Expanding Daybreak as Cyber Defense Window Narrows

·

OpenAI is expanding its Daybreak platform, which provides access to advanced cyber capabilities for trusted defenders. The move comes as the cybersecurity landscape becomes increasingly complex, with threat actors leveraging AI to conduct attacks at unprecedented speed and scale.

The company’s latest model, GPT-5.6-Cyber, is designed to improve performance on specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains. It is available through Daybreak Red access, which provides more advanced capabilities than the standard Daybreak Blue tier.

GPT-5.6-Sol, a general-purpose model, has been shown to deliver state-of-the-art performance on cybersecurity tasks in production environments. However, it can block legitimate defensive work due to system-level safeguards designed to prevent misuse. Daybreak Blue access removes these guardrails, allowing defenders to get more out of the model in real-world security tasks.

Even with reduced safeguarding, GPT-5.6-Sol may still refuse to comply with certain highly dual-use cybersecurity prompts. To address this issue, OpenAI trained GPT-5.6-Cyber to further reduce refusals and improve performance on specific tasks. The model is designed to help trusted defenders conduct legitimate security activities.

To measure the reduced rate of refusals provided by GPT-5.6-Cyber through Daybreak Red access, OpenAI created an internal evaluation called Advanced Cybersecurity Completion Rate. This metric measures how often models will respond to requests involving exploit-chain development and other advanced cybersecurity scenarios. According to this evaluation, GPT-5.6-Cyber completes 95% of these requests compared to just 1.5% for GPT-5.6-Sol.

GPT-5.6-Cyber outperforms both GPT-5.6-Sol and the previous model, GPT-5.5-Cyber, on several specialized cybersecurity tasks. On ExploitGym, which evaluates an agent’s ability to turn known vulnerabilities into working exploits in controlled environments, GPT-5.6-Cyber shows significant improvement over its predecessors.

Another area where GPT-5.6-Cyber excels is finding and accurately calibrating the severity of novel zero-day vulnerabilities. OpenAI created an internal evaluation dataset that provides models with a current release of an open-source repository, asking them to generate proof-of-concept exploits alongside a technical write-up of their findings.

GPT-5.6-Cyber also shows improvement on Vulnerability Discovery and Report Writing, which evaluates an agent’s ability to find vulnerabilities in a repo with known vulnerabilities. While GPT-5.6-Sol performs better than GPT-5.6-Cyber on this evaluation, the latter model still outperforms its predecessor.

OpenAI has also used GPT-5.6-Cyber to identify high-severity issues in various software projects, including popular databases and mobile phones. The company is working closely with Daybreak partners and members of the open-source community to disclose and remediate these vulnerabilities.

The Preparedness Framework assesses a model’s cybersecurity capability as High for GPT-5.6-Sol and similarly reaches the High threshold but not Critical for GPT-5.6-Cyber. The latter model improved over its predecessor on some specialized cyber tasks, but not sufficiently to reach the Critical threshold.

OpenAI is taking additional steps to enable safer use of cyber models through identity verification, account security, monitoring, approved-use restrictions, and legal attestations. The company also encourages Daybreak customers using Codex to switch from full-access mode to auto-review mode, which evaluates actions requiring elevated permissions before execution.

The company requires all individual accounts in Daybreak to adopt hardware security keys beginning September 1, 2026. OpenAI is actively working on additional security measures, including improved monitoring, and prioritizing alignment training and testing for upcoming releases.