Summary
- GPT‑5.6‑Cyber is a purpose-trained model for advanced vulnerability research, exploit validation, and other specialised cybersecurity work.
- OpenAI says it completes 95% of requests in an internal advanced-cyber evaluation, compared with 1.5% for safeguarded GPT‑5.6 Sol.
- Daybreak Red access is controlled through identity verification, account security, monitoring, approved-use restrictions, and legal attestations.
OpenAI has released a cybersecurity-specific model through a restricted-access programme that deliberately reduces refusals on advanced exploit-development and vulnerability-research tasks.
GPT‑5.6‑Cyber is available through Daybreak Red, the more permissive of two access tiers in an expanded OpenAI Daybreak programme announced on 10 August. The company describes the model as purpose-trained for authorised vulnerability research, exploit validation, security testing, and related advanced work.
Daybreak Blue gives approved defenders access to general-purpose frontier models including GPT‑5.6 Sol with system-level cyber guardrails removed. OpenAI says that configuration still refuses some highly dual-use requests, which led it to train GPT‑5.6‑Cyber to reduce refusals further for selected authorised users.
The difference is substantial in OpenAI’s own testing. On an internal Advanced Cybersecurity Completion Rate evaluation covering exploit-chain development, authentication bypass, privilege escalation, and other advanced scenarios, GPT‑5.6‑Cyber completed 95% of requests.
The company reports completion rates of 1.5% for GPT‑5.6 Sol with its normal safeguards and 2% for GPT‑5.6 Sol under Daybreak Blue. GPT‑5.5‑Cyber completed 57.3% in the same evaluation.
Those are internal company measurements rather than independent assessments of real-world offensive effectiveness. They nevertheless make the access distinction unusually explicit: OpenAI is intentionally providing an approved group with a system that will respond to categories of cyber request its generally available configurations decline.
The company also reports stronger performance for GPT‑5.6‑Cyber on parts of its exploit-development and vulnerability-research evaluation suite. It says the model outperforms GPT‑5.6 Sol and GPT‑5.5‑Cyber on ExploitGym, while GPT‑5.6 Sol remains stronger in some other evaluations, including a standard ExploitBench setting.
OpenAI has already used GPT‑5.6‑Cyber internally to research real software. The company says it identified previously unknown vulnerabilities in Google’s V8 JavaScript engine, including a flaw subsequently assigned CVE-2026-15903 after coordinated disclosure and remediation.
The capability is being governed through restricted distribution rather than ordinary model safeguards alone. OpenAI says Daybreak access uses identity verification, account-security requirements, monitoring, approved-use restrictions, and legal attestations.
Individual Daybreak users will also be required to adopt hardware security keys from 1 September. OpenAI says it is continuing to develop additional monitoring and is encouraging use of an auto-review mode for agent actions requiring elevated permissions.
That makes Daybreak Red closer to privileged technical access than a conventional software tier. The control problem includes not only whether a user is permitted to conduct advanced research, but how identity is established, how use is monitored, what environments are authorised, and how access can be withdrawn when the risk changes.
The programme is also a test of whether capability can be distributed selectively as cyber models become more useful for both vulnerability discovery and exploitation. OpenAI assesses GPT‑5.6‑Cyber as reaching its High cybersecurity capability threshold but remaining below the Critical threshold under its Preparedness Framework.
The policy challenge will become more difficult if those capabilities continue to improve. Daybreak creates a clearer distinction between general cyber assistance and privileged access to specialised models, while also creating a high-value access tier whose controls will need to remain credible as the underlying capability grows.



