OpenAI has released GPT-5.6-Cyber, a model trained to answer sensitive cyber requests its consumer model refuses, to vetted defenders working on advanced security research. The company has split its Daybreak program into two access tiers. On OpenAI's internal completion test, the new model completed 95.0% of requests involving exploit-chain development, authentication bypass, privilege escalation and other advanced cybersecurity scenarios, compared with 1.5% for GPT-5.6 Sol with its safeguards on. The launch comes days after OpenAI paused some work on Astra because preliminary evaluations left it unable to rule out a Critical cyber capability level for Astra, though it said that was not a confirmed determination.
The new model's 95.0% result therefore measures a sharp drop in refusals, not success at every task.
What Changed
- OpenAI released GPT-5.6-Cyber, a model trained to answer sensitive cyber requests its consumer model refuses, and split its Daybreak program into two access tiers.
- On OpenAI's internal Advanced Cybersecurity Completion Rate evaluation, GPT-5.6-Cyber completed 95.0% of advanced cybersecurity requests, against 1.5% for GPT-5.6 Sol with safeguards on, 2.0% under Daybreak Blue and 57.3% for GPT-5.5-Cyber.
- The model found two previously unknown flaws in V8, Chrome's JavaScript engine, which Google fixed and assigned CVE-2026-15903. Three further vulnerability claims name neither the software nor the vendors.
- Before GPT-5.6 Sol's July 2026 release, the UK AI Security Institute identified universal jailbreaks in the cyber domain that were often developed within hours.
AI-generated summary, reviewed by an editor. More on our AI guidelines.
Two levels of access
Daybreak Blue gives defenders GPT-5.6 Sol with its system-level cyber guardrails removed. Through Daybreak Red, approved researchers can access GPT-5.6-Cyber, a model built on Sol and trained to refuse less during zero-day discovery, exploit development and security testing.
Accenture, IBM, CrowdStrike, Cisco and Palo Alto Networks may put the models into security products, managed services and customer work. Entry requires identity verification, account monitoring, approved-use restrictions and legal attestations. Hardware security keys become mandatory for individual Daybreak accounts on September 1, 2026.
The internal measurements
GPT-5.5-Cyber, released on June 22, 2026, completed 57.3% of requests on the same Advanced Cybersecurity Completion Rate evaluation. GPT-5.6 Sol under Daybreak Blue completed 2.0%.
Jared Atkinson, CTO of early-access customer SpecterOps, said the model "reasons more accurately about real exploit constraints, tracks complex state better, and has completed work in under a day that earlier models had not resolved after weeks of intermittent effort."
The completion rates and benchmark comparisons in this story are OpenAI's own measurements, not independent ones, and no outside party has verified them. No system card for GPT-5.6-Cyber has been published.
Get Implicator.ai in your inbox
Strategic AI news from San Francisco. No hype, no "AI will change everything" throat clearing. Just what moved, who won, and why it matters. Daily at 6am PST.
No spam. Unsubscribe anytime.
One confirmed vulnerability chain
GPT-5.6-Cyber found two previously unknown flaws in V8, Chrome's JavaScript engine, that could be chained to corrupt memory and escape its heap sandbox. Google fixed the issue and assigned CVE-2026-15903.
OpenAI also lists at least five vulnerabilities in an unnamed mobile operating system, three critical flaws in an unnamed database and more than 400 privilege-escalation vulnerabilities in an unnamed operating-system kernel. OpenAI names neither the software nor the vendors, so those claims cannot be checked from outside.
Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.
Guardrails and their limits
Before GPT-5.6 Sol's July 2026 release, the UK AI Security Institute identified "universal jailbreaks in the cyber domain, including jailbreaks that allowed for long-form agentic task completion in domains like vulnerability discovery and exploit development". The jailbreaks "were often developed within hours."
AISI had privileged access to the safety monitor's reasoning, exact policy wording and live classifier feedback. Those tools are unavailable to an ordinary attacker. Xander Davies, who leads AISI's red team, said the jailbreaks "are still findable without this access, just slower. Exactly how much slower is unclear and an open question!"
OpenAI's own tests also found limits. GPT-5.6-Cyber performed worse than Sol on an internal vulnerability-discovery and report-writing test, which OpenAI believes is due to the model sometimes producing shorter, less detailed reports. On ExploitBench's standard 300-turn setting, Sol under Daybreak Blue performed best and used fewer tokens. The gap narrowed when the test expanded to 600 turns.
GPT-5.6-Cyber reached OpenAI's High cyber threshold, not Critical. Margaret Cunningham, vice president of security and AI strategy at DarkTrace, said: "My concern is less that one model was jailbroken and more that offensive discovery is speeding up while defense still depends on very human processes: figuring out what matters, what can be patched, and what has to be contained."
Frequently Asked Questions
What is GPT-5.6-Cyber?
A model built on GPT-5.6 Sol and trained to refuse less during zero-day discovery, exploit development and security testing. It is available to approved researchers through the Daybreak Red tier. It reached OpenAI's High cyber threshold, not Critical.
What is the difference between Daybreak Blue and Daybreak Red?
Daybreak Blue gives defenders GPT-5.6 Sol with its system-level cyber guardrails removed. Through Daybreak Red, approved researchers can access GPT-5.6-Cyber for zero-day discovery, exploit development and security testing.
What does the 95% figure actually measure?
It measures how often the model responds to requests involving exploit-chain development, authentication bypass, privilege escalation and other advanced cybersecurity scenarios. It is a drop in refusals, not a success rate at completing those tasks.
Which vulnerabilities has the model found?
It found two previously unknown flaws in V8, Chrome's JavaScript engine, that could be chained to corrupt memory and escape the heap sandbox. Google fixed the issue as CVE-2026-15903. OpenAI also lists flaws in an unnamed mobile operating system, database and OS kernel.
How is access to the program controlled?
Entry requires identity verification, account monitoring, approved-use restrictions and legal attestations. Hardware security keys become mandatory for individual Daybreak accounts on September 1, 2026.
AI-generated summary, reviewed by an editor. More on our AI guidelines.
Related stories



IMPLICATOR