OpenAI is expanding its cybersecurity business as AI-powered attacks become more sophisticated, launching a new GPT-5.6-Cyber model and expanding its Daybreak cyber-defence service. The move comes as AI agents are increasingly being used in offensive cyber activity, raising concerns that attackers could automate parts of hacking at greater speed and scale.

The new model is not being released broadly. OpenAI is initially making GPT-5.6-Cyber available only to a limited group of trusted cybersecurity partners, while Daybreak is being expanded into two tiers designed for different levels of defensive work.

OpenAI launches GPT-5.6-Cyber

The centrepiece of the announcement is GPT-5.6-Cyber, a cybersecurity-focused model built on GPT-5.6 Sol.

OpenAI says the model has been trained for specialised cybersecurity tasks and is designed to help defenders with activities such as security testing and vulnerability research. It is available through the higher-level Red tier of Daybreak rather than as a general-purpose model for all customers.

GPT-5.6 Sol
      ↓
Cybersecurity-focused training
      ↓
GPT-5.6-Cyber
      ↓
Specialised security capabilities
      ↓
Security testing + vulnerability research

The restricted rollout reflects the dual-use nature of powerful cybersecurity AI: the same capabilities that can help defenders find vulnerabilities can potentially be misused by attackers.

Daybreak gets two tiers: Blue and Red

OpenAI is restructuring Daybreak into two tiers:

Daybreak tierMain purposeKey capabilities
BlueDefensive cybersecurityIncident response, malware analysis, patch validation
RedAdvanced security researchSecurity testing, vulnerability research, specialised cyber models
Red + GPT-5.6-CyberAdvanced cyber defencePurpose-trained AI for specialised cybersecurity work

OpenAI describes Blue as the recommended starting point for most defenders, while Red provides more advanced and potentially more powerful tools.

                 DAYBREAK
                    │
          ┌─────────┴─────────┐
          ↓                   ↓
        BLUE                 RED
          │                   │
 Incident response      Security testing
 Malware analysis       Vulnerability research
 Patch validation       Cyber-focused models
                              │
                              ↓
                       GPT-5.6-Cyber

Blue focuses on everyday enterprise defence

The Blue tier is aimed at organisations that need practical cybersecurity assistance rather than highly specialised offensive-security research.

Its capabilities include:

  • Incident response
  • Malware analysis
  • Patch validation
  • Defensive security workflows

This makes Blue more closely aligned with the day-to-day needs of enterprise security teams.

SECURITY INCIDENT
       ↓
AI-assisted analysis
       ↓
Identify threat
       ↓
Understand malware
       ↓
Validate patch
       ↓
Remediate system

The objective is to shorten the time between detecting a cyber threat and responding to it.

Red is designed for more advanced cybersecurity work

Red takes a different approach.

OpenAI says this tier provides purpose-trained cybersecurity models for security testing and vulnerability research. Because those capabilities can potentially be used for offensive purposes as well as defence, access is more restricted.

RED TIER

Security research
       +
Vulnerability discovery
       +
Security testing
       +
Cyber-trained models
       ↓
Advanced defenders

This is why OpenAI is not simply making GPT-5.6-Cyber available to anyone.

GPT-5.6-Cyber initially limited to trusted partners

The new model is currently available only to trusted customer partners.

TechCrunch reports that these include organisations such as Accenture, IBM, CrowdStrike and Cloudflare, among others.

The restricted approach allows OpenAI to gather real-world feedback while maintaining greater control over how the model’s more powerful cybersecurity capabilities are used.

AccessAvailability
General publicNo
Regular Daybreak usersNo GPT-5.6-Cyber access
Approved Blue customersDefensive services
Trusted Red partnersGPT-5.6-Cyber

Why OpenAI is making this move now

The launch comes amid growing evidence that AI agents are becoming capable of carrying out increasingly sophisticated cyber activity.

TechCrunch points to several recent examples involving AI systems, including incidents involving Hugging Face, a gym website and AI-generated social-engineering activity.

The broader pattern is:

Traditional cyberattack
        ↓
Human attacker
        ↓
Manual tools
        ↓
Limited speed

AI-assisted attack
        ↓
AI agent
        ↓
Automated reasoning
        ↓
Automated actions
        ↓
Greater speed + scale

The concern is not simply that AI can write malicious code. More powerful AI agents can potentially combine information gathering, reasoning and tool use into longer attack workflows.

AI is changing the economics of cyberattacks

Traditional cyberattacks often require skilled operators to perform multiple tasks manually.

AI can potentially reduce the amount of human effort required for parts of that process.

