ModelsPolicy OpenAI

OpenAI's GPT-5.6-Cyber answers 95 percent of the security questions its other models refuse

Illustration for the OpenAI GPT-5.6-Cyber Daybreak story

OpenAI shipped a cybersecurity model that answers 95 percent of the questions its normal models refuse.

Two tiers, one gap

On August 10, 2026, OpenAI expanded Daybreak, its cybersecurity initiative, into two tiers. Daybreak Blue is GPT-5.6 Sol with the system-level cyber guardrails removed, and it answers roughly 2 percent of advanced security queries. Daybreak Red grants access to something else entirely: GPT-5.6-Cyber, a model trained specifically for this work, which answers 95 percent.

That gap is the whole story. The same company that spent the year explaining why its models refuse offensive security questions has now built one that mostly does not. Removing guardrails from a general model barely moves the needle, from refusal to a 2 percent answer rate. Getting to 95 percent required a model trained for the job.

OpenAI says GPT-5.6-Cyber has already been used extensively in real vulnerability research, including work that turned up previously unknown vulnerabilities in Chrome’s v8 engine.

Who gets access

Access is not open. It is limited to approved defenders, with additional controls and monitoring for higher-risk work. OpenAI’s framing is that frontier capability should reach defenders before attackers deploy offensive AI at scale.

Whether the gate holds

The open question is governance, not capability. Who decides what counts as a trusted defender, and what happens when the vetting is wrong? Approved-access programs have leaked before, and a model that answers 95 percent of attack questions is valuable to exactly the people it is being withheld from.

The defender-first argument has real force: security teams facing automated attacks arguably need tooling that matches what adversaries will eventually build for themselves. But that argument only works as long as the access boundary is real. The thing to watch is not the model’s answer rate, it is whether the approval process and the monitoring around higher-risk work hold up once the program scales beyond its first cohort.

Sources

ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.