OpenAI has released GPT-5.6-Cyber, a cybersecurity-specific model designed to handle advanced defensive work that general-purpose models often refuse, including exploit validation, vulnerability research, and exploit-chain development.
The model is available through Daybreak Red, a restricted access tier for vetted defenders conducting authorized security testing. In OpenAI’s internal testing, GPT-5.6-Cyber completed 95% of advanced cyber requests, far above standard GPT-5.6 Sol, while still rating High rather than Critical under the company’s Preparedness Framework. OpenAI is pairing the reduced refusal rate with identity checks, monitoring, and additional account controls.
GPT-5.6-Cyber is built to answer harder cyber requests
OpenAI said GPT-5.6-Cyber is built on GPT-5.6 Sol and trained for specialized tasks including finding zero-day vulnerabilities and developing exploit chains. Its Advanced Cybersecurity Completion Rate evaluation covered requests involving exploit-chain development, authentication bypass, privilege escalation, and similar scenarios.
GPT-5.6-Cyber completed 95% of those requests. GPT-5.6 Sol with Daybreak Blue access completed 2%, while the earlier GPT-5.5-Cyber completed 57.3%. OpenAI said the model was specifically trained to reduce refusals on higher-risk, dual-use cyber tasks that its general-purpose model may still block.
OpenAI still places GPT-5.6-Cyber below its highest cyber capability threshold.
Axios reported that the launch came days after OpenAI delayed its forthcoming Astra model after it reached Critical hacking capabilities during safety testing. GPT-5.6-Cyber, by comparison, reached the High threshold but not the Critical threshold.
How GPT-5.6-Cyber differs from Daybreak
GPT-5.6-Cyber is the model itself, while Daybreak is OpenAI’s controlled-access program for cybersecurity professionals.
Daybreak Blue grants approved defenders access to GPT-5.6 Sol, with system-level cyber guardrails removed, for authorized work such as vulnerability discovery, malware analysis, incident response, and patch validation. GPT-5.6 Sol can still refuse some highly dual-use requests even through Blue.
Daybreak Red is intended for more advanced research and gives vetted users access to purpose-trained cybersecurity models, including GPT-5.6-Cyber, for authorized vulnerability research, exploit validation, exploit development, and security testing.
Reduced safeguards bring added risk
OpenAI said GPT-5.6-Cyber helped uncover two previously unknown V8 vulnerabilities that could be chained to corrupt memory and escape the V8 heap sandbox. Google fixed one as CVE-2026-15903. According to The Hacker News, the flaw carried a CVSS score of 8.8.
The model does not outperform GPT-5.6 Sol on every security task. OpenAI found that GPT-5.6-Cyber performed worse on an open-ended vulnerability discovery and report-writing evaluation, which it attributed to the model sometimes producing shorter, less detailed reports.
“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment,” OpenAI said.
Daybreak access is controlled through identity verification, account security, monitoring, approved-use restrictions, and legal attestations. OpenAI will also require individual Daybreak accounts to use hardware security keys beginning September 1, 2026.
What security teams should consider
For security teams approved to use the program, OpenAI recommends keeping cyber workflows sandboxed and isolated from sensitive production systems, monitoring agent actions, and defining which systems and actions are authorized.
GPT-5.6-Cyber is designed to complete requests that standard frontier models may refuse, including exploit development and other highly dual-use work. The more freedom teams give the model, the more carefully they need to control where it can operate, what it can access, and which actions require human approval.
Organizations considering Daybreak Red will need to decide where the model can operate, what systems it can access, and which actions still require human approval. OpenAI recommends additional monitoring and human oversight for higher-risk workflows.
GPT-5.6-Cyber may be most useful in environments where advanced testing is already tightly scoped and supervised. Its higher completion rate could reduce friction for legitimate research while requiring security teams to put stronger operational boundaries around how the model is used.
Also read: Black Hat 2026 researchers found critical flaws in tools from Anthropic, Google, and OpenAI that could enable credential theft, RCE, and supply chain attacks.





