OpenAI has restructured its cybersecurity access program and released a new specialized model that the company says can now complete the overwhelming majority of advanced exploit-development tasks it is tested against — a jump the company is treating seriously enough to require hardware security keys for anyone using it.
The changes, announced Monday, split OpenAI's year-old Daybreak program for vetted cybersecurity professionals into two tiers. Daybreak Blue gives approved defenders general-purpose access to GPT-5.6 Sol for day-to-day security work such as incident response and patch validation. Daybreak Red is reserved for a new, purpose-trained model, GPT-5.6-Cyber, gated behind tighter vetting for vulnerability research, exploit validation and offensive security testing.
The gap between the two tiers is stark. GPT-5.6-Cyber completes roughly 95 percent of sensitive requests covering exploit-chain development, authentication bypass and privilege escalation, up from about 57 percent for its predecessor, GPT-5.5-Cyber, and far above the low single digits that standard GPT-5.6 Sol manages on the same tests, according to Unite.AI's review of the release.
A model that finds real bugs
OpenAI says GPT-5.6-Cyber has already proven its offensive capability outside the lab. Using the model, researchers discovered two previously unknown vulnerabilities in Chrome's V8 JavaScript engine that could be chained together to corrupt memory and escape the browser's security sandbox. One of the flaws, a compiler bug that could let an attacker read or overwrite memory, was assigned CVE-2026-15903 after OpenAI coordinated disclosure with Google, which has since patched it. The model is also reported to have flagged more than 400 privilege-escalation issues across various systems, including at least five in a widely used mobile operating system.
Those results are why OpenAI is classifying GPT-5.6-Cyber as "High" under its internal Preparedness Framework, the scale it uses to judge how dangerous a model's capabilities could be if misused. It is the first OpenAI model to reach that tier for cybersecurity — one step below the "Critical" threshold that would trigger the company's most severe restrictions.
The timing has invited scrutiny. The release follows a string of AI-linked security incidents this year, including a breach affecting the Hugging Face model-hosting platform. OpenAI moved to head off questions about its own model's role in that incident directly, according to a report from Digit.
GPT 5.6 Cyber was not involved in exploiting Hugging Face, nor are any other models planned for an upcoming release.
OpenAI
Locking down access
Because a model this capable at finding and chaining exploits could just as easily be turned toward attack as defense, OpenAI is pairing the release with tighter account security. Starting September 1, hardware security keys will be mandatory for every individual Daybreak account, closing off a path where a compromised password alone could hand an attacker access to exploit-generation tooling. Red-tier access remains restricted to vetted security researchers and organizations, which OpenAI says it reviews case by case.
The move fits a broader pattern this year of frontier AI labs racing to arm defenders before offensive uses of AI-assisted hacking become routine, even as each new capability jump raises the question of how long that head start will last. OpenAI has framed the release around what it calls a narrowing "cyber defense window" — the idea that AI will eventually be able to find and exploit vulnerabilities faster than human teams can patch them — and argues that giving security teams equally capable tools is its best answer for now.
What happens next will hinge on uptake among the defenders OpenAI is courting, and on whether rivals such as Google DeepMind and Anthropic, which run their own AI-for-security efforts, follow with comparable capability disclosures. OpenAI has not said how many organizations currently hold Daybreak Red access, or whether the mandatory security-key policy will eventually extend to Daybreak Blue as well.