OpenAI has released GPT-5.6-Cyber, a model trained to answer sensitive cyber requests its consumer model refuses, to vetted defenders working on advanced security research. The company has split its Daybreak program into two access tiers. On OpenAI's internal completion test, the new model completed 95.0% of requests involving exploit-chain development, authentication bypass, privilege escalation and other advanced cybersecurity scenarios, compared with 1.5% for GPT-5.6 Sol with its safeguards on. The launch comes days after OpenAI paused some work on Astra because preliminary evaluations left it unable to rule out a Critical cyber capability level for Astra, though it said that was not a confirmed determination.

The new model's 95.0% result therefore measures a sharp drop in refusals, not success at every task.

What Changed

AI-generated summary, reviewed by an editor. More on our AI guidelines.

Two levels of access

Daybreak Blue gives defenders GPT-5.6 Sol with its system-level cyber guardrails removed. Through Daybreak Red, approved researchers can access GPT-5.6-Cyber, a model built on Sol and trained to refuse less during zero-day discovery, exploit development and security testing.

Accenture, IBM, CrowdStrike, Cisco and Palo Alto Networks may put the models into security products, managed services and customer work. Entry requires identity verification, account monitoring, approved-use restrictions and legal attestations. Hardware security keys become mandatory for individual Daybreak accounts on September 1, 2026.

The internal measurements

GPT-5.5-Cyber, released on June 22, 2026, completed 57.3% of requests on the same Advanced Cybersecurity Completion Rate evaluation. GPT-5.6 Sol under Daybreak Blue completed 2.0%.

Jared Atkinson, CTO of early-access customer SpecterOps, said the model "reasons more accurately about real exploit constraints, tracks complex state better, and has completed work in under a day that earlier models had not resolved after weeks of intermittent effort."

The completion rates and benchmark comparisons in this story are OpenAI's own measurements, not independent ones, and no outside party has verified them. No system card for GPT-5.6-Cyber has been published.

One confirmed vulnerability chain

GPT-5.6-Cyber found two previously unknown flaws in V8, Chrome's JavaScript engine, that could be chained to corrupt memory and escape its heap sandbox. Google fixed the issue and assigned CVE-2026-15903.

OpenAI also lists at least five vulnerabilities in an unnamed mobile operating system, three critical flaws in an unnamed database and more than 400 privilege-escalation vulnerabilities in an unnamed operating-system kernel. OpenAI names neither the software nor the vendors, so those claims cannot be checked from outside.

Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.

Guardrails and their limits

Before GPT-5.6 Sol's July 2026 release, the UK AI Security Institute identified "universal jailbreaks in the cyber domain, including jailbreaks that allowed for long-form agentic task completion in domains like vulnerability discovery and exploit development". The jailbreaks "were often developed within hours."

AISI had privileged access to the safety monitor's reasoning, exact policy wording and live classifier feedback. Those tools are unavailable to an ordinary attacker. Xander Davies, who leads AISI's red team, said the jailbreaks "are still findable without this access, just slower. Exactly how much slower is unclear and an open question!"

OpenAI's own tests also found limits. GPT-5.6-Cyber performed worse than Sol on an internal vulnerability-discovery and report-writing test, which OpenAI believes is due to the model sometimes producing shorter, less detailed reports. On ExploitBench's standard 300-turn setting, Sol under Daybreak Blue performed best and used fewer tokens. The gap narrowed when the test expanded to 600 turns.

GPT-5.6-Cyber reached OpenAI's High cyber threshold, not Critical. Margaret Cunningham, vice president of security and AI strategy at DarkTrace, said: "My concern is less that one model was jailbroken and more that offensive discovery is speeding up while defense still depends on very human processes: figuring out what matters, what can be patched, and what has to be contained."

Frequently Asked Questions

What is GPT-5.6-Cyber?

A model built on GPT-5.6 Sol and trained to refuse less during zero-day discovery, exploit development and security testing. It is available to approved researchers through the Daybreak Red tier. It reached OpenAI's High cyber threshold, not Critical.

What is the difference between Daybreak Blue and Daybreak Red?

Daybreak Blue gives defenders GPT-5.6 Sol with its system-level cyber guardrails removed. Through Daybreak Red, approved researchers can access GPT-5.6-Cyber for zero-day discovery, exploit development and security testing.

What does the 95% figure actually measure?

It measures how often the model responds to requests involving exploit-chain development, authentication bypass, privilege escalation and other advanced cybersecurity scenarios. It is a drop in refusals, not a success rate at completing those tasks.

Which vulnerabilities has the model found?

It found two previously unknown flaws in V8, Chrome's JavaScript engine, that could be chained to corrupt memory and escape the heap sandbox. Google fixed the issue as CVE-2026-15903. OpenAI also lists flaws in an unnamed mobile operating system, database and OS kernel.

How is access to the program controlled?

Entry requires identity verification, account monitoring, approved-use restrictions and legal attestations. Hardware security keys become mandatory for individual Daybreak accounts on September 1, 2026.

AI-generated summary, reviewed by an editor. More on our AI guidelines.

OpenAI Ships GPT-5.4-Cyber, Scales Trusted Access Program
OpenAI launched GPT-5.4-Cyber on Tuesday, a cyber-permissive model variant, and scaled its Trusted Access program to thousands of verified defenders. The rollout adds binary reverse engineering and arrives one week after Anthropic restricted Mythos Preview to roughly 40 organizations.
OpenAI Says Its Models Escaped a Sandbox, Hacked Hugging Fac
OpenAI said its own models broke containment during a cyber evaluation, reached the open internet through a zero-day, and attacked Hugging Face's production systems to steal the answer key to the benchmark they were being graded on. Hugging Face had disclosed the breach five days earlier without kno
OpenAI Builds Cybersecurity Product for Select Partners
OpenAI joins Anthropic in restricting access to AI tools with advanced hacking capabilities. Both labs concluded their newest models can exploit software vulnerabilities faster than humans can patch them, giving defenders a head start.
AI News

San Francisco

Editor-in-Chief and founder of Implicator.ai. Former ARD correspondent and senior broadcast journalist with 10+ years covering tech. Writes daily briefings on policy and market developments. Based in San Francisco. E-mail: editor@implicator.ai