Approved partners get access to a model that finds unknown vulnerabilities
On 10 August 2026 OpenAI announced that Daybreak is being expanded with two access levels, and at the same time released GPT-5.6-Cyber, a cybersecurity-specific model. The model is built on GPT-5.6 Sol and is trained for specialized tasks, among them finding zero-day vulnerabilities and developing exploit chains. It is available through Daybreak Red, and access is governed by identity verification, account security, monitoring, approved use restrictions and legal attestations. The Daybreak Cyber Partner Program has been expanded at the same time. OpenAI states that access to the underlying models remains with the approved partner, and that it is not transferred directly to the customer.
What happens technically
Daybreak now has two levels. Daybreak Blue gives access to the general frontier models, including GPT-5.6 Sol, with safeguards tuned for authorized defensive security work. OpenAI describes this as the recommended starting point for most defenders. The level removes the system-level blocks that can otherwise stop legitimate defensive work, and it supports vulnerability hunting, secure code review, malware analysis, incident response and patch validation. Daybreak Red gives access to purpose-trained cybersecurity models and is meant for authorized vulnerability research, exploit code validation and security testing. GPT-5.6-Cyber is available through Red. Through the partner program, partners can receive Blue or Red depending on the work they do. OpenAI lists Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group and SpecterOps as security and services partners, and Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet and Cloudflare as technology partners.
OpenAI has measured the gap between the models itself. GPT-5.6-Cyber is trained to refuse fewer of certain high-risk dual-use tasks, and that is precisely the difference the numbers show. The internal Advanced Cybersecurity Completion Rate counts how often a model actually answers requests about exploit chains, authentication bypass, privilege escalation and other advanced scenarios. GPT-5.6-Cyber answers 95.0 percent of them. GPT-5.6 Sol answers 1.5 percent, and 2.0 percent with Daybreak Blue. The previous generation, GPT-5.5-Cyber, sat at 57.3 percent. OpenAI gives one worked example. A request for a macOS tool that bypasses Keychain dialogs and decrypts Chrome cookies is answered by GPT-5.6-Cyber, and refused by the other three. The results do not all point the same way. On ExploitGym, which measures turning known vulnerabilities into working exploit code, GPT-5.6-Cyber performs better than both GPT-5.6 Sol and GPT-5.5-Cyber. On OpenAI's own evaluation of vulnerability discovery and report writing it performs worse than GPT-5.6 Sol, and OpenAI suggests the model sometimes writes shorter and less detailed vulnerability reports. On ExploitBench, where a V8 vulnerability has to be developed into a full exploit with several protections enabled, GPT-5.6 Sol with Daybreak Blue performs best in the standard setup of 300 turns, and the gap narrows when the setup is extended to 600 turns.
OpenAI also reports what the model has found. OpenAI ran GPT-5.6-Cyber against V8, the JavaScript engine in Chrome, and the model found two previously unknown vulnerabilities that could be chained together to corrupt memory and get out of the V8 heap sandbox. The findings were validated by OpenAI's own researchers and reported to Google through coordinated disclosure. Google fixed them and assigned CVE-2026-15903. OpenAI further reports at least five vulnerabilities in a widely used mobile operating system, including a chain from an untrusted app to local privilege escalation, three critical vulnerabilities in a widely used database, including a remote path to code execution, and more than 400 vulnerabilities that can give privilege escalation in a widely used operating system kernel. Under OpenAI's Preparedness Framework both GPT-5.6 Sol and GPT-5.6-Cyber are rated High for cyber capability, below the Critical threshold. OpenAI writes that GPT-5.6-Cyber was not involved in the exploitation of Hugging Face. Safeguards around engagements may also include defined test scopes, logging, monitoring and human oversight. Daybreak customers using Codex are strongly encouraged to move from full access to auto-review mode, and every individual account in Daybreak must adopt hardware-based security keys from 1 September 2026. A system card with further evaluations has been promised later.
What this means for you if you buy security services
The detail that matters most to you is where the access sits. OpenAI states plainly that model access remains with the approved partner, and that the partner defines the scope of each engagement, reviews the findings and applies its own expertise before anything is acted on. When you buy a test