OpenAI Daybreak cybersecurity program adds Blue, Red and GPT-5.6-Cyber
OpenAI added two Daybreak access tiers for vetted defenders, separating routine security work from advanced vulnerability research.
By Wei-Lin Zhao · AI Correspondent
· 3 min read
OpenAI expanded its Daybreak cybersecurity program on Aug. 10 with two access tiers, Daybreak Blue and Daybreak Red, and a specialized GPT-5.6-Cyber model available through Red. The release puts increasingly permissive cyber capabilities behind approved-defender access, reflecting the company’s effort to offer advanced research tools while keeping authorization and monitoring in place.
Daybreak Blue is the recommended starting point for most defenders, OpenAI said. It provides GPT-5.6 Sol for vulnerability discovery, secure code review, malware analysis, incident response and patch validation. Red is aimed at authorized vulnerability research, exploit validation and security testing, with GPT-5.6-Cyber built on GPT-5.6 Sol.
What is the difference between Daybreak Blue and Daybreak Red?
Blue is intended for standard defensive workflows. OpenAI says it removes system-level cyber guardrails that can prevent legitimate security work, but retains refusals for some highly dual-use requests, including certain work involving production systems.
Red offers a purpose-trained model for more advanced work. OpenAI says GPT-5.6-Cyber was trained to improve performance on tasks including zero-day discovery and exploit-chain development, while reducing refusals for selected higher-risk requests. Access is not described as public or unrestricted: OpenAI says advanced Daybreak access is for verified defenders and uses verification, scope controls, human judgment, monitoring and oversight.
For security leaders, the tier design positions model selection around workflow: Blue for investigation and remediation work, Red for advanced testing that requires tighter authorization. That distinction matters because lowering refusal rates makes the model more useful for legitimate researchers while also increasing the need to verify who is using it and under what scope. Those controls are part of the broader enterprise security program, rather than a substitute for one.
How does GPT-5.6-Cyber compare with GPT-5.6 Sol?
OpenAI’s own internal Advanced Cybersecurity Completion Rate test found GPT-5.6-Cyber completed 95.0% of evaluated advanced requests, compared with 1.5% for GPT-5.6 Sol with safeguards enabled and 2.0% for GPT-5.6 Sol through Daybreak Blue. The company said its evaluation covers scenarios including exploit-chain development, authentication bypass and privilege escalation. These are vendor-created results, not independent validation.
The results are not uniformly in favor of the specialized model. OpenAI said GPT-5.6-Cyber exceeded GPT-5.6 Sol on ExploitGym2 and its internal zero-day discovery evaluation. Yet GPT-5.6 Sol in Blue scored higher on OpenAI’s Vulnerability Discovery and Report Writing evaluation; the company attributed GPT-5.6-Cyber’s lower result to shorter, less detailed reports. In OpenAI’s ExploitBench3 test at a 300-turn limit, Blue also performed best and used tokens more efficiently, according to the company.
The expansion follows a June Daybreak update that included an updated Codex Security plugin, a limited release of GPT-5.5-Cyber, a partner program and Patch the Planet, OpenAI’s initiative with Trail of Bits and other participants to help open-source projects move from vulnerability findings to tested fixes. OpenAI has argued that the operational bottleneck is increasingly patching and validating findings, rather than identifying them.
This story draws on original reporting from SiliconANGLE.