⚡ Uncle Cat AI Radar
ModelsSafetyPolicy

OpenAI ships GPT-5.6-Cyber to vetted security teams

OpenAI released a purpose-trained cyber model that answers 95% of advanced security prompts its general models refuse, behind identity-verified access tiers.

OpenAI on Monday expanded its cybersecurity programme Daybreak into two access tiers and released GPT-5.6-Cyber, a model trained specifically for authorised offensive and defensive security work.

Two doors, different keys

The lower tier, Daybreak Blue, gives approved defenders frontier models including GPT-5.6 Sol with the system-level cyber guardrails relaxed — aimed at malware analysis, vulnerability triage and incident response. Daybreak Red is the narrow gate: it carries GPT-5.6-Cyber itself and is scoped to authorised vulnerability research, exploit validation and red-team simulation. Entry requires identity verification, hardened account security and legal attestations; OpenAI says hardware security keys become mandatory on 1 September 2026, and it recommends isolated sandboxes plus monitoring for higher-risk work.

The capability gap is the point. On OpenAI's internal Advanced Cybersecurity Completion Rate measure, GPT-5.6-Cyber engages with roughly 95% of sensitive security requests — exploit-chain construction, authentication bypass, privilege escalation — against about 1.5% for the guarded GPT-5.6 Sol. In one cited case the standard variants refused a WebSocket authentication bypass task the cyber model completed with working code.

Evidence offered

OpenAI says it used the model in live research, surfacing two previously unknown flaws in V8, Chrome's JavaScript engine, that could be chained to corrupt memory and break out of the heap sandbox, plus five issues in a major mobile operating system including privilege-escalation chains. The company classifies the model as "High" cyber capability under its Preparedness Framework, short of the "Critical" threshold that would trigger heavier restrictions.

Why it matters

Until now the industry's answer to dual-use cyber capability was blanket refusal. OpenAI has instead built a licensing regime: the capability exists, and eligibility is decided by vetting rather than by the model. That shifts the security question from "can a model do this" to "who holds the credential" — a template rivals and regulators will now have to respond to, and a new attack surface if the vetting leaks.

Sources