OpenAI has introduced two access tiers under its Daybreak cybersecurity program, aimed at giving approved defenders access to AI models for authorised security work.
The move comes as threat actors are increasingly expected to use AI to conduct cyberattacks at greater speed and scale. The two tiers are Daybreak Blue and Daybreak Red.
Daybreak Blue provides access to general-purpose frontier models, including GPT-5.6 Sol, with safeguards tailored to authorised defensive security work. It supports tasks such as vulnerability discovery, secure code review, malware analysis, incident response and patch validation.
Daybreak Red provides access to cybersecurity-focused models for authorised vulnerability research, exploit validation and security testing.
OpenAI has also introduced GPT-5.6-Cyber through Daybreak Red. Built on GPT-5.6 Sol, the model is trained for specialised cybersecurity tasks, including finding zero-day vulnerabilities and developing exploit chains. It is also designed to reduce refusals for certain higher-risk, dual-use cybersecurity tasks.
The company is working with Daybreak partners and the open-source community to disclose and address the vulnerabilities.
Under its Preparedness Framework, the company assessed GPT-5.6-Cyber as reaching the High threshold for cybersecurity capability but not the Critical threshold. The model improved over GPT-5.6 Sol on some specialised cybersecurity tasks but did not reach the Critical level.
Daybreak Blue and Daybreak Red are available to approved individuals and organisations conducting authorised work. Access is controlled through identity verification, account security, monitoring, approved-use restrictions and legal attestations.
The company is also requiring individual Daybreak accounts to use hardware security keys starting September 1, 2026, and said it is working on additional security measures and monitoring. It is also encouraging Daybreak customers using Codex to switch from full-access mode to auto-review mode, which reviews actions requiring elevated permissions before execution.
OpenAI recommends that organisations run security workflows in controlled environments, monitor agent actions, and clearly define the systems and actions that agents are authorized to access.
