In a keynote speech during a summit at OpenAI’s headquarters attended by 300 enterprise security leaders and CISOs from Fortune 1000 companies, OpenAI President Greg Brockman announced Daybreak for Frontline Defenders, a new global initiative to help frontline defenders use frontier cyber AI to protect essential services in the United States and around the world.
The initiative entails a $1 billion global commitment to expand subsidized access to Daybreak cyber models, training, technical support, and partnerships in the United States and internationally. Daybreak is a defensive model that involves frontier models; the Codex harness, which is an execution engine and control loop that sits between an AI model and a user’s computer; and Codex Security, an OpenAI tool used to identify, validate, and review fixes for vulnerabilities in connected code repositories, trusted workflows, and ecosystem partners.
In announcing the initiative, Brockman said he asked an off-the-shelf version of Codex to test his personal website and fix the vulnerabilities it uncovered.
“I’m not an expert in these things, but fortunately Codex is,” Brockman said. “It fixed all the issues that it found. And it was just an experience where I felt protected.”
Daybreak will also include more than 35 enterprise products and partner-operated services through the Daybreak Defense Network, bringing Daybreak cyber models into the tools, services, and workflows enterprise defenders already use.
A major part of the initiative is Daybreak for America, under which OpenAI will work to protect small water and electricity providers as well as local governments and banks. As part of that effort, OpenAI is launching a new pilot with the Multi-State Information Sharing and Analysis Center (MS-ISAC) to train and support state, local, tribal, and territorial cyber defenders, beginning with public-sector and water-system defenders.
OpenAI says the pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public sector and water system defenders, helping them validate and prioritize findings, coordinate remediation, and develop a repeatable approach that can be expanded over time.
“We might be heading to a world where critical infrastructure outages are just a way of life,” Brockman said. “We have a window to avoid that, but we have to act.”
As part of this broader push, OpenAI convened its second gathering of utility companies to help them use its tools to harden their systems. Participants represent 40 states and the District of Columbia and collectively serve more than half of the US population.
Company CEO Sam Altman was in North Carolina yesterday, where he highlighted how OpenAI is partnering with cyber defenders to protect systems and services North Carolinians rely on. Last week, OpenAI led a coalition of now more than 150 organizations across cybersecurity, technology, critical infrastructure, finance, and AI in a call for collective action to close the cyber-defense gap, warning that there is a narrowing opportunity to use AI to close security gaps before attackers seize them.
“If there is a hole, if there are these small vulnerabilities, the barrier to chain them together has just come down tremendously,” Brockman said. “The places where you used to be able to relax on your best practices — that’s just not going to cut it anymore.”
Earlier this month, following attacks on US water systems, OpenAI offered affected states and utilities up to $1 million in no-cost API credits, Daybreak access, and technical assistance. OpenAI said teams used that support to review code and system configurations, validate findings, develop patches, and confirm fixes without disrupting essential services.
Eligible state and local governments, critical infrastructure operators, nonprofits, open-source maintainers, and supporting organizations can visit the Daybreak website to learn more about access, technical assistance, training, and other cyber-defense support.
Experts credit the effort but question the bottleneck
Utility experts give the initiative high marks but say more should be done.
“I applaud the effort and initiative, but AI can’t really assess an OT architecture without a human telling it what is there,” Gus Serino, industrial control security expert and president of I&C Secure, tells CSO. “These utilities need to have hardware and software identified, purchased, installed, configured, and maintained. AI can help with some of that but will still rely on humans to actually do the implementation.”
“I know the utilities could use extra tools, but I have my concerns about over them with things they simply can’t change quickly,” Patrick Miller, president and CEO of Ampyx Cyber, tells CSO. “Finding more vulnerabilities is the easier part, and that’s already accelerated beyond what they can handle. The associated defensive efforts are a great option, but these approaches need to be tested before they can be rolled out safely in an OT environment.”