BEFORE

Reconnaissance
      ↓
Human analysis
      ↓
Exploit research
      ↓
Human decision
      ↓
Execution


AI-ASSISTED

AI reconnaissance
      ↓
AI analysis
      ↓
AI-assisted research
      ↓
Automated decisions
      ↓
Tool execution

This could make sophisticated cyber activity more accessible and allow attackers to operate at a larger scale.

OpenAI argues that defenders therefore have a narrowing window to prepare.

The defensive race is accelerating

The cybersecurity industry is increasingly entering an AI-versus-AI race.

Attackers can use AI to improve offensive capabilities.

Defenders can use AI to detect, investigate and respond to those attacks.

        AI
       /  \
      /    \
 ATTACKS   DEFENCE
    ↓         ↓
Automate   Detect
Research   Analyse
Exploit    Respond
Social     Patch
engineer   Protect
      \      /
       \    /
      AI CYBER
       RACE

OpenAI’s Daybreak expansion is essentially a bet that AI can give defenders enough of an advantage to offset the increasing capabilities available to attackers.

OpenAI is competing with Anthropic in cybersecurity AI

OpenAI is not alone in developing specialised AI for cybersecurity.

Anthropic has already released its own cyber-focused model, Mythos, and the companies are increasingly positioning their frontier AI systems as tools for security professionals.

CompanyCybersecurity initiative
OpenAIDaybreak + GPT-5.6-Cyber
AnthropicMythos
Cybersecurity companiesAI-assisted security platforms
Enterprise security teamsIncreasing AI adoption

The competition is creating a new category of specialised AI models focused specifically on cybersecurity.

Why cybersecurity models need different training

General-purpose AI models can already help with coding and technical analysis.

But cybersecurity involves specialised workflows involving:

  • Vulnerability research
  • Threat detection
  • Malware analysis
  • Incident response
  • Security testing
  • Patch validation
  • Network and system analysis

A model specifically trained for these tasks can potentially perform better than a general-purpose model.

GENERAL AI
     ↓
Coding
Research
Reasoning
     ↓
CYBER TRAINING
     ↓
Security-specific model
     ↓
Better specialised workflows

GPT-5.6-Cyber represents OpenAI’s attempt to build that specialised layer on top of its broader frontier models.

The biggest challenge is dual-use risk

The same technology can help both sides.

A cybersecurity AI could help a defender identify a vulnerability before criminals exploit it.

But the underlying capability could also potentially help an attacker understand the same vulnerability.

                  CYBER AI
                     │
            ┌────────┴────────┐
            ↓                 ↓
        DEFENDER            ATTACKER
            │                 │
       Find flaws          Find flaws
       Test systems        Target systems
       Analyse malware     Develop attacks
       Patch systems       Exploit weaknesses

This is why OpenAI is keeping GPT-5.6-Cyber behind a controlled-access system rather than releasing it broadly.

OpenAI previously placed strong guardrails around frontier models

TechCrunch notes that OpenAI had previously applied significant restrictions to the use of its frontier models for cybersecurity-related activities.

The new Daybreak structure changes that approach by giving approved defenders access to more specialised capabilities while maintaining restrictions around who can use them.

EARLIER

Frontier model
      ↓
Strong guardrails
      ↓
Limited cyber use


NOW

Approved defender
      ↓
Daybreak Blue / Red
      ↓
Specialised cyber capabilities
      ↓
Controlled access

The strategy is essentially to loosen restrictions for trusted defenders without making the most powerful cyber capabilities freely available.

The Hugging Face incident adds urgency

The timing also comes after a series of incidents that have raised concerns about AI agents operating beyond their intended boundaries.

TechCrunch recently reported on AI systems involved in cyber-related activity, including an incident involving Hugging Face. The broader concern is that AI agents can increasingly interact with external systems rather than simply generating text.

CHATBOT
   ↓
Generates information

AI AGENT
   ↓
Reasons
   ↓
Uses tools
   ↓
Interacts with systems
   ↓
Can potentially execute actions

That transition from generating information to taking actions is one of the most important changes in the cybersecurity landscape.

AI agents are becoming the new attack surface

As companies deploy AI agents that can access browsers, code repositories, cloud platforms and internal systems, those agents themselves become potential targets.

Security teams therefore need to protect not only traditional software but also AI-driven workflows.

ENTERPRISE

Employees
   +
Applications
   +
Cloud
   +
APIs
   +
AI agents
   ↓
Expanded attack surface

This means cybersecurity teams will increasingly need to understand both traditional vulnerabilities and AI-specific risks.

AI could also make defenders much faster

The defensive benefits could be significant.

