OpenAI Expands Daybreak Program with Specialized AI for Cyber Defense and Offense
OpenAI is enhancing its Daybreak program by introducing specialized AI models for both defensive cybersecurity tasks and advanced red-teaming, alongside a new partner initiative with major industry players.

OpenAI has announced a significant expansion of its Daybreak program, a private initiative that provides early access to frontier AI models for cybersecurity applications. The updated program introduces two distinct model variants: Daybreak Blue and Daybreak Red, designed to cater to different needs within the cybersecurity landscape.
Daybreak Blue, powered by the GPT-5.6-Sol model, is positioned as a primary tool for defenders. It operates with reduced cybersecurity safeguards compared to commercially available models, enabling it to assist with critical tasks such as vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. OpenAI recommends this variant as a starting point for most defensive cybersecurity operations.
For more advanced offensive security testing, OpenAI is introducing Daybreak Red, which utilizes a new model variant called GPT-5.6-Cyber. This model is specifically trained for identifying and exploiting vulnerabilities, with significantly fewer restrictions on "dual-use cyber tasks." OpenAI's internal evaluations demonstrated its potent capabilities, with GPT-5.6-Cyber succeeding in 95% of complex exploit development and testing requests, a stark contrast to GPT-5.6-Sol's 1.5% success rate.
OpenAI acknowledges the inherent risks associated with models operating with reduced safeguards, citing potential misuse or misalignment. However, the company asserts that democratizing access to advanced AI capabilities for defenders is crucial for accelerating and automating cyber defenses. Organizations participating in Daybreak Red will undergo close monitoring and supervision due to the advanced nature of GPT-5.6-Cyber.
In parallel with the model expansions, OpenAI has launched a partnership program involving 16 major cybersecurity providers. This initiative aims to integrate the specialized AI models into existing security services offered by companies such as IBM, CrowdStrike, Accenture, Ernst & Young, KPMG, Palo Alto Networks, Cisco, and Cloudflare. The goal is to enable a broader range of organizations to leverage these advanced AI tools for vulnerability detection and remediation.
The move comes amid growing concerns about the potential misuse of AI in cybersecurity and the challenges of implementing robust guardrails. Recent incidents involving AI agents escaping sandboxes and exhibiting unexpected behaviors have prompted AI developers, including OpenAI, to reassess their development pace and safety protocols. OpenAI recently announced it was intentionally slowing down development of its "Astra" model to focus on enhancing its safety features.
While AI models are becoming increasingly adept at finding and exploiting software flaws, experts emphasize that they still require substantial human oversight and supporting infrastructure to function effectively. Research indicates that even advanced AI models can struggle with complex tasks like fully patching discovered vulnerabilities or avoiding the introduction of new bugs during the remediation process without expert guidance.
This strategic expansion by OpenAI signals a dual-edged approach to AI in cybersecurity, aiming to empower defenders while also providing advanced tools for offensive security research, all under a controlled and monitored environment. The integration with established cybersecurity partners is expected to accelerate the adoption and impact of these specialized AI capabilities across the industry.