On August 10, 2026 OpenAI announced an expansion of Daybreak, its cybersecurity programme, and introduced GPT-5.6-Cyber. The company describes the release as putting “frontier intelligence in the hands of trusted defenders before attackers can deploy offensive AI at scale.” The model is built on GPT-5.6 Sol and, in OpenAI’s framing, is trained to improve on specialised cyber tasks such as finding zero-day vulnerabilities and developing exploit chains, and to reduce refusals on certain higher-risk dual-use requests.
Access is split into two tiers. Daybreak Blue offers general frontier models with defensive safeguards for vulnerability discovery, secure code review, malware analysis, incident response and patch validation. Daybreak Red is the restricted tier that carries GPT-5.6-Cyber, and OpenAI states that “access is limited to approved defenders, with additional controls and monitoring for higher-risk cybersecurity work.” There is no self-serve path: individuals verify identity and request trusted access, organisations apply through an enterprise form, and the model is provisioned only after approval. OpenAI’s developer documentation lists gpt-5.6-cyber as available on the Responses API only, with a 400,000-token context window and pricing of 12.50 dollars per million input tokens and 75 dollars per million output tokens.
The company reports that GPT-5.6-Cyber completes 95.0 percent of advanced cybersecurity requests, against 1.5 percent for GPT-5.6 Sol and 2.0 percent under Daybreak Blue access. Those are OpenAI’s own numbers on OpenAI’s own task set, and the announcement does not publish the underlying request taxonomy, so the figures show the size of the refusal gap the company chose to close rather than an independent capability measurement. OpenAI also says it used the model in its own vulnerability research, citing previously unknown flaws surfaced in Chrome’s v8 engine and other open-source software.
The structural point for a technical leader is that the safeguard has moved from the model to the account. Refusal behaviour was the control surface for dual-use cyber capability across the industry; here that control is deliberately relaxed and replaced by identity verification, approval and monitoring, with hardware security keys required on individual Daybreak accounts from September 1, 2026. That is a defensible design, but it converts a technical guardrail into an access-management problem, and access management is a category with a long record of failure. The unproven part is whether approved-defender vetting holds at scale, and whether the defensive advantage OpenAI is claiming actually outruns the offensive value of the same capability once the tier is large enough to leak.