Two Access Tiers for OpenAI’s Advanced Cyber Capabilities

Daybreak now separates OpenAI’s cyber capabilities into two access tiers, with GPT-5.6-Cyber reserved for advanced security research.

The Daybreak program is now structured around two access tiers for approved cybersecurity professionals. Daybreak Blue provides access to OpenAI’s most advanced general-purpose models, including GPT-5.6 Sol, with safeguards adapted for defensive work. Daybreak Red provides access to specialized models for vulnerability research, exploit validation, and advanced security testing.

GPT-5.6-Cyber is the first model tied to this second tier. Built on GPT-5.6 Sol, it was specifically trained to reduce refusals on certain dual-use tasks and strengthen capabilities related to vulnerability research, exploit chains, and complex technical investigations.

On an internal evaluation measuring the ability to respond to advanced cybersecurity requests, OpenAI reports a 95% completion rate for GPT-5.6-Cyber, compared with 57.3% for GPT-5.5-Cyber, 2% for GPT-5.6 Sol with Daybreak Blue, and 1.5% with its standard safeguards enabled. Results are more mixed across other evaluations: GPT-5.6-Cyber improves on ExploitGym and novel vulnerability discovery, while GPT-5.6 Sol retains an advantage on some tasks requiring detailed reports or a limited interaction budget.

OpenAI also says it has used the model on real-world software. Research on V8, Chrome’s JavaScript engine, led to the discovery of two vulnerabilities that could be chained together, one of which was fixed by Google under CVE-2026-15903. The company also says it is working on the disclosure and remediation of additional vulnerabilities found in mobile systems, databases, and an operating system kernel.

Access remains subject to approval. Daybreak accounts are covered by identity verification, usage restrictions, monitoring, and legal attestations. OpenAI also plans to require hardware security keys for individual accounts and recommends isolated environments as well as review mechanisms for actions requiring elevated permissions.

Under its Preparedness Framework, OpenAI rates GPT-5.6-Cyber at the “High” level for cybersecurity capabilities, below its “Critical” threshold. A more complete system card is expected to be published later.