Access Restricted to Vetted Partners

OpenAI Introduces GPT-5.6-Cyber Security Model

GPT-5.6-Cyber, OpenAI, OpenAI GPT-5.6-Cyber cybersecurity model, GPT-5.6-Cyber for vulnerability research, OpenAI AI model for exploit development
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Robert Way/Shutterstock.com

OpenAI has introduced GPT-5.6-Cyber, a specialized cybersecurity model whose access will remain restricted to vetted defenders and partner organizations.

The existing Daybreak program, which provides security teams with access to AI models, tools, and workflows for cyber defense, will now be split into two tiers: Daybreak Blue and Daybreak Red. OpenAI describes Blue as the “recommended starting point for most defenders.” It provides access to GPT-5.6 Sol without the model’s usual system-level cybersecurity safeguards. The model can be used for tasks such as malware analysis, incident response, and patch validation.

Ad

Red, by contrast, is designed for more specialized and tightly controlled work. It is the only tier that provides access to the new GPT-5.6-Cyber model, which was specifically trained for exploit development and validation as well as advanced vulnerability research.

In an internal test called the Advanced Cybersecurity Completion Rate, OpenAI says GPT-5.6-Cyber answered 95 percent of sensitive security requests, including requests involving exploit chain development, authentication bypasses, and privilege escalation. In the same test, the standard GPT-5.6 Sol model with its security safeguards enabled answered just 1.5 percent of such requests. The version available through Daybreak Blue reached around 2 percent, while the previous GPT-5.5-Cyber model scored 57.3 percent.

Despite its high response rate, OpenAI classifies GPT-5.6-Cyber differently under its own Preparedness Framework. Unlike the recently introduced Astra model, GPT-5.6-Cyber is placed in the category of high, but not critical, cyber capability.

Ad

OpenAI Requires Identity Verification and Hardware Security Keys

According to OpenAI, access to both tiers requires identity verification, additional account security measures, continuous monitoring, and legally binding user agreements. Starting September 1, 2026, hardware security keys will also be mandatory for all Daybreak accounts.

Cybersecurity vendors and consulting firms can additionally apply to the Daybreak Cyber Partner Program. Companies including Accenture, IBM, CrowdStrike, Cisco, and Palo Alto Networks can already integrate the models into their own security products and managed services through the program. Direct access to the models remains with the approved partner and is not automatically passed on to its end customers.

OpenAI also explicitly stressed that GPT-5.6-Cyber was not involved in the recently disclosed security incident affecting the Hugging Face platform. None of the models planned for upcoming releases are intended to be used for a corresponding test, either.

(Editorial Team)

Ad

Artikel zu diesem Thema

Weitere Artikel