OpenAI expanded its Daybreak cybersecurity program on August 10 with a two-tier structure and a new specialized model. Daybreak Blue provides approved defenders access to GPT-5.6 Sol (a frontier general-purpose model) with system-level cyber guardrails removed for everyday security work like vulnerability discovery, malware analysis, and incident response. Daybreak Red gates GPT-5.6-Cyber, a purpose-trained cybersecurity model, behind stricter vetting for authorized vulnerability research, exploit validation, and security testing.
GPT-5.6-Cyber is built on GPT-5.6 Sol but trained to reduce refusals on dual-use cybersecurity tasks and improve performance on specialized workflows like zero-day discovery and exploit-chain development. On OpenAI's internal Advanced Cybersecurity Completion Rate benchmark, GPT-5.6-Cyber answers 95% of advanced prompts involving exploit chains, authentication bypasses, and privilege escalation—compared to just 1.5% for standard GPT-5.6 Sol and 2% for Daybreak Blue. The model discovered two previously unknown V8 vulnerabilities in Chrome that could be chained to corrupt memory and escape the V8 heap sandbox (CVE-2026-15903), which Google has already patched.
For security teams and defenders, this dual-tier design reflects the tension between enabling legitimate defensive work and preventing offensive misuse. Partner programs include Accenture, IBM, CrowdStrike, Cisco, and Palo Alto Networks. Access requires identity verification, approved-use restrictions, legal attestations, and—starting September 1, 2026—hardware security keys for individual accounts. GPT-5.6-Cyber stays below OpenAI's 'Critical' threshold but represents its first frontier cyber model with refusal-mitigated capabilities at scale for authorized defenders.