OpenAI is splitting its cybersecurity program into two access tiers and releasing a new purpose-trained model alongside them, the company announced on August 10, 2026. Daybreak Blue opens frontier general-purpose models, including GPT-5.6 Sol, to approved defenders for everyday security work, while Daybreak Red gates the new GPT-5.6-Cyber model behind tighter vetting for vulnerability research, exploit validation, and security testing.
The structure addresses a tension OpenAI says it has been managing in production. The system-level safeguards it runs on GPT-5.6 Sol screen cybersecurity-related requests to prevent misuse, but the company says those same screens block legitimate defensive work. Daybreak Blue removes them for verified users. A residue of highly dual-use prompts, such as penetration testing production systems, still draws refusals even under Blue access, which is where GPT-5.6-Cyber comes in: a version of GPT-5.6 Sol trained to reduce refusals on advanced cybersecurity tasks and to improve on specialized work like finding zero-day vulnerabilities and developing exploit chains.
What the evaluations measured
To quantify how much more permissive the new model is, OpenAI built an internal evaluation it calls the Advanced Cybersecurity Completion Rate, measuring how often models respond to requests involving exploit-chain development, authentication bypass, privilege escalation, and similar scenarios. On that benchmark, the company reports, GPT-5.6-Cyber completes 95.0% of requests, against 1.5% for GPT-5.6 Sol under standard safeguards and 2.0% for GPT-5.6 Sol under Daybreak Blue. The prior purpose-trained model, GPT-5.5-Cyber, completed 57.3%, a refusal rate the company says generated persistent complaints from security researchers.
Capability evaluations tell a more qualified story. On ExploitGym, which tests whether agents can turn known vulnerabilities into working exploits that achieve code execution in controlled environments, OpenAI says GPT-5.6-Cyber outperforms both GPT-5.6 Sol and GPT-5.5-Cyber. On the company’s internal Vulnerability Discovery and Report Writing evaluation, GPT-5.6-Cyber improves over GPT-5.5-Cyber but lands below GPT-5.6 Sol, a result OpenAI attributes to the model producing shorter, less detailed reports. On ExploitBench, a harder exploitation task with the V8 sandbox enabled and less information given to the agent, the general-purpose GPT-5.6 Sol performs best within the standard 300-turn limit, with the gap narrowing when runs extend to 600 turns. All of these figures are vendor-reported, several on internal benchmarks that outside evaluators have not replicated.
The claims with the most weight behind them are not benchmarks at all. OpenAI says it used GPT-5.6-Cyber to investigate V8, the JavaScript engine inside Chrome, and uncovered two previously unknown vulnerabilities that could be chained to corrupt memory and escape the V8 heap sandbox. The first, a compiler bug in which a skipped safety check lets an attacker read or overwrite memory inside Chrome’s sandbox, was reported to Google through coordinated disclosure, fixed, and assigned CVE-2026-15903. The company also lists, without naming the affected software, at least five vulnerabilities in a popular mobile operating system including a privilege-escalation chain from an untrusted app, three critical vulnerabilities in a popular database including a remote path to code execution, and more than 400 privilege-escalation vulnerabilities in a popular operating system kernel, all moving through disclosure with Daybreak partners and open-source maintainers.
SpecterOps, the security firm whose CTO Jared Atkinson tested the model early, described the results in terms of work compression: the model “has completed work in under a day that earlier models had not resolved after weeks of intermittent effort.”
How the two tiers are governed
Access to both tiers runs through identity verification, account security requirements, monitoring, approved-use restrictions, and legal attestations, with separate application paths for individuals and organizations. OpenAI is pushing Daybreak customers using its Codex coding agent from full-access mode toward an auto-review mode that evaluates actions requiring elevated permissions before execution, and the company will require hardware security keys on all individual Daybreak accounts beginning September 1, 2026. A system card with further evaluations of GPT-5.6-Cyber is planned for a later date.
Under OpenAI’s Preparedness Framework, both GPT-5.6 Sol and GPT-5.6-Cyber were assessed as High for cybersecurity capability and below the Critical threshold. That assessment lands days after Unite.AI reported that OpenAI’s upcoming Astra model may cross the Critical cybersecurity threshold, and the company used the announcement to reiterate a point from its earlier incident disclosures: GPT-5.6-Cyber was not involved in the exploitation of Hugging Face, and no model with that involvement is slated for release.
Where Daybreak stood before this release
The tiered structure consolidates a program that had been expanding in pieces. OpenAI launched the full version of GPT-5.5-Cyber on June 22, 2026 alongside a Daybreak Cyber Partner Program counting Accenture, CrowdStrike, Cisco, IBM, and Palo Alto Networks among its participants, and Patch the Planet, an open-source remediation initiative founded with Trail of Bits. On that earlier release, OpenAI reported GPT-5.5-Cyber reaching 85.6% on CyberGym against 81.8% for GPT-5.5, and 39.5% against 25.95% on ExploitGym.
Per the June 22 post, more than 30 open-source projects committed to participate, and the initial five-day sprint surfaced hundreds of issues with dozens of patches merged. Daybreak Blue and Red replace what had been a single Trusted Access track with a two-rung ladder: the general-purpose frontier, guardrails relaxed, for the broad defender base, and a refusal-light specialist model for the smaller group whose authorized work runs to exploit development and red teaming.
Credit: Source link

























