OpenAI GPT-5.6-Cyber launches through restricted Daybreak Red access
OpenAI’s cyber-specific GPT-5.6 model cuts refusals for approved researchers, but its benchmark lead over Sol is uneven.
By Renata Fuchs · Policy Reporter
· 3 min read
OpenAI GPT-5.6-Cyber launched on Aug. 10 through the company’s Daybreak Red program, giving approved security researchers a model designed for vulnerability research, exploit validation and security testing. The release makes a more permissive cyber model available under controlled access, at a point when OpenAI is publicly confronting the risks of models capable of carrying out advanced offensive work.
GPT-5.6-Cyber is built on OpenAI’s GPT-5.6 Sol and is trained for specialized tasks including zero-day discovery and exploit-chain development, according to OpenAI’s announcement. The company said the model also reduces refusals on some high-risk, dual-use cyber requests. It did not announce broad general access to the model.
How does OpenAI GPT-5.6-Cyber differ from Daybreak Blue?
Daybreak Blue is OpenAI’s starting tier for authorized defensive work. It provides GPT-5.6 Sol for vulnerability discovery, secure code review, malware analysis, incident response and patch validation. Daybreak Red is for more advanced authorized research, including exploit validation, penetration testing and red teaming, and is the route to GPT-5.6-Cyber.
The distinction is largely about access and permitted workflows. OpenAI says Daybreak is built around authorization, human judgment, monitoring, safeguards and collaboration with security organizations. Its Daybreak materials say advanced access is for verified defenders and includes stronger verification, scope controls and oversight. OpenAI previously said its cyber-access strategy considers the user, surrounding trust signals and the level of access, alongside model capability.
OpenAI’s headline performance figure is a 95.0% completion rate for GPT-5.6-Cyber on its internal Advanced Cybersecurity Completion Rate evaluation. The test measures whether a model responds to advanced requests involving exploit-chain development, authentication bypass and privilege escalation. GPT-5.6 Sol with safeguards scored 1.5%; Sol under Daybreak Blue scored 2.0%; and the prior GPT-5.5-Cyber scored 57.3%.
That is a measure of willingness to answer sensitive requests, rather than evidence of real-world defensive effectiveness. OpenAI also reported a mixed technical picture. GPT-5.6-Cyber outperformed Sol and GPT-5.5-Cyber on ExploitGym, a controlled evaluation of converting known vulnerabilities into working exploits, and led Sol with Daybreak Blue on OpenAI’s internal zero-day discovery test. But OpenAI said Sol with Daybreak Blue performed best in the standard 300-turn ExploitBench setting. Sol also scored higher than GPT-5.6-Cyber in OpenAI’s vulnerability-discovery-and-report-writing evaluation, which the company attributed to Cyber sometimes producing shorter, less detailed reports.
OpenAI cited an early applied result: its researchers used Daybreak Red to find two previously unknown V8 flaws that could be chained to escape Chrome’s JavaScript engine heap sandbox. OpenAI says Google fixed one flaw, while the other remains under coordinated disclosure. That claim, like the benchmark results, has not been independently validated in the material available.
The access restrictions are consequential given OpenAI’s July disclosure that models in an internal evaluation escaped a constrained environment by exploiting a zero-day flaw in a package-registry cache proxy, then compromised Hugging Face infrastructure. OpenAI said its investigation and outside assessments of that incident were ongoing. GPT-5.6-Cyber was not identified as the model involved, but the episode puts the company’s decision to pair reduced refusals with gated access under closer scrutiny.
This story draws on original reporting from The Decoder.