Enterprise

OpenAI splits Daybreak into Blue and Red tiers, launches GPT-5.6-Cyber for exploit research

The new purpose-trained cyber model clears 95% of advanced-security requests, and OpenAI is opening the partner program to Accenture, IBM, CrowdStrike, Cisco, and Palo Alto Networks.

Photo: Unsplash / Philipp Katzenberger — Dark room with monitors displaying lines of code, illustrating cybersecurity research work

OpenAI on August 10, 2026 split its Daybreak cybersecurity program into two access tiers, Blue and Red, and introduced GPT-5.6-Cyber, a purpose-trained model available only through Red for authorized vulnerability research, exploit validation, and security testing. The restructure formalizes something the industry has been circling for two years: that offensive security work and defensive security work require different guardrails, and that the models trusted to do either need to be gated behind different doors.

The completion-rate numbers make the tiering legible. On OpenAI’s internal Advanced Cybersecurity Completion Rate evaluation, GPT-5.6 Sol clears 1.5% of advanced requests. Daybreak Blue, which wraps Sol in vulnerability-discovery, secure-code-review, malware-analysis, incident-response, and patch-validation safeguards, clears 2.0%. GPT-5.6-Cyber, gated behind Red, clears 95.0%. Red, per OpenAI, “removes refusals that persist even when Sol’s system-level guardrails are relaxed.”

Pricing tracks the capability gap. VentureBeat’s Daybreak table lists GPT-5.6-Cyber at $12.50 per million input tokens and $75 per million output tokens ($1.25 cached), against GPT-5.6 Sol at $5 and $30. Cyber is roughly 2.5x the price for the token budget most researchers actually burn.

The field results OpenAI is willing to cite are aggressive. Researchers used GPT-5.6-Cyber to investigate V8, Chrome’s JavaScript engine, uncovering two previously unknown vulnerabilities that could be chained to corrupt memory and escape the V8 heap sandbox. Google patched the issue as CVE-2026-15903. VentureBeat reports the model has also contributed to at least five vulnerabilities in an unnamed mobile OS, three critical database bugs, and more than 400 privilege-escalation flaws in an operating-system kernel.

The Daybreak Cyber Partner Program is opening to Accenture, IBM, CrowdStrike, Cisco, Palo Alto Networks, Sophos, Cloudflare, Akamai, and Fortinet, who can embed the models into their own products and managed services. Access controls tighten in parallel: all individual Daybreak accounts must adopt hardware security keys by September 1, 2026, with enhanced monitoring and a Codex auto-review mode shipping alongside.

The competitive frame is straightforward. TechCrunch notes the rollout follows Anthropic’s release of Mythos, its cyber-focused model. Axios reports GPT-5.6-Cyber reached only the “High” cyber capability threshold under OpenAI’s Preparedness Framework, a designation that governs release rather than blocks it. The frontier labs aren’t debating whether to ship offensive-capable models to enterprise defenders. They’re competing on who gates them more legibly.

Sources