OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, and incident response.

OpenAI says GPT 5.6 Cyber is only available to select companies, including Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps.

It's also rolling out to supported security vendors, including Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare.

OpenAI says it won't give regular users access to the underlying models, citing security risks, and it makes sense because models have been abused to launch security attacks.

Instead, OpenAI says approved partners will use them inside existing security products, managed services, and customer engagements.

"By bringing our frontier cyber models into their services, we can help more defenders find serious vulnerabilities, validate which ones matter, and fix them faster," OpenAI wrote in a blog post.

OpenAI offers Daybreak Blue and Daybreak Red for different security work

OpenAI says partners can access two versions of ChatGPT's cyber capabilities through what the company calls Daybreak Access.

Daybreak Blue is designed for a broad range of defensive security workloads, while Daybreak Red is intended for more specialized and closely governed work.

OpenAI says the models can help security teams by:

  • identifying vulnerabilities
  • determining whether a weakness can actually be exploited
  • identifying affected systems
  • developing fixes
  • helping move those fixes into production.

Depending on the engagement, partners may use the models for vulnerability discovery and validation, red teaming, penetration testing, incident response, and remediation across enterprise environments.

OpenAI says safeguards may include identity verification, clearly defined testing scopes, logging, monitoring, and human oversight.

"Access to the underlying models remains with the approved partner and is not transferred directly to the customer," OpenAI explained. "Partners work with organizations to define the boundaries of each engagement, review findings, and apply their expertise before action is taken."

The approach gives enterprises access to more advanced AI security capabilities without requiring them to build their own specialized cyber AI infrastructure.

OpenAI says cybersecurity providers and consultancies can also apply to join the Daybreak Cyber Partner program, while organizations interested in using the technology can access it through participating security providers.

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper