OpenAI just shipped an AI model that hacks like a professional, and starting September 1 you'll need a physical security key just to touch it.
On August 10, OpenAI launched GPT-5.6-Cyber through a new program called Daybreak Red, opening the model to vetted security researchers only. It's the first OpenAI model to reach "High" cybersecurity capability under the company's own Preparedness Framework, the internal scale it uses to decide when a model has become too dangerous to hand out freely. In OpenAI's internal evaluation, GPT-5.6-Cyber completed 95% of advanced exploit-chain and privilege-escalation prompts. Standard GPT-5.6 Sol managed 1.5%.
That gap is the whole story. Most of what makes GPT-5.6-Cyber different comes down to one thing: permission. Built on the same GPT-5.6 Sol base, the model has had its refusal safeguards stripped down for approved users, so it will walk through requests that would get a normal ChatGPT session shut down in seconds.
Before OpenAI ever announced the model, GPT-5.6-Cyber went looking for real vulnerabilities in real software. It found two, both in the V8 JavaScript engine that powers Google Chrome. One of them, CVE-2026-15903, carries a CVSS severity score of 8.8. The bug lived in V8's optimizing compiler, which skipped a safety check during integer conversion and let an attacker read or overwrite memory through a crafted webpage. Google has since patched it, fixing the flaw in Chrome 150.0.7871.128 after OpenAI disclosed it through normal coordinated channels.
That's not a hypothetical capability claim. It's a working exploit chain against one of the most heavily audited codebases on the internet, found by a language model before a human researcher got there. Chrome's V8 engine has an enormous bug bounty program behind it and teams of engineers who do nothing but harden it. GPT-5.6-Cyber still beat them to it.
OpenAI Launches GPT-5.6-Cyber to Arm Vetted Defenders Against Hackers OpenAI expanded its Daybreak cybersecurity program with GPT-5.6-Cyber, a model that answered 95% of advanced exploit-related security prompts in testing versus 1.5% for its standard model. Access requires identity verification, legal attestations, and mandatory hardware security keys by September 2026.
Access to the model runs through two tiers. Daybreak Blue strips guardrails off the regular GPT-5.6 Sol for defensive work: malware analysis, incident response, patch validation. Daybreak Red goes further, handing out models trained specifically for offense, exploit validation, and vulnerability research. GPT-5.6-Cyber only lives behind Red, and OpenAI is being deliberately selective about who gets that access.
Why the hardware keys #
Here's the part that tells you how seriously OpenAI is treating this. Starting September 1, every individual Daybreak account, Blue or Red, will be required to authenticate with a FIDO2 hardware security key. OpenAI has partnered with Yubico and arranged preferred pricing for accounts that need one. Miss the deadline and your access gets pulled immediately, no grace period.
A password can be phished. A session token can leak. A hardware key that has to be physically plugged in to authenticate is a much narrower door, and OpenAI clearly doesn't want this particular door left ajar. Frankly, that's the right instinct. A model that completes 95% of advanced exploit prompts is not something you want protected by the same login flow as a free ChatGPT account.
What OpenAI is really admitting here, whether it says so directly or not, is that offensive AI capability has arrived faster than most people expected. The Chrome bug is the proof. A model found a CVSS 8.8 Chrome vulnerability on its own, before launch, without a human directing every step. Security researchers have warned about exactly that for years, mostly in the abstract. Now there's a specific model, a specific CVE number, a specific patch to point to.
Enterprise security teams should take note of the access model here, not just the capability. That's the real story. OpenAI isn't pretending it can make an AI this good at hacking and simply trust everyone with it: it built a gate, then bolted a physical lock onto that gate less than a month after opening it. That tells you something about how OpenAI itself rates the risk of this thing leaking into the wrong hands. The company that built the tool doesn't fully trust its own access controls to hold without hardware in the loop. That's worth sitting with.
Also read: A Single Missing Database Rule Exposed 181,000 tl;dv Meetings • How Does AI Agent Spending Limit Escrow Work When You Hand It a Card • Applied Materials Beat Every Number and Wall Street Sold the Stock Anyway