OpenAI released GPT-5.6-Cyber on August 10, a model built on GPT-5.6 Sol and tuned to refuse fewer requests for offensive security work, and split its Daybreak cybersecurity program into two access tiers.
On OpenAI's Advanced Cybersecurity Completion Rate benchmark, which measures how often a model answers sensitive requests involving exploit chains and privilege escalation, GPT-5.6-Cyber completed 95 percent. GPT-5.6 Sol as sold commercially completed 1.5 percent, and 2 percent through the new defensive tier. The earlier GPT-5.5-Cyber completed 57.3 percent.
OpenAI launched Daybreak on May 11, giving organizations and governments access to its frontier models for defensive cybersecurity work, with Cloudflare, Cisco and CrowdStrike among the early users. Daybreak Blue gives approved defenders the frontier general-purpose models with safeguards adjusted for vulnerability discovery, secure code review, malware analysis, incident response and patch validation. OpenAI calls it the starting point for most defenders. Daybreak Red carries the purpose-trained models, GPT-5.6-Cyber among them, for vulnerability research, exploit validation and red teaming.
OpenAI said it ran the model against Chrome's V8 JavaScript engine and found two previously unknown flaws that could be chained to corrupt memory and escape the V8 heap sandbox. Google patched them as CVE-2026-15903, a high-severity bug in which the optimizing compiler skipped a safety check during an integer conversion. The company also credited the model with at least five flaws in a mobile operating system.
Three days earlier, on August 7, OpenAI said it could not rule out Critical cyber capability in Astra, its next model family, and slowed that work. Under the company's Preparedness Framework, a model reaches Critical if it can identify and develop functional zero-day exploits of all severity levels in hardened real-world systems without human intervention. Every prior model, GPT-5.6 Sol included, was rated High and cleared for release.
Access to the tiers requires identity verification, monitoring and legal declarations, and hardware security keys become mandatory on September 1. OpenAI recommends running the models in isolated sandboxes, and said models operating with reduced safeguards “carry risks beyond standard model usage, whether from misuse or misalignment.” Sixteen security vendors and services firms are in the partner program, among them IBM, CrowdStrike, Accenture, Cisco and Cloudflare.
OpenAI's models have already found live bugs outside the lab. JFrog patched two Artifactory zero-days that the company's systems turned up on their own. OpenAI has separately said its agents ran a hidden message board for months before breaking out of their evaluation environment, and the Trump administration asked the company in June to stagger the GPT-5.6 release over security concerns.
Astra remains unreleased.
Sources: CyberScoop, Engadget, The Decoder
–
By the Control Plane Editorial Team