Imagine a security team receiving thousands of alerts.

A traditional workflow may require analysts to manually investigate each suspicious event.

An AI system can potentially prioritise alerts, correlate events and help analysts understand the likely cause.

THOUSANDS OF ALERTS
        ↓
AI triage
        ↓
Prioritise threats
        ↓
Analyse suspicious activity
        ↓
Human security team
        ↓
Faster response

The value is therefore not necessarily replacing cybersecurity professionals.

Instead, AI can potentially allow a small team to handle a much larger volume of security information.

Malware analysis is another major use case

Malware analysts often need to understand what suspicious software does, how it behaves and what systems it targets.

AI can assist with the analysis process.

Daybreak Blue specifically includes malware analysis among its capabilities.

Suspicious file
      ↓
AI-assisted analysis
      ↓
Behaviour identified
      ↓
Threat classified
      ↓
Security response

This could reduce the time required to analyse new threats.

Patch validation could become faster

Another Daybreak Blue capability is patch validation.

After a company fixes a vulnerability, security teams need to determine whether the fix actually addresses the underlying problem.

AI-assisted testing could help security teams validate patches more efficiently.

Vulnerability
      ↓
Patch developed
      ↓
AI-assisted testing
      ↓
Patch validated?
   ↙          ↘
 YES           NO
 ↓             ↓
Deploy       Improve patch

This creates a feedback loop between vulnerability discovery and remediation.

Daybreak is becoming an enterprise cybersecurity platform

OpenAI’s move suggests Daybreak is evolving beyond simply offering access to a model.

The service combines:

Models + tools + workflows

for cybersecurity defenders.

             DAYBREAK
                 │
      ┌──────────┼──────────┐
      ↓          ↓          ↓
    MODELS      TOOLS     WORKFLOWS
      │          │          │
      └──────────┼──────────┘
                 ↓
        Enterprise defence

This is strategically important because enterprises often want complete security workflows rather than a standalone AI model.

OpenAI is turning cybersecurity into a business

The launch also represents a commercial opportunity.

Large enterprises spend heavily on cybersecurity, and AI companies have a potential advantage because they develop the same technologies that attackers may use.

That creates a new market:

AI MODEL
   ↓
Cybersecurity capability
   ↓
Enterprise security service
   ↓
Recurring business revenue

The more companies deploy AI agents, the greater the potential demand for AI-powered security products.

The irony of AI cybersecurity

There is an obvious tension in OpenAI’s strategy.

The company is helping develop increasingly capable AI systems.

Those same capabilities may contribute to more sophisticated cyberattacks.

OpenAI is therefore also selling technology intended to defend against threats that AI advancement itself could help accelerate.

AI capability improves
        ↓
Potential offensive capability improves
        ↓
Cyber risk increases
        ↓
Demand for AI defence increases
        ↓
OpenAI develops cyber defence tools
        ↓
AI capability improves further

This creates a feedback loop that could become increasingly important as AI agents become more autonomous.

Critics see a commercial opportunity as well

TechCrunch notes that critics have argued that the growing focus on AI-driven cyberattacks also creates a marketing opportunity for AI companies.

The companies developing frontier AI can position themselves as uniquely capable of defending against AI-powered attacks because they understand the technology behind those threats.

That argument does not necessarily mean the threats are exaggerated.

Rather, it highlights the commercial reality that:

The company building the technology can also sell the defence.

Why trusted access matters

OpenAI’s decision to restrict GPT-5.6-Cyber to trusted partners is particularly important.

It allows the company to:

  • Monitor usage
  • Collect feedback
  • Evaluate real-world performance
  • Study misuse risks
  • Improve safeguards
  • Limit access to powerful capabilities
LIMITED RELEASE
      ↓
Trusted partners
      ↓
Real-world testing
      ↓
Security monitoring
      ↓
Model improvement
      ↓
Potential wider availability

Whether OpenAI eventually expands access will depend partly on how safely the model performs in real-world environments.

What the launch means for cybersecurity professionals

Security professionals could increasingly work alongside AI systems rather than simply use conventional security software.

The future workflow may look like:

SECURITY ANALYST
       +
AI CYBER AGENT
       ↓
Continuous monitoring
       ↓
Threat detection
       ↓
Investigation
       ↓
Vulnerability research
       ↓
Patch validation
       ↓
Human approval
       ↓
Remediation

The human remains responsible for high-impact decisions, while AI handles more of the analysis and repetitive work.

What it means for businesses

For enterprises, the emergence of AI-powered cybersecurity tools could reduce response times but also introduce new questions.

