OpenAI announced on August 10, 2026, an expansion of its OpenAI Daybreak program, adding two access tiers—Daybreak Blue and Daybreak Red—intended for approved cybersecurity defenders. According to OpenAI's post, Daybreak Blue access removes system-level guardrails that screen cybersecurity-related requests, which the company says can block legitimate defensive work such as incident detection and response, investigations, vulnerability management, and security assessments. The company also introduced GPT-5.6-Cyber, a cybersecurity-specific model available through Daybreak Red access and built on GPT-5.6 Sol. OpenAI states the model is trained to improve performance on tasks such as finding zero-day vulnerabilities and developing exploit chains, and to reduce refusals on certain higher-risk, dual-use cyber tasks. Using an internal evaluation it calls the Advanced Cybersecurity Completion Rate, OpenAI reports GPT-5.6-Cyber completes 95.0% of tested requests, compared with 1.5% for GPT-5.6 Sol, 2.0% for GPT-5.6 Sol with Daybreak Blue, and 57.3% for the earlier GPT-5.5-Cyber. OpenAI says the changes are motivated by a 'narrowing window' for defenders as threat actors increasingly use AI. The company reported mixed results across benchmarks including ExploitGym, ExploitBench, and its internal vulnerability discovery evaluations, with each model outperforming in some settings.
- GPT-5.6-Cyber completes 95.0% of Advanced Cybersecurity Completion Rate requests vs 1.5% for GPT-5.6 Sol
- Two new access tiers—Daybreak Blue (removes guardrails) and Daybreak Red (GPT-5.6-Cyber)—are for approved defenders only
- The model is built on GPT-5.6 Sol and trained for exploit-chain development and zero-day discovery
What it means for you
OpenAI is giving vetted security professionals access to versions of its models with the usual safety brakes removed, so they can do offensive security work like finding and exploiting software flaws. For nearly everyone else, this changes nothing you can touch—it is gated behind an approval process for trusted defenders. It does signal that AI-assisted hacking is getting more capable on both the attack and defense sides.
Try this
If you run a small business, use this as a prompt to check the basics: confirm your systems auto-update, your important accounts use multi-factor authentication, and you have working backups. That is where AI-accelerated attacks will hit ordinary businesses first.
Who should care
Professional security researchers, penetration testers, and in-house security teams who might apply for Daybreak access—plus anyone tracking how AI is changing the pace of cyberattacks.
Skip this if
You are not a security professional and do not run a security function. This is a specialist, approval-only tool you cannot access and do not need to act on.
Sources: OpenAI — read the original