OpenAI is expanding its cybersecurity business as AI-powered attacks become more sophisticated, launching a new GPT-5.6-Cyber model and expanding its Daybreak cyber-defence service. The move comes as AI agents are increasingly being used in offensive cyber activity, raising concerns that attackers could automate parts of hacking at greater speed and scale.
The new model is not being released broadly. OpenAI is initially making GPT-5.6-Cyber available only to a limited group of trusted cybersecurity partners, while Daybreak is being expanded into two tiers designed for different levels of defensive work.
OpenAI launches GPT-5.6-Cyber
The centrepiece of the announcement is GPT-5.6-Cyber, a cybersecurity-focused model built on GPT-5.6 Sol.
OpenAI says the model has been trained for specialised cybersecurity tasks and is designed to help defenders with activities such as security testing and vulnerability research. It is available through the higher-level Red tier of Daybreak rather than as a general-purpose model for all customers.
GPT-5.6 Sol
↓
Cybersecurity-focused training
↓
GPT-5.6-Cyber
↓
Specialised security capabilities
↓
Security testing + vulnerability research
The restricted rollout reflects the dual-use nature of powerful cybersecurity AI: the same capabilities that can help defenders find vulnerabilities can potentially be misused by attackers.
Daybreak gets two tiers: Blue and Red
OpenAI is restructuring Daybreak into two tiers:
| Daybreak tier | Main purpose | Key capabilities |
|---|---|---|
| Blue | Defensive cybersecurity | Incident response, malware analysis, patch validation |
| Red | Advanced security research | Security testing, vulnerability research, specialised cyber models |
| Red + GPT-5.6-Cyber | Advanced cyber defence | Purpose-trained AI for specialised cybersecurity work |
OpenAI describes Blue as the recommended starting point for most defenders, while Red provides more advanced and potentially more powerful tools.
DAYBREAK
│
┌─────────┴─────────┐
↓ ↓
BLUE RED
│ │
Incident response Security testing
Malware analysis Vulnerability research
Patch validation Cyber-focused models
│
↓
GPT-5.6-Cyber
Blue focuses on everyday enterprise defence
The Blue tier is aimed at organisations that need practical cybersecurity assistance rather than highly specialised offensive-security research.
Its capabilities include:
- Incident response
- Malware analysis
- Patch validation
- Defensive security workflows
This makes Blue more closely aligned with the day-to-day needs of enterprise security teams.
SECURITY INCIDENT
↓
AI-assisted analysis
↓
Identify threat
↓
Understand malware
↓
Validate patch
↓
Remediate system
The objective is to shorten the time between detecting a cyber threat and responding to it.
Red is designed for more advanced cybersecurity work
Red takes a different approach.
OpenAI says this tier provides purpose-trained cybersecurity models for security testing and vulnerability research. Because those capabilities can potentially be used for offensive purposes as well as defence, access is more restricted.
RED TIER
Security research
+
Vulnerability discovery
+
Security testing
+
Cyber-trained models
↓
Advanced defenders
This is why OpenAI is not simply making GPT-5.6-Cyber available to anyone.
GPT-5.6-Cyber initially limited to trusted partners
The new model is currently available only to trusted customer partners.
TechCrunch reports that these include organisations such as Accenture, IBM, CrowdStrike and Cloudflare, among others.
The restricted approach allows OpenAI to gather real-world feedback while maintaining greater control over how the model’s more powerful cybersecurity capabilities are used.
| Access | Availability |
|---|---|
| General public | No |
| Regular Daybreak users | No GPT-5.6-Cyber access |
| Approved Blue customers | Defensive services |
| Trusted Red partners | GPT-5.6-Cyber |
Why OpenAI is making this move now
The launch comes amid growing evidence that AI agents are becoming capable of carrying out increasingly sophisticated cyber activity.
TechCrunch points to several recent examples involving AI systems, including incidents involving Hugging Face, a gym website and AI-generated social-engineering activity.
The broader pattern is:
Traditional cyberattack
↓
Human attacker
↓
Manual tools
↓
Limited speed
AI-assisted attack
↓
AI agent
↓
Automated reasoning
↓
Automated actions
↓
Greater speed + scale
The concern is not simply that AI can write malicious code. More powerful AI agents can potentially combine information gathering, reasoning and tool use into longer attack workflows.
AI is changing the economics of cyberattacks
Traditional cyberattacks often require skilled operators to perform multiple tasks manually.
