OpenAI launches GPT-5.6-Cyber to find vulnerabilities before hackers
OpenAI has launched GPT-5.6-Cyber, a specialised AI model that helps approved security teams find vulnerabilities and validate exploits.
AI is moving deeper into cybersecurity, and OpenAI wants trusted defenders to have access to the same level of capability that attackers could eventually gain.
OpenAI has introduced GPT-5.6-Cyber, a specialised model designed to help approved security teams find vulnerabilities, validate exploits and strengthen software before attackers can take advantage of weaknesses.
The model is part of an expanded OpenAI Daybreak programme, which gives vetted researchers access to AI tools for authorised security work. Its approach is to give capable defensive teams better tools while keeping access to higher-risk capabilities tightly controlled.
A model built for harder security tasks
GPT-5.6-Cyber is based on GPT-5.6 Sol but has been further trained for specialised security work. Its capabilities include identifying zero-day vulnerabilities, which are previously unknown software flaws, validating weaknesses and testing exploit chains in controlled environments.
The model is available through Daybreak Red, a higher-access tier for approved users conducting vulnerability research, exploit validation and red-team exercises. Red teaming involves deliberately testing systems in controlled conditions to discover weaknesses before real attackers do.
Two access levels for different needs
OpenAI is expanding Daybreak into two tiers. Daybreak Blue is intended for most security teams. It provides access to general-purpose frontier models such as GPT-5.6 Sol, with safeguards adapted for legitimate defensive tasks.
These include secure code reviews, malware analysis, incident response, vulnerability discovery and patch validation. Daybreak Red is designed for teams working on more sensitive research. It provides access to GPT-5.6-Cyber for authorised testing where normal restrictions could interfere with legitimate security work.
Why OpenAI is reducing refusals
Security research often involves dual-use techniques. A method used to understand and fix a vulnerability can also be misused by an attacker. OpenAI says GPT-5.6-Cyber is designed to reduce unnecessary refusals for approved users while maintaining strict access controls.
GPT-5.6-Cyber showed a major lead in OpenAI's internal Advanced Cybersecurity Completion Rate evaluation. It completed 95.0% of advanced security requests, compared with 1.5% for GPT-5.6 Sol and 2.0% for GPT-5.6 Sol with Daybreak Blue access. GPT-5.5-Cyber completed 57.3%.
The model has already found vulnerabilities
OpenAI says GPT-5.6-Cyber has been used to examine real-world software. In one case, researchers used it to investigate V8, the JavaScript engine used by Chrome. The model helped identify two previously unknown vulnerabilities that could be chained to cause memory corruption and escape the V8 heap sandbox. Google fixed the issue.
OpenAI also says the model found high-severity vulnerabilities in other software, including a mobile operating system, a database and an operating system kernel. The company says it is working with affected partners and open-source communities to disclose and fix the issues responsibly.
Powerful tools need tighter controls
OpenAI says access to Daybreak is restricted to approved individuals and organisations. The programme includes identity verification, account security measures, monitoring, approved-use requirements and legal attestations.
From 1 September 2026, individual Daybreak accounts will also be required to use hardware security keys. OpenAI recommends that teams run high-risk workflows inside isolated environments, monitor agent actions and clearly define what systems an AI agent is authorised to access.
A new role for AI in cyber defence
GPT-5.6-Cyber points to a broader change in security operations. AI is moving beyond routine code analysis and support tasks towards vulnerability research, exploit validation and more complex security testing.
For organisations, the potential benefit is speed. Finding a vulnerability earlier can give developers more time to patch it before it becomes an active threat. But greater capability also brings greater responsibility.
OpenAI's Daybreak model shows that the future of AI-powered security may depend as much on access controls and oversight as on the intelligence of the models themselves.


