GPT-5.6-Cyber is a cybersecurity-specific model released by OpenAI on August 10, 2026 and distributed only through Daybreak Red, one of two access tiers the company introduced the same day for its Daybreak programme for cyber defenders. It is built on GPT-5.6 Sol and trained both to improve performance on specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains, and to reduce refusals on certain higher-risk dual-use cyber requests (Source: openai.com).
| Field | Value | |
|---|---|---|
| Developer | [[companies/openai\ | OpenAI]] |
| Announced | August 10, 2026 | |
| Base model | [[models/gpt-56\ | GPT-5.6 Sol]] |
| Access | Daybreak Red (approved individuals and organizations) | |
| Open weights | No | |
| Preparedness classification | High for cybersecurity; below Critical |
Daybreak access tiers
OpenAI framed the release around what it described as a narrowing window for defenders as threat actors adopt AI for attacks at greater speed and scale, including in fully autonomous ways, stating that its answer was to "put frontier intelligence in the hands of trusted defenders everywhere before attackers deploy offensive AI capabilities at scale" (Source: openai.com). Daybreak was expanded into two tiers:
- Daybreak Blue provides access to frontier general-purpose models, including GPT-5.6 Sol, with safeguards tailored to authorized defensive security work. OpenAI describes it as the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response and patch validation. In production OpenAI deploys system-level safeguards that screen cybersecurity-related requests; Daybreak Blue removes those guardrails, which the company says can otherwise block legitimate defensive work.
- Daybreak Red provides access to the purpose-trained cybersecurity models for authorized vulnerability research, exploit validation and security testing. OpenAI recommends it for teams whose authorized work includes advanced vulnerability research, exploit development or red teaming.
OpenAI states that even without system-level guardrails GPT-5.6 Sol still refuses highly dual-use prompts, giving penetration testing of production systems as an example, and that GPT-5.6-Cyber was trained to address that residual refusal behaviour (Source: openai.com). Axios reported that Accenture, IBM, CrowdStrike, Cisco and Palo Alto Networks may incorporate the models into security products and managed services (Source: axios.com).
Capabilities and benchmarks
All figures below are self-reported by OpenAI and, per a footnote to the announcement, use each model's highest publicly available reasoning level; OpenAI notes that GPT-5.6-Cyber tends to spend a larger reasoning budget than GPT-5.6 Sol, producing higher token usage (Source: openai.com).
Refusal reduction
OpenAI built an internal evaluation, the Advanced Cybersecurity Completion Rate, to measure how often a model responds to requests involving exploit-chain development, authentication bypass, privilege escalation and other advanced cybersecurity scenarios.
| Configuration | Completion rate |
|---|---|
| GPT-5.6-Cyber (Daybreak Red) | 95.0% |
| GPT-5.5-Cyber (Daybreak Red) | 57.3% |
| GPT-5.6 Sol (Daybreak Blue) | 2.0% |
| GPT-5.6 Sol (safeguards enabled) | 1.5% |
OpenAI presented the increase over GPT-5.5-Cyber as a response to feedback from security researchers who encountered persistent refusals with the earlier model (Source: openai.com).
Exploit development and vulnerability research
On ExploitGym, which evaluates whether agents can turn known vulnerabilities into working exploits achieving arbitrary code execution in controlled environments, OpenAI reports GPT-5.6-Cyber outperforming both GPT-5.6 Sol and GPT-5.5-Cyber; the evaluations were run on an internal implementation in security-hardened, isolated environments with monitoring for misaligned behaviour. On an internal dataset that supplies models with the current release of an open-source repository and asks for proof-of-concept exploits of maximum impact plus a technical write-up — scored on severity and impact of findings and on the calibration and quality of the write-up — GPT-5.6-Cyber outperformed GPT-5.6 Sol (Source: openai.com).
Results are not uniformly in the specialized model's favour. On OpenAI's internal Vulnerability Discovery and Report Writing evaluation, which scores an agent on finding severe and actionable vulnerabilities, developing a working proof of concept and submitting a high-quality report, both GPT-5.6 Sol and GPT-5.6-Cyber improve over GPT-5.5-Cyber, but GPT-5.6-Cyber performs worse than GPT-5.6 Sol; OpenAI attributes this to the model sometimes producing shorter, less detailed vulnerability reports. On ExploitBench, which tests development of a V8 vulnerability into a full exploit with defensive protections such as the V8 sandbox left enabled and less information supplied about the target vulnerability, GPT-5.6 Sol through Daybreak Blue solves tasks more token-efficiently and performs best in the standard 300-turn setting; extending to 600 turns narrows the gap between the two models (Source: openai.com).