AI can potentially reduce the amount of human effort required for parts of that process.
BEFORE
Reconnaissance
↓
Human analysis
↓
Exploit research
↓
Human decision
↓
Execution
AI-ASSISTED
AI reconnaissance
↓
AI analysis
↓
AI-assisted research
↓
Automated decisions
↓
Tool execution
This could make sophisticated cyber activity more accessible and allow attackers to operate at a larger scale.
OpenAI argues that defenders therefore have a narrowing window to prepare.
The defensive race is accelerating
The cybersecurity industry is increasingly entering an AI-versus-AI race.
Attackers can use AI to improve offensive capabilities.
Defenders can use AI to detect, investigate and respond to those attacks.
AI
/ \
/ \
ATTACKS DEFENCE
↓ ↓
Automate Detect
Research Analyse
Exploit Respond
Social Patch
engineer Protect
\ /
\ /
AI CYBER
RACE
OpenAI’s Daybreak expansion is essentially a bet that AI can give defenders enough of an advantage to offset the increasing capabilities available to attackers.
OpenAI is competing with Anthropic in cybersecurity AI
OpenAI is not alone in developing specialised AI for cybersecurity.
Anthropic has already released its own cyber-focused model, Mythos, and the companies are increasingly positioning their frontier AI systems as tools for security professionals.
| Company | Cybersecurity initiative |
|---|---|
| OpenAI | Daybreak + GPT-5.6-Cyber |
| Anthropic | Mythos |
| Cybersecurity companies | AI-assisted security platforms |
| Enterprise security teams | Increasing AI adoption |
The competition is creating a new category of specialised AI models focused specifically on cybersecurity.
Why cybersecurity models need different training
General-purpose AI models can already help with coding and technical analysis.
But cybersecurity involves specialised workflows involving:
- Vulnerability research
- Threat detection
- Malware analysis
- Incident response
- Security testing
- Patch validation
- Network and system analysis
A model specifically trained for these tasks can potentially perform better than a general-purpose model.
GENERAL AI
↓
Coding
Research
Reasoning
↓
CYBER TRAINING
↓
Security-specific model
↓
Better specialised workflows
GPT-5.6-Cyber represents OpenAI’s attempt to build that specialised layer on top of its broader frontier models.
The biggest challenge is dual-use risk
The same technology can help both sides.
A cybersecurity AI could help a defender identify a vulnerability before criminals exploit it.
But the underlying capability could also potentially help an attacker understand the same vulnerability.
CYBER AI
│
┌────────┴────────┐
↓ ↓
DEFENDER ATTACKER
│ │
Find flaws Find flaws
Test systems Target systems
Analyse malware Develop attacks
Patch systems Exploit weaknesses
This is why OpenAI is keeping GPT-5.6-Cyber behind a controlled-access system rather than releasing it broadly.
OpenAI previously placed strong guardrails around frontier models
TechCrunch notes that OpenAI had previously applied significant restrictions to the use of its frontier models for cybersecurity-related activities.
The new Daybreak structure changes that approach by giving approved defenders access to more specialised capabilities while maintaining restrictions around who can use them.
EARLIER
Frontier model
↓
Strong guardrails
↓
Limited cyber use
NOW
Approved defender
↓
Daybreak Blue / Red
↓
Specialised cyber capabilities
↓
Controlled access
The strategy is essentially to loosen restrictions for trusted defenders without making the most powerful cyber capabilities freely available.
The Hugging Face incident adds urgency
The timing also comes after a series of incidents that have raised concerns about AI agents operating beyond their intended boundaries.
TechCrunch recently reported on AI systems involved in cyber-related activity, including an incident involving Hugging Face. The broader concern is that AI agents can increasingly interact with external systems rather than simply generating text.
CHATBOT
↓
Generates information
AI AGENT
↓
Reasons
↓
Uses tools
↓
Interacts with systems
↓
Can potentially execute actions
That transition from generating information to taking actions is one of the most important changes in the cybersecurity landscape.
AI agents are becoming the new attack surface
As companies deploy AI agents that can access browsers, code repositories, cloud platforms and internal systems, those agents themselves become potential targets.
Security teams therefore need to protect not only traditional software but also AI-driven workflows.
ENTERPRISE
Employees
+
Applications
+
Cloud
+
APIs
+
AI agents
↓
Expanded attack surface
This means cybersecurity teams will increasingly need to understand both traditional vulnerabilities and AI-specific risks.
AI could also make defenders much faster
The defensive benefits could be significant.
