OpenAI extends Daybreak, its cyber program, from detection to remediation
OpenAI expands its Daybreak cyber program with Codex Security and GPT-5.5-Cyber to accelerate vulnerability remediation for verified security defenders.
OpenAI is expanding Daybreak, its cybersecurity program, to help defenders move from vulnerability discovery to high-speed remediation. Several components accompany this expansion: an update to Codex Security, the full version of GPT-5.5-Cyber, a partner program, and the open-source initiative Patch the Planet, conducted with Trail of Bits and handled separately.
OpenAI's framing: AI has shifted the security bottleneck; finding vulnerabilities is no longer the bottleneck, fixing them has become it. Codex Security, its code review tool, gains turnkey defensive workflows, from scanning to generating a patch for review, including severity reports, attack path tracing, and threat modeling. The company states that in a few months, the tool has scanned tens of millions of commits across tens of thousands of codebases, with hundreds of thousands of findings having been marked as remediated, and humans retaining the choice of what they investigate and apply.
The second pillar is GPT-5.5-Cyber, which OpenAI describes as its most capable model for finding and helping to remediate vulnerabilities, and more permissive for authorized cyber work. Its distribution remains limited to verified defenders, accompanied by verification, monitoring, and restricted controls; OpenAI attributes a new record to it on the CyberGym benchmark, at 85.6% compared to 81.8% for GPT-5.5. Finally, a partner program opens access, via their own products, to major security players, with direct access to the model remaining on their side. The company also states it is forging agreements for supervised access with several states, including France, Germany, Japan, and Korea, and is in dialogue with the US government.