TL;DR
OpenAI split its Daybreak security programme into two access tiers on Monday and released GPT-5.6-Cyber behind the more permissive one. On the company’s own internal measure, the new model responds to 95% of advanced exploit-development requests where the general-purpose version responds to 1.5%. Reaching it requires identity verification, legal attestations and, from 1 September, a hardware security key.
Two tiers, two thresholds
Daybreak Blue carries the general frontier models with the production content filters lifted for authorised defensive work — malware analysis, patch validation, incident response. Daybreak Red carries the purpose-trained models and is pitched at penetration testing and exploit validation.
The gap between them is the whole point. OpenAI’s Advanced Cybersecurity Completion Rate measures how often a model will engage with requests covering exploit chains, authentication bypass and privilege escalation. GPT-5.6 Sol scores 1.5% in production and 2.0% even with Blue access. GPT-5.6-Cyber scores 95%. Last year’s GPT-5.5-Cyber managed 57.3%.
That is not a capability jump so much as a policy one. The same underlying model refuses or complies depending on who is asking, and OpenAI now decides who qualifies.
Evidence it works
Since training finished, the model has been turned on real codebases. It found two previously unknown flaws in V8, Chrome’s JavaScript engine, which chain together to corrupt memory and break out of the heap sandbox. Google patched them as CVE-2026-15903. OpenAI also reports five vulnerabilities in an unnamed mobile operating system, three critical issues in a database, and more than 400 privilege-escalation paths in an operating system kernel.
Under its Preparedness Framework, OpenAI rates the model High for cyber capability but below Critical — the same assessment it gave GPT-5.6 Sol.
Looking forward
A separate announcement the same day named the delivery channel: consultancies and vendors including Accenture, IBM, PwC and Manchester-headquartered NCC Group, who reach customers directly. Crucially, model access stays with the partner and is never handed to the client.
For UK readers this lands days after OpenAI paused work on Astra over critical cyber risk, and while AISI publishes incident reports that Washington answers with letters. Capability control has moved from testing what a model can do to deciding who may use it — a decision currently sitting with the lab, not a regulator.