A photo taken on March 31, 2023 in Manta, near Turin, shows a computer screen with the home page of the artificial intelligence OpenAI web site, displaying its chatGPT robot. Italy’s privacy watchdog said on March it had blocked the controversial robot ChatGPT, saying the artificial intelligence app did not respect user data and could not verify users’ age. (Photo by Marco BERTORELLO / AFP) (Photo by MARCO BERTORELLO/AFP via Getty Images)
AFP via Getty Images
Three days after pausing Astra over the chance it could reach “Critical” cyber capability, OpenAI put an offense-grade hacking model on sale. The two moves look contradictory until you see what separates the caged model from the one on the market. The dividing line is a vetting form, not a capability gap.
On August 10 OpenAI expanded its Daybreak security program into two tiers and released GPT-5.6-Cyber, a model built for exploit validation, vulnerability research, and red teaming. Axios reported the launch alongside the detail that matters most: the new model reaches the “High” cyber threshold under the same Preparedness Framework that just sidelined Astra for edging toward the tier above it.
What The Two Tiers Do
Daybreak Blue is the entry point. It gives vetted defenders the standard GPT-5.6 Sol model with guardrails tuned for defensive work, meaning vulnerability detection, malware analysis, incident response, and patch validation. Daybreak Red goes further, unlocking GPT-5.6-Cyber for the offensive research that defenders use to find holes before attackers do, and it sits behind stricter checks.
The gap between the tiers is not subtle. On tasks involving exploit chains, authentication bypass, and privilege escalation, GPT-5.6-Cyber completes 95% of requests, against 1.5% for the standard safeguarded model and 2% under Daybreak Blue. The previous generation, GPT-5.5-Cyber, sat at 57.3%. In one documented test, only the new model produced working code for a WebSocket authentication bypass while every other variant refused. Both models carry the same High capability rating. The jump from 2% to 95% reflects what OpenAI unlocks for a given user, not what the underlying systems can do.
This is not a lab demo. Turned loose on real software, GPT-5.6-Cyber found two previously unknown vulnerabilities in Chrome’s V8 engine, now patched under CVE-2026-15903, plus a privilege-escalation chain in a widely used mobile operating system. The same capability that put Astra in a sandbox is, one tier down, a product with a signup flow.
The Framework Became A Business Model
OpenAI built the Preparedness Framework as a safety document, a ladder of capability thresholds that decides how much containment a model needs. This launch quietly repurposed it. The framework is now the mechanism that decides who gets which model and under what terms.
Independently identify and develop functional zero-day exploits… or devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high-level desired goal.
That is the framework’s definition of Critical, the line Astra approached and the reason it went into isolation. GPT-5.6-Cyber lands a notch below, at High, and High is precisely the capability OpenAI decided it can sell if the buyer clears the gate. The gate is real: identity verification, monitoring, legal declarations, and mandatory hardware security keys starting September 1. Capability sets the ceiling on what a model can do; vetting sets the price of admission to it. The safety tiers and the access tiers turned out to be the same ladder read from opposite ends.
That reframing kills a lazy story. The popular read on this launch is safety-versus-commerce, OpenAI loosening its own restraints to chase revenue. The mechanics say something else. The containment engineering and the commercial packaging are one system. The work of deciding what a model is allowed to do, for whom, under what monitoring, is what makes selling a High-capability cyber model possible at all.
Who Already Bought In
Daybreak predates this launch. OpenAI started it in May as a defensive initiative. By then its Trusted Access roster already read like a directory of the security industry: Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, Palo Alto Networks, and Zscaler, alongside banks from JPMorgan to Goldman Sachs. Those names are the tell. The frontier lab is not lining up to compete with the security incumbents, it is positioning to supply them.
That shapes where the spending flows. A model that finds zero-days on command is raw capability, and raw capability still needs the workflow, the deployment, and the enterprise trust that established security vendors already own.
Companies like CrowdStrike built Charlotte AI around an agent-run security operations center. Palo Alto Networks runs a research arm that keeps producing the field evidence the industry cites. They are the layer that turns a capability like this into something a corporation will actually run. The lab sells the ammunition; the incumbents own the guns and the customers.
What This Tells Investors
The security stack is reorganizing around models fighting models, and this launch names the supply chain. Frontier labs provide the capability, tiered and metered by how much containment a buyer will submit to. Security vendors turn that capability into products with the enterprise relationships to sell them. The buyers, from hyperscalers to banks, sit in the Trusted Access list already.
The signal to track is the tiering itself. OpenAI has shown it will sell a High-capability offensive model and cage a Critical one, which means the next frontier release from any lab arrives pre-sorted into what ships and what stays locked. Anthropic and Google DeepMind run comparable frameworks, and how they draw that same line will decide whether a market for contained, offense-grade AI becomes a real product category or stays one company’s experiment. What OpenAI put a price on this week was a threshold in its own safety framework.
Click Here For The Original Source.