Imagine a security team receiving thousands of alerts.
A traditional workflow may require analysts to manually investigate each suspicious event.
An AI system can potentially prioritise alerts, correlate events and help analysts understand the likely cause.
THOUSANDS OF ALERTS
↓
AI triage
↓
Prioritise threats
↓
Analyse suspicious activity
↓
Human security team
↓
Faster response
The value is therefore not necessarily replacing cybersecurity professionals.
Instead, AI can potentially allow a small team to handle a much larger volume of security information.
Malware analysis is another major use case
Malware analysts often need to understand what suspicious software does, how it behaves and what systems it targets.
AI can assist with the analysis process.
Daybreak Blue specifically includes malware analysis among its capabilities.
Suspicious file
↓
AI-assisted analysis
↓
Behaviour identified
↓
Threat classified
↓
Security response
This could reduce the time required to analyse new threats.
Patch validation could become faster
Another Daybreak Blue capability is patch validation.
After a company fixes a vulnerability, security teams need to determine whether the fix actually addresses the underlying problem.
AI-assisted testing could help security teams validate patches more efficiently.
Vulnerability
↓
Patch developed
↓
AI-assisted testing
↓
Patch validated?
↙ ↘
YES NO
↓ ↓
Deploy Improve patch
This creates a feedback loop between vulnerability discovery and remediation.
Daybreak is becoming an enterprise cybersecurity platform
OpenAI’s move suggests Daybreak is evolving beyond simply offering access to a model.
The service combines:
Models + tools + workflows
for cybersecurity defenders.
DAYBREAK
│
┌──────────┼──────────┐
↓ ↓ ↓
MODELS TOOLS WORKFLOWS
│ │ │
└──────────┼──────────┘
↓
Enterprise defence
This is strategically important because enterprises often want complete security workflows rather than a standalone AI model.
OpenAI is turning cybersecurity into a business
The launch also represents a commercial opportunity.
Large enterprises spend heavily on cybersecurity, and AI companies have a potential advantage because they develop the same technologies that attackers may use.
That creates a new market:
AI MODEL
↓
Cybersecurity capability
↓
Enterprise security service
↓
Recurring business revenue
The more companies deploy AI agents, the greater the potential demand for AI-powered security products.
The irony of AI cybersecurity
There is an obvious tension in OpenAI’s strategy.
The company is helping develop increasingly capable AI systems.
Those same capabilities may contribute to more sophisticated cyberattacks.
OpenAI is therefore also selling technology intended to defend against threats that AI advancement itself could help accelerate.
AI capability improves
↓
Potential offensive capability improves
↓
Cyber risk increases
↓
Demand for AI defence increases
↓
OpenAI develops cyber defence tools
↓
AI capability improves further
This creates a feedback loop that could become increasingly important as AI agents become more autonomous.
Critics see a commercial opportunity as well
TechCrunch notes that critics have argued that the growing focus on AI-driven cyberattacks also creates a marketing opportunity for AI companies.
The companies developing frontier AI can position themselves as uniquely capable of defending against AI-powered attacks because they understand the technology behind those threats.
That argument does not necessarily mean the threats are exaggerated.
Rather, it highlights the commercial reality that:
The company building the technology can also sell the defence.
Why trusted access matters
OpenAI’s decision to restrict GPT-5.6-Cyber to trusted partners is particularly important.
It allows the company to:
- Monitor usage
- Collect feedback
- Evaluate real-world performance
- Study misuse risks
- Improve safeguards
- Limit access to powerful capabilities
LIMITED RELEASE
↓
Trusted partners
↓
Real-world testing
↓
Security monitoring
↓
Model improvement
↓
Potential wider availability
Whether OpenAI eventually expands access will depend partly on how safely the model performs in real-world environments.
What the launch means for cybersecurity professionals
Security professionals could increasingly work alongside AI systems rather than simply use conventional security software.
The future workflow may look like:
SECURITY ANALYST
+
AI CYBER AGENT
↓
Continuous monitoring
↓
Threat detection
↓
Investigation
↓
Vulnerability research
↓
Patch validation
↓
Human approval
↓
Remediation
The human remains responsible for high-impact decisions, while AI handles more of the analysis and repetitive work.
What it means for businesses
For enterprises, the emergence of AI-powered cybersecurity tools could reduce response times but also introduce new questions.
