As AI-led attacks multiply, OpenAI launches a new cyber model OpenAI announced the expansion of its Daybreak cyber defense service into two tiers, Blue and Red, with Red introducing the new GPT-5.6-Cyber model for trusted customers including Accenture, IBM, Crowdstrike, and Cloudflare. The move comes as AI-led cyberattacks increase, and OpenAI positions Daybreak as a defensive tool for enterprises. Every day seems to brings fresh news https://www.washingtonpost.com/technology/2026/08/10/openai-anthropic-under-pressure-explain-ai-hacking-sprees/ of an AI agent going “rogue.” Whether that’s compromising Hugging Face https://techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action/ , hacking a gym website https://techcrunch.com/2026/08/10/tech-industry-is-buzzing-after-a-claude-agent-hacked-into-a-gym/ , or creating its own fake profiles to socially engineer an intrusion https://www.bbc.com/news/articles/c1w1lvn7d9go , AI models are increasingly behaving like bad actors. So, the AI labs that make the models doing the hacking are expanding their cyber protection offerings. This week, OpenAI announced https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/ an expansion of Daybreak, its cyber defense service which it launched earlier this year, not long after Anthropic released its cyber-focused model Mythos. Daybreak is a service that bundles access to models, tools and workflows for defenders. The expansion includes access to a brand new cyber-focused model designed for defensive work. OpenAI said Monday that Daybreak would now consist of two tiers: Blue and Red. Both of these tiers will allow approved customers access to OpenAI’s limited-access frontier cyber models https://openai.com/index/putting-frontier-cyber-models-in-more-trusted-hands/ . Frontier models — the most advanced available — have been a subject of controversy. The Trump administration previously sought to collaborate https://www.cnbc.com/2026/07/17/white-house-ai-access-anthropic-openai.html with AI companies on the roll out of such models, purportedly over safety concerns. Previously, OpenAI deployed significant guardrails https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/ to using these models, limiting what customers could do with them. Blue, which appears to be the more basic of the two, offers a variety of cyber services, including incident response, malware analysis, and patch validation. OpenAI calls Blue its “recommended starting point for most defenders,” implying that it should be more than enough for most enterprises. Red, on the other hand, offers a broader and potentially more dangerous toolkit. The company grants its users “purpose-trained cybersecurity models,” designed to carry out security testing and vulnerability research. With Red also comes the new model, GPT‑5.6‑Cyber, which is only available at that tier. 5.6-Cyber is built off of GPT‑5.6 Sol, and offers enhanced capabilities for certain specialized cybersecurity tasks, the company said. At the moment, GPT‑5.6‑Cyber is only being made available for “trusted customer partners,” including reportedly https://www.bleepingcomputer.com/news/security/openai-releases-chatgpt-56-cyber-but-its-only-for-approved-users/amp/ Accenture, IBM, Crowdstrike, Cloudflare, and others. While the threats from AI agents are rapidly increasing, critics have also pointed out that they function as marketing opportunities for the AI labs. OpenAI is certainly marketing its upgraded Daybreak that way. “The cybersecurity world is rapidly changing—threat actors will increasingly use AI to conduct cyberattacks at unprecedented speed and scale, including in fully autonomous ways,” the company said in a blog post. “As these capabilities spread, defenders have a narrowing window to prepare.” At the same time, enterprises remain interested in buying their protection from the AI labs who know the security risks best, because they know them first-hand.