Daybreak, OpenAI’s controlled-access program for authorized cybersecurity work, now includes Daybreak Red, a new tier that gives approved users GPT-5.6-Cyber to find unknown vulnerabilities and develop working exploits.
OpenAI expanded its Daybreak program to two access tiers and introduced GPT-5.6-Cyber, a new model for approved users conducting advanced cybersecurity research.
Daybreak gives approved individuals and organizations access to OpenAI models for authorized security work. The program now separates that access into Daybreak Blue and Daybreak Red.
Daybreak Blue provides general-purpose models without the usual cybersecurity guardrails so approved partners can run defensive tasks such as reviewing code, analyzing malicious software, responding to incidents, and checking security patches. OpenAI recommends Blue as the starting point for most approved users.
Daybreak Red provides access to OpenAI’s cyber-specific models for more advanced cybersecurity work. That includes researching vulnerabilities, confirming whether a flaw can be used to compromise software, and testing security under authorization.
Daybreak Red allows more advanced security testing
Daybreak Blue removes the usual system checks that screen cybersecurity requests. However, GPT-5.6 Sol can still block work involving techniques that could be used to compromise a system.
Under the Daybreak Red initiative, GPT-5.6-Cyber was trained with fewer of those built-in restrictions. It can assist approved researchers with testing whether vulnerabilities can be combined to break into a system, bypass access controls, or gain administrative control.
GPT-5.6-Cyber completed 95% of the requests, compared with 1.5% for GPT-5.6 Sol with its standard safeguards and 2% for GPT-5.6 Sol through Daybreak Blue.
GPT-5.6-Cyber finds vulnerabilities in real software
OpenAI said it used GPT-5.6-Cyber to find two previously unknown vulnerabilities in V8, the software engine used by Chrome. Researchers confirmed the flaws and reported them to Google, which fixed a high-severity vulnerability.
The company also said the model helped identify at least five vulnerabilities in a widely used mobile operating system, three critical vulnerabilities in a popular database, and more than 400 ways to gain higher levels of access through a widely used operating-system kernel. OpenAI did not name those products and said disclosure and repair work remains underway.
OpenAI assessed GPT-5.6-Cyber as reaching its “High” cybersecurity capability level but remaining below its highest “Critical” threshold. OpenAI said it will publish a technical report with more GPT-5.6-Cyber test results, but did not provide a release date.
Daybreak uses OpenAI’s existing Trusted Access for Cyber program to approve users and determine which models and security-testing capabilities they can access.
Beginning September 1, 2026, OpenAI will require individual accounts (not companies or organizations) to use a physical security key. The company is also encouraging customers using Codex to adopt its auto-review mode, which checks actions requiring elevated system permissions before they run. OpenAI said additional monitoring measures are planned in the coming weeks.