Companies will need to evaluate:
- Data privacy
- AI access controls
- Model reliability
- False positives
- False negatives
- Human oversight
- Auditability
- Agent permissions
- Third-party AI risks
The security architecture itself will increasingly need to account for AI systems.
Key numbers and facts
┌──────────────────────────────────────┐
│ OPENAI CYBER LAUNCH │
├──────────────────────────────────────┤
│ New model GPT-5.6-Cyber│
│ Built from GPT-5.6 Sol │
│ Platform Daybreak │
│ Daybreak tiers Blue + Red │
│ Blue focus Defence │
│ Red focus Advanced security│
│ Cyber model access Trusted partners│
│ Reported partners Accenture, IBM,│
│ CrowdStrike,│
│ Cloudflare │
│ Public availability No │
└──────────────────────────────────────┘
The AI cybersecurity arms race
The bigger picture can be summarised in one chain:
MORE CAPABLE AI
↓
MORE CAPABLE AI AGENTS
↓
AI-ASSISTED ATTACKS
↓
GREATER CYBER RISK
↓
AI-POWERED DEFENCE
↓
SPECIALISED CYBER MODELS
↓
FASTER DETECTION + RESPONSE
↓
CONTINUOUS AI SECURITY RACE
This is likely to become one of the most important cybersecurity trends of the next several years.
What to watch next
Wider access to GPT-5.6-Cyber
The immediate question is whether OpenAI expands access beyond trusted partners.
Performance in real-world security work
The model’s usefulness will ultimately depend on whether it can improve security outcomes rather than simply perform well in benchmarks.
AI-powered attacks
More real-world incidents involving autonomous or semi-autonomous agents would increase pressure on enterprises to adopt AI security tools.
Competition with Anthropic
Anthropic’s Mythos and other specialised cybersecurity systems could accelerate competition between AI companies.
Regulation
Governments may increasingly examine how highly capable cyber models should be distributed and controlled.
Enterprise adoption
The most important commercial test will be whether large companies are willing to integrate AI cyber agents into their existing security operations.
Conclusion
OpenAI is expanding its cybersecurity push with GPT-5.6-Cyber, a new model specifically designed for advanced cybersecurity work, while restructuring its Daybreak service into Blue and Red tiers. The announcement comes as AI agents become increasingly capable of performing activities that resemble real-world cyberattacks, increasing concerns about the speed and scale of future threats.
The Blue tier is positioned as the more accessible defensive offering, providing capabilities such as incident response, malware analysis and patch validation. Red is aimed at more advanced security professionals and includes purpose-trained cybersecurity models for security testing and vulnerability research. GPT-5.6-Cyber is currently restricted to trusted customer partners.
The timing is important. Recent incidents involving AI agents have demonstrated that the technology is moving beyond simple text generation. AI systems are increasingly able to interact with websites, tools and external environments, creating a new category of security risk.
That is changing the cybersecurity equation. Instead of attackers using AI merely to write code or research vulnerabilities, increasingly capable agents could potentially automate larger portions of cyber operations. Defenders therefore face pressure to deploy equally capable AI systems for monitoring, investigation, vulnerability research and response.
OpenAI’s approach is notable because it does not simply release another general-purpose model. It is building a controlled cybersecurity ecosystem combining models, tools and workflows. That suggests the company sees cybersecurity as a major enterprise market rather than a niche application for its AI technology.
The restricted availability of GPT-5.6-Cyber also highlights the central challenge of cybersecurity AI: dual-use capability. A system capable of finding vulnerabilities can help organisations fix them, but the same capability can potentially be misused by attackers. Keeping the model with trusted partners allows OpenAI to gather real-world experience while maintaining greater control over access.
The competitive landscape is also developing quickly. Anthropic has already introduced its cyber-focused Mythos model, meaning major AI labs are increasingly competing not only to build the most capable general AI systems but also to build specialised models for defending the digital infrastructure those systems are changing.
For businesses, the implications are significant. AI agents themselves are becoming part of the enterprise attack surface, while AI is simultaneously becoming one of the most important tools available to cybersecurity teams.
The result could be a new AI cybersecurity arms race: more capable AI enables more sophisticated attacks, which increases demand for more capable AI defence, which in turn drives further development of specialised security models.
OpenAI’s GPT-5.6-Cyber launch is therefore about more than a new model. It signals that cybersecurity is becoming one of the major battlegrounds in the next phase of enterprise AI, with the winners likely to be the companies that can deploy powerful AI while maintaining enough control to prevent that same power from becoming a security liability.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.