Companies will need to evaluate:

  • Data privacy
  • AI access controls
  • Model reliability
  • False positives
  • False negatives
  • Human oversight
  • Auditability
  • Agent permissions
  • Third-party AI risks

The security architecture itself will increasingly need to account for AI systems.

Key numbers and facts

┌──────────────────────────────────────┐
│       OPENAI CYBER LAUNCH            │
├──────────────────────────────────────┤
│ New model                 GPT-5.6-Cyber│
│ Built from                GPT-5.6 Sol │
│ Platform                  Daybreak   │
│ Daybreak tiers            Blue + Red │
│ Blue focus                Defence    │
│ Red focus                 Advanced security│
│ Cyber model access        Trusted partners│
│ Reported partners         Accenture, IBM,│
│                           CrowdStrike,│
│                           Cloudflare │
│ Public availability       No         │
└──────────────────────────────────────┘

The AI cybersecurity arms race

The bigger picture can be summarised in one chain:

MORE CAPABLE AI
       ↓
MORE CAPABLE AI AGENTS
       ↓
AI-ASSISTED ATTACKS
       ↓
GREATER CYBER RISK
       ↓
AI-POWERED DEFENCE
       ↓
SPECIALISED CYBER MODELS
       ↓
FASTER DETECTION + RESPONSE
       ↓
CONTINUOUS AI SECURITY RACE

This is likely to become one of the most important cybersecurity trends of the next several years.

What to watch next

Wider access to GPT-5.6-Cyber

The immediate question is whether OpenAI expands access beyond trusted partners.

Performance in real-world security work

The model’s usefulness will ultimately depend on whether it can improve security outcomes rather than simply perform well in benchmarks.

AI-powered attacks

More real-world incidents involving autonomous or semi-autonomous agents would increase pressure on enterprises to adopt AI security tools.

Competition with Anthropic

Anthropic’s Mythos and other specialised cybersecurity systems could accelerate competition between AI companies.

Regulation

Governments may increasingly examine how highly capable cyber models should be distributed and controlled.

Enterprise adoption

The most important commercial test will be whether large companies are willing to integrate AI cyber agents into their existing security operations.

Conclusion

OpenAI is expanding its cybersecurity push with GPT-5.6-Cyber, a new model specifically designed for advanced cybersecurity work, while restructuring its Daybreak service into Blue and Red tiers. The announcement comes as AI agents become increasingly capable of performing activities that resemble real-world cyberattacks, increasing concerns about the speed and scale of future threats.

The Blue tier is positioned as the more accessible defensive offering, providing capabilities such as incident response, malware analysis and patch validation. Red is aimed at more advanced security professionals and includes purpose-trained cybersecurity models for security testing and vulnerability research. GPT-5.6-Cyber is currently restricted to trusted customer partners.

The timing is important. Recent incidents involving AI agents have demonstrated that the technology is moving beyond simple text generation. AI systems are increasingly able to interact with websites, tools and external environments, creating a new category of security risk.

That is changing the cybersecurity equation. Instead of attackers using AI merely to write code or research vulnerabilities, increasingly capable agents could potentially automate larger portions of cyber operations. Defenders therefore face pressure to deploy equally capable AI systems for monitoring, investigation, vulnerability research and response.

OpenAI’s approach is notable because it does not simply release another general-purpose model. It is building a controlled cybersecurity ecosystem combining models, tools and workflows. That suggests the company sees cybersecurity as a major enterprise market rather than a niche application for its AI technology.

The restricted availability of GPT-5.6-Cyber also highlights the central challenge of cybersecurity AI: dual-use capability. A system capable of finding vulnerabilities can help organisations fix them, but the same capability can potentially be misused by attackers. Keeping the model with trusted partners allows OpenAI to gather real-world experience while maintaining greater control over access.

The competitive landscape is also developing quickly. Anthropic has already introduced its cyber-focused Mythos model, meaning major AI labs are increasingly competing not only to build the most capable general AI systems but also to build specialised models for defending the digital infrastructure those systems are changing.

For businesses, the implications are significant. AI agents themselves are becoming part of the enterprise attack surface, while AI is simultaneously becoming one of the most important tools available to cybersecurity teams.

The result could be a new AI cybersecurity arms race: more capable AI enables more sophisticated attacks, which increases demand for more capable AI defence, which in turn drives further development of specialised security models.

OpenAI’s GPT-5.6-Cyber launch is therefore about more than a new model. It signals that cybersecurity is becoming one of the major battlegrounds in the next phase of enterprise AI, with the winners likely to be the companies that can deploy powerful AI while maintaining enough control to prevent that same power from becoming a security liability.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.