Ukraine is adding a new AI capability to its cyber defenses as Russian attacks continue putting pressure on civilian infrastructure.
OpenAI said Wednesday it will give the Ukrainian government access to its Daybreak cyber defense program, working with the Ministry of Digital Transformation to help security teams find software vulnerabilities and develop and test fixes faster.
The program is designed for authorized security work, including reviewing older software, investigating suspicious activity, validating vulnerabilities and testing patches.
The announcement came alongside the United Nations General Assembly in New York, where Dmytro Kushneruk, Ukraine's consul general in San Francisco, and Sasha Baker, OpenAI's head of national security policy, announced the partnership.
Ukraine's cyber defenders are dealing with a heavy workload. CERT-UA, the country's national cyber incident response team, handled nearly 6,000 cyber incidents in 2025, including attacks involving hospitals, energy systems and telecommunications.
"We are proud to support Ukraine’s cyber defenders, who are protecting essential services against attacks every day," Baker said.
OpenAI's growing cyber push
The Ukrainian deployment adds to European defenders' expanding use of OpenAI's cyber models.
OpenAI said the European Union Agency for Cybersecurity, or ENISA, has used its models to find vulnerabilities in software used across EU institutions, with the flaws subsequently fixed. In Poland, CERT Polska used the models to identify six vulnerabilities in third-party router software. The vendor has released fixes that CERT Polska says prevent the attacks it observed.
OpenAI has also presented Daybreak to U.S. utilities, showing that the company sees defensive cybersecurity as a potential application well beyond government agencies.
AI can strengthen defense and attack
The technology brings an important complication: the same AI capabilities that help defenders find weaknesses can help attackers discover them too.
Sophos threat intelligence director Rafe Pilling told the BBC that Russian offensive cyber operations have been "a key component" of the Kremlin's aggression against Ukraine since 2014. He described efforts to strengthen Ukraine's cyber defenses as "a welcome development."
The concern is increasingly relevant as AI becomes part of the broader Russia-Ukraine conflict. Anthropic has reported alleged use of its Claude platform in Russian drone-related development and attempts targeting Ukrainian government, military, and diplomatic organizations.
That leaves defenders with a familiar cybersecurity problem at greater speed: the same technology that improves detection can also lower the barrier to finding and exploiting weaknesses.
What this means for users
For ordinary Ukrainians, the immediate goal is less about giving people an AI tool and more about helping organizations keep essential services running. Faster vulnerability discovery and patch testing could reduce the time that hospitals, utilities and telecommunications providers remain exposed.
But AI does not remove the underlying security problem. Ukraine already uses AI tools from other technology companies, according to RUSI researcher Jamie MacColl, and organizations still need skilled defenders to validate findings and deploy fixes safely.
The bigger development is that advanced AI is becoming part of the operational cybersecurity layer protecting critical infrastructure. That could make defenders faster, but it also raises the stakes if powerful models are misused or if teams act on AI-generated findings without sufficient human review.
OpenAI's move puts AI-assisted vulnerability research closer to the front lines of a real-world cyber conflict. For Ukraine, the value will ultimately depend not simply on access to a more capable model, but on whether its defenders can turn that capability into faster detection, verified fixes and stronger protection for systems people rely on every day.
Other news: ShinyHunters claims it breached the FBI through a PeopleSoft zero-day and released 5,000 records as evidence, adding another high-profile target to the threat group's recent activity.





