OpenAI Expands Daybreak With GPT-5.6-Cyber Access OpenAI expanded its Daybreak cybersecurity program on August 10, adding Blue and Red access tiers and releasing GPT-5.6-Cyber to approved defenders. The release followed OpenAI's August 7 disclosure that it had slowed some Astra development activities after preliminary evaluations indicated it could not rule out Critical cyber capability. GPT-5.6-Cyber remains gated to vetted partners for authorized vulnerability research and security testing. OpenAI Expands Daybreak With GPT-5.6-Cyber Access OpenAI expanded its Daybreak cybersecurity program on August 10, adding Blue and Red access tiers and releasing GPT-5.6-Cyber to approved defenders. The release followed OpenAI's August 7 disclosure that it had slowed some Astra development activities after preliminary evaluations indicated it could not rule out Critical cyber capability. GPT-5.6-Cyber remains gated to vetted partners for authorized vulnerability research and security testing. OpenAI expanded its Daybreak cybersecurity access program on August 10, introducing two access tiers and making its new GPT-5.6-Cyber model available to approved defenders. The announcement follows the company's August 7 disclosure that it had slowed some activities involving Astra, an upcoming model, after preliminary evaluations found enough progress in agentic coding and cybersecurity that OpenAI could not rule out the Critical capability threshold in its Preparedness Framework. According to OpenAI, a model meets that Critical cyber threshold if it can autonomously identify and develop functional zero-day exploits across many hardened, real-world critical systems, or devise and execute novel end-to-end attacks against hardened targets from a high-level goal. OpenAI described Astra's evaluation as preliminary and stated that the unreleased model was not involved in the reported Hugging Face incident. Two levels of Daybreak access OpenAI's Daybreak program now separates access into Daybreak Blue and Daybreak Red . Daybreak Blue gives approved defenders access to frontier general-purpose models, including GPT-5.6 Sol, with system-level cyber guardrails removed for authorized defensive work. OpenAI lists vulnerability discovery, secure code review, malware analysis, incident response, and patch validation among its intended uses. Daybreak Red provides access to purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing. Its first announced model is GPT-5.6-Cyber , built on GPT-5.6 Sol. OpenAI reported that the model was trained to improve performance on specialized tasks including zero-day discovery and exploit-chain development, while reducing refusals for certain higher-risk dual-use cyber requests. OpenAI also stated that GPT-5.6-Cyber is classified at the High cyber-capability threshold, rather than the potential Critical threshold under evaluation for Astra. That distinction matters because the Daybreak launch is a controlled deployment of a specialized model, while Astra remains an unreleased system subject to expanded internal testing and security controls. Access remains gated to approved partners BleepingComputer reported that the model is not available to regular users and identified consultancies including Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps among the approved participants. The report also listed security vendors including Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare. According to BleepingComputer, approved partners can use the models in security products, managed services, and customer engagements, with engagement boundaries, logging, monitoring, and human oversight among the safeguards described by OpenAI. The underlying models remain with approved partners rather than being transferred directly to customers, the report said. Axios reported that Daybreak members can incorporate the models into security products and services. It also reported response-rate results from OpenAI's testing: GPT-5.6-Cyber responded to 95% of advanced cybersecurity-work requests, including exploit-chain development, authentication bypass, and privilege escalation prompts. Axios reported response rates of 1.5% for GPT-5.6 Sol and 2% for the Daybreak Blue version in the same comparison. Security tooling and dual-use risk The program illustrates a recurring access-control problem for AI security tooling. General-purpose model safeguards can block legitimate defensive workflows, while relaxing them can expose capabilities relevant to offensive activity. Gated access, identity verification, defined testing scopes, logging, and expert review are controls commonly used when vendors provide high-risk security capabilities to enterprise customers. For security teams, the practical distinction is between broad defensive assistance in Blue and specialized exploit-validation work in Red. Teams evaluating such systems will need to assess authorization workflows, auditability, data-handling terms, and how model-generated findings are validated before remediation or production changes. OpenAI's Astra disclosure separately leaves an important open question: whether additional evaluations ultimately confirm or rule out the Critical threshold for that upcoming model. Key Points - 1OpenAI added gated Blue and Red Daybreak tiers, separating broad defensive model access from specialized exploit-validation and vulnerability-research capabilities. - 2GPT-5.6-Cyber is reported as High capability, while Astra's preliminary testing raised the possibility of the stricter Critical cyber threshold. - 3Comparable high-risk AI security deployments depend on authorization, scoped testing, logging, human review, and validation of model-generated vulnerability findings. Scoring Rationale The gated release of a specialized cyber model and the expansion of Daybreak are notable for security engineers evaluating AI-assisted vulnerability research and incident response. Astra's potential Critical capability classification also makes this a consequential public disclosure about frontier-model cyber risk controls, though access is limited to approved partners. Sources Primary source and supporting public references used for this report. View 4 more sources OpenAI introduces a new cyber model amid fears of AI cyberattacksaxios.com https://www.axios.com/2026/08/10/openai-gpt-astra-restrictions-safety-hacking-defenders OpenAI says it slowed Astra model development over security concernstechcrunch.com https://techcrunch.com/2026/08/07/openai-says-it-slowed-astra-model-development-over-security-concerns/ OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved usersbleepingcomputer.com https://www.bleepingcomputer.com/news/security/openai-releases-chatgpt-56-cyber-but-its-only-for-approved-users/ OpenAI expands Daybreak cybersecurity initiative as AI agent threats evolvecnbc.com https://www.cnbc.com/2026/08/10/open-ai-daybreak-cybersecurity.html Practice interview problems based on real data 1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with. Try 250 free problems /problems