Cyber Security

GPT-5.6-Cyber Cuts Refusals Behind Daybreak Red

OpenAI has introduced GPT-5.6-Cyber, a specialized security model designed to answer advanced, dual-use cybersecurity requests with fewer refusals. The company announced the model on August 10 as part…

August 11, 2026 5 min read

OpenAI has introduced GPT-5.6-Cyber, a specialized security model designed to answer advanced, dual-use cybersecurity requests with fewer refusals. The company announced the model on August 10 as part of an expansion of its Daybreak program.

This is not a new model option arriving in ordinary ChatGPT. GPT-5.6-Cyber is available only through Daybreak Red to approved individuals and organizations conducting authorized vulnerability research, exploit validation, penetration testing, or related security work.

The wider Daybreak update creates a clearer access ladder. Most defenders are directed toward Daybreak Blue, while the more permissive model remains behind additional approval and oversight.

Daybreak Blue and Red Serve Different Security Work

Daybreak Blue provides approved defenders with GPT-5.6 Sol for tasks such as secure code review, malware analysis, incident response, vulnerability management, and patch validation.

In this tier, OpenAI relaxes the system-level screening used in its standard deployment so legitimate defensive requests are less likely to be blocked. GPT-5.6 Sol can still refuse highly dual-use requests, particularly when they involve exploit development or activity against production systems.

Daybreak Red is intended for the narrower group of researchers whose authorized work requires those capabilities. GPT-5.6-Cyber is built on GPT-5.6 Sol but receives specialized training for vulnerability discovery, exploit-chain development, and other advanced security tasks.

OpenAI is also expanding access through its Daybreak Cyber Partner Program. Approved security vendors, consultancies, and managed-service providers can incorporate Daybreak models into governed customer engagements.

The underlying model access remains with the approved partner rather than transferring directly to its customer. A business may therefore benefit from Daybreak-assisted security work without receiving unrestricted access to GPT-5.6-Cyber.

The 95% Figure Measures Responses, Not Successful Results

The headline number attached to GPT-5.6-Cyber comes from an internal OpenAI evaluation called Advanced Cybersecurity Completion Rate.

OpenAI says the model completed 95% of advanced requests in this test, compared with 2% for GPT-5.6 Sol under Daybreak Blue and 1.5% under standard safeguards. GPT-5.5-Cyber completed 57.3%.

That represents a 93 percentage-point increase over Daybreak Blue and a 37.7-point increase over GPT-5.5-Cyber. The size of the change shows that reduced refusals are a central feature of the model, not a minor adjustment.

Completion, however, does not mean an exploit worked, a vulnerability report was correct, or the model produced a safe operational outcome. The evaluation measures whether a model responds to certain requests instead of refusing them.

For an authorized researcher, that difference can remove a genuine obstacle. A model that repeatedly stops during exploit validation or reverse engineering may be unusable even when the work is lawful. The same permissiveness also increases the consequences of a compromised account, an incorrectly defined testing scope, or an agent operating with excessive permissions.

OpenAI’s Results Describe a Specialist, Not a Universal Upgrade

OpenAI reports that GPT-5.6-Cyber outperformed GPT-5.6 Sol and GPT-5.5-Cyber on its implementation of ExploitGym, which tests whether agents can turn known vulnerabilities into working exploits in controlled environments.

The specialized model also led GPT-5.6 Sol with Daybreak Blue in an internal zero-day evaluation. That test asked models to find vulnerabilities in open-source repositories, develop proof-of-concept exploits, assess their severity, and prepare technical explanations.

The results were less consistent elsewhere. GPT-5.6-Cyber performed worse than GPT-5.6 Sol on OpenAI’s Vulnerability Discovery and Report Writing evaluation. OpenAI attributes that result to the specialized model sometimes producing shorter and less detailed reports.

GPT-5.6 Sol with Daybreak Blue also performed best in the standard 300-turn version of ExploitBench. The gap narrowed when the limit increased to 600 turns, indicating that the outcome can depend on the available reasoning budget as well as the model.

This uneven profile supports OpenAI’s recommendation that most security teams begin with Daybreak Blue. Red access is not automatically the better option for every defensive workflow. A similar workflow-first pattern appears in Microsoft’s MAI-Cyber-1-Flash system, where the surrounding orchestration and review process are as important as the specialized model.

OpenAI classifies GPT-5.6-Cyber as having High cybersecurity capability under its Preparedness Framework, but says it remains below the Critical threshold. Its status should not be confused with Astra’s unresolved Critical capability assessment. OpenAI also says GPT-5.6-Cyber was not involved in the Hugging Face security incident.

The Chrome Record Confirms a Fix, With Limits

OpenAI says it used GPT-5.6-Cyber to investigate V8, the JavaScript engine used by Chrome, and identified two previously unknown vulnerabilities that could be chained together.

One publicly documented result is CVE-2026-15903. Google’s Chrome security advisory credits “OpenAI Codex Security (amyb)” with reporting the issue. The National Vulnerability Database record describes a high-severity out-of-bounds read-and-write flaw affecting Chrome versions before 150.0.7871.128.

These records independently confirm the vulnerability, the affected version boundary, Google’s fix, and the organizational credit. They do not disclose exactly how the work was divided among GPT-5.6-Cyber, OpenAI’s researchers, automated tools, and human validation. Nor do they independently reproduce OpenAI’s broader model benchmarks.

OpenAI also reports finding vulnerabilities in a mobile operating system, a database, and an operating-system kernel. Because the affected projects and most technical records have not yet been disclosed, those claims cannot currently receive the same external verification as the Chrome vulnerability.

Access Controls Will Determine Whether Daybreak Scales Safely

Reduced refusals make account and runtime security more consequential. OpenAI says Daybreak access is governed through identity verification, account-security requirements, monitoring, approved-use restrictions, and legal attestations.

Starting September 1, individual Daybreak accounts will be required to use hardware security keys. OpenAI is also encouraging Codex users to choose auto-review mode, which evaluates actions requiring elevated permissions before they execute.

The company recommends running Daybreak workflows inside isolated environments, limiting access to production systems and the open internet, defining authorized targets, and monitoring agent actions. These controls address the type of containment and authorization problems examined in InfoSeely’s coverage of recent OpenAI cyber evaluation incidents.

Access approval alone cannot make an advanced cyber workflow safe. Organizations still need scoped credentials, technical network boundaries, audit logs, human review, and stop conditions for actions that leave the authorized environment.

Several commercial and evidentiary questions remain open. OpenAI has not published GPT-5.6-Cyber pricing, application acceptance rates, complete independent benchmark results, or its dedicated system card. The company says the system card and additional monitoring measures will arrive later.

For routine code review, vulnerability triage, threat detection, and patch validation, Daybreak Blue is the intended starting point. Daybreak Red is meant for advanced, explicitly authorized work where fewer refusals justify the additional risk and governance burden. The release expands access to powerful cyber capabilities, but it does so through a controlled gate rather than a public product rollout.