Jared Atkinson, chief technology officer of SpecterOps, one of the early-access customer partners, said the model "is materially improving our specialist vulnerability-research workflows," reasoning "more accurately about real exploit constraints," tracking complex state better, and completing "work in under a day that earlier models had not resolved after weeks of intermittent effort" (Source: openai.com).
Findings in deployed software
OpenAI reports using GPT-5.6-Cyber after its training run to study selected software projects. In V8, the JavaScript engine used by Chrome, the model surfaced two previously unknown vulnerabilities that could be chained to corrupt memory and escape the V8 heap sandbox; OpenAI researchers validated the findings and reported them to Google through coordinated vulnerability disclosure, and Google issued a fix as CVE-2026-15903. OpenAI describes CVE-2026-15903 as a high-severity V8 issue in which the optimizing compiler incorrectly skipped a safety check when converting values to integers, allowing undefined values to produce an unexpectedly large number; used as an array index, the result could cause the compiler to omit the usual bounds check, permitting an attacker to read or overwrite memory belonging to other objects and potentially execute arbitrary code inside Chrome's sandbox. Escaping the heap sandbox would generally require a second vulnerability, which OpenAI says the model also found (Source: openai.com).
OpenAI additionally reports at least five vulnerabilities in an unnamed widely used mobile operating system, including a chain from an untrusted application to local privilege escalation; three critical vulnerabilities in an unnamed widely used database, including a remote path to code execution; and over 400 vulnerabilities leading to privilege escalation in an unnamed widely used operating-system kernel. It states it is working with Daybreak partners and the open-source community to disclose and remediate these (Source: openai.com).
Safety and evaluations
Under OpenAI's Preparedness Framework, GPT-5.6 Sol was assessed as High for cybersecurity capability and below the Critical threshold. OpenAI states that it evaluated GPT-5.6-Cyber's frontier cyber capabilities before launch and determined that it likewise reaches High but not Critical: the model improved over GPT-5.6 Sol on some specialized cyber tasks it was directly trained for, "but not sufficiently to reach our Critical threshold." The company said GPT-5.6-Cyber was not involved in exploiting Hugging Face (OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation (OpenAI, July 2026)), "nor are any other models planned for an upcoming release," and that a system card with further evaluations would be published at a later date (Source: openai.com).
The release came three days after OpenAI disclosed, on August 7, 2026, that preliminary evaluations of its unreleased Astra model left it unable to rule out Critical cybersecurity capability, and that it was pausing internal activities involving Astra that did not meet strengthened controls (Source: openai.com).
Access and safeguards
OpenAI acknowledges that "models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment," while stating that it believes "democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense." Daybreak Blue and Daybreak Red access are available to approved individuals and organizations conducting authorized work, controlled through identity verification, account security, monitoring, approved-use restrictions and legal attestations (Source: openai.com).
Announced alongside the release were several additional measures: Daybreak customers using Codex are strongly encouraged, through application defaults and interface features, to switch from full-access mode to auto-review mode, which evaluates actions requiring elevated permissions before execution and can block requests posing a significant risk of destructive behaviour; all individual Daybreak accounts must adopt hardware security keys beginning September 1, 2026; further security measures including improved monitoring were said to be rolling out in the following weeks; alignment training and testing were being prioritized for upcoming Daybreak releases; and Codex documentation on safety best practices was updated. OpenAI's stated best practices for the Daybreak series are to run security workflows in controlled environments without access to sensitive production systems or the open internet and to test sandbox boundaries regularly, to review tool calls outside the Codex sandbox before execution and add monitoring and human oversight for higher-risk workflows, and to specify authorized systems and actions using scoped permission profiles (Source: openai.com).
Relationships
- instance-of: Autonomous cyber-agents, AI and Cybersecurity
- depends-on: GPT-5.6 (Sol, Terra, Luna) (base model), OpenAI Preparedness Framework V.2 (classification regime)
- related: Astra, OpenAI, OpenAI and Hugging Face Partner to Address Security Incident During Model Evaluation (OpenAI, July 2026), Dual-Use Frontier AI