OpenAI GPT-5.6-Cyber targets vetted defenders with fewer cyber refusals
OpenAI’s GPT-5.6-Cyber reported a 95% response rate on its internal dual-use cyber test, but the figure is not an accuracy score.
By Colin Brandt · Enterprise Reporter
· 3 min read
OpenAI GPT-5.6-Cyber launched August 10 as a specialized security model for approved defenders, alongside an expansion of the company’s Daybreak access program. OpenAI says the model is designed to handle advanced vulnerability research and exploit-development work that its general models may decline, a controlled release that gives selected security teams more latitude while keeping the model outside standard ChatGPT and API access.
The model is built on GPT-5.6 Sol, OpenAI’s flagship general model released in July, and has been trained for work including zero-day vulnerability discovery and exploit-chain development, according to the company. OpenAI said the model also received training intended to reduce refusals on certain higher-risk, dual-use cyber prompts.
What does GPT-5.6-Cyber’s 95% completion rate measure?
The 95% figure is not a measure of accuracy, successful exploitation or independently verified task completion. It is OpenAI’s result on an internal measure called Advanced Cybersecurity Completion Rate, which records whether a model responds to prompts involving exploit chains, authentication bypass, privilege escalation and related advanced scenarios.
OpenAI reported a 95.0% completion rate for GPT-5.6-Cyber, compared with 57.3% for GPT-5.5-Cyber, 1.5% for GPT-5.6 Sol under its ordinary system-level safeguards, and 2.0% for Sol through Daybreak Blue. The comparison shows that the specialized model’s central change is willingness to address a defined class of sensitive requests, not a broad claim that it completes 95% of cybersecurity work correctly.
That distinction matters for security leaders assessing model claims. An evaluation is only as useful as its test cases and scoring method; teams weighing the results against their own workflows should use representative AI model evaluations, rather than treat a single benchmark as a deployment decision.
Who can access OpenAI GPT-5.6-Cyber?
GPT-5.6-Cyber is available through Daybreak Red, OpenAI’s tier for approved, authorized vulnerability research, exploit validation and security testing. Daybreak Blue is the broader route OpenAI recommends for most approved defenders. It provides frontier general-purpose models including Sol with safeguards tailored for authorized defensive work, covering uses such as secure-code review, malware analysis, incident response and patch validation.
OpenAI says its production safeguards screen cybersecurity requests to limit misuse, while acknowledging that those controls can block legitimate defensive work. Blue changes the access conditions for Sol. Red provides access to a separately trained cyber model intended for teams with a need for more sensitive research and testing capabilities.
OpenAI’s own performance disclosures also limit any simple claim that Cyber is better across the board. The company said GPT-5.6-Cyber outperformed Sol and GPT-5.5-Cyber on ExploitGym, its controlled-environment exploit-development evaluation, and exceeded Sol on an internal zero-day-focused test. Yet Sol outperformed Cyber on OpenAI’s Vulnerability Discovery and Report Writing evaluation, which OpenAI attributed to Cyber sometimes producing shorter and less detailed reports. Sol also performed best and used tokens more efficiently in ExploitBench’s standard 300-turn setting, OpenAI said.
For operators, the release is a gated product split rather than a general model upgrade: Blue addresses many defensive workflows with adjusted guardrails, while Red offers a purpose-trained model for a narrower group of authorized security teams. The reported benchmark gains remain first-party results, and OpenAI did not present them as independent validation of production security outcomes.
This story draws on original reporting from VentureBeat.