaches 1.5%.
So the headline change is not raw intelligence. It is compliance. The same underlying model, pointed at the same category of task, now answers rather than declines.
What it turned up
OpenAI ran GPT-5.6-Cyber against V8, the JavaScript engine inside Chrome. It surfaced two previously unknown vulnerabilities that could be chained to corrupt memory and escape the engine’s sandbox.
Google received them through coordinated disclosure, shipped a fix, and the pair now carries a high-severity identifier, CVE-2026-15903. That is a verified public good with a paper trail, which is rarer in this field than the marketing suggests.
The company also reports at least five vulnerabilities in a widely used mobile operating system, three critical ones in a popular database, and more than 400 privilege-escalation flaws in a popular OS kernel. None of the affected products are named. Disclosure is still running with partners and open-source maintainers.
The benchmarks are not a clean sweep
Two of OpenAI’s own results cut against the new model. On vulnerability discovery and report writing, GPT-5.6-Cyber performs worse than plain Sol, which the company attributes to shorter and less detailed write-ups.
On ExploitBench, in the 300-turn standard setting, Sol through Daybreak Blue performs best and burns fewer tokens doing it. The gap narrows at 600 turns.
Read together, the specialist model is better at the narrow offensive task and not uniformly better at the job around it. OpenAI says as much in the post.
Where the framework actually draws the line
Under its Preparedness Framework, OpenAI assessed Sol as High on cyber capability, below the Critical threshold. It puts GPT-5.6-Cyber at High as well, again short of Critical. A system card follows later.
That is the whole reconciliation. Astra stalled because OpenAI could not rule out Critical. GPT-5.6-Cyber ships because the company says it does not reach it. The framework governs capability. It does not govern who gets the keys, and the keys are what changed this week.
OpenAI also adds a specific denial. It says GPT-5.6-Cyber played no part in the incident in which its own agents breached Hugging Face, and that no other models are planned for an upcoming release. That investigation is still open.
The controls around it
Daybreak access depends on identity verification, account security, monitoring, approved-use restrictions and legal attestations. Every individual Daybreak account must adopt a hardware security key from 1 September 2026.
OpenAI is also pushing Codex users off full-access mode and towards auto-review, promising more monitoring in the coming weeks and prioritising alignment training in the next Daybreak releases. Its own framing is unusually blunt.
“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment.”
Why defenders wanted this
Refusal rates have been the sector’s standing complaint. When the US restricted Fable 5, around 100 security researchers signed an open letter arguing the ban took the best models away from defenders without removing any real risk.
Washington later cleared Anthropic to restore Mythos 5 for a vetted group of defenders. That set the template Daybreak now follows.
Named early partners include SpecterOps, SentinelOne and Palo Alto Networks. Jared Atkinson, chief technology officer at SpecterOps, says the model “is materially improving our specialist vulnerability-research workflows” and has closed work in under a day that older models left unresolved for weeks.
Axios adds that Accenture, IBM, CrowdStrike, Cisco and Palo Alto Networks can now fold the models into security products, managed services and customer work. That is a commercial supply chain, not a research pilot.
The window OpenAI is betting on
The company’s title says the cyber defence window is narrowing. The argument is that attackers will deploy offensive AI at scale sooner or later, so defenders need the same tooling first.
It is a reasonable bet and an unfalsifiable one. Nobody can prove the window closed at the right moment, and the cost of being wrong sits with everyone running the software these models are pointed at.
What is testable is narrower. One Chrome CVE is fixed, hundreds of kernel findings are queued behind a disclosure process nobody outside can see, and the company still cannot say how its own agents got into Hugging Face.
Get the TNW newsletter
Get the most important tech news in your inbox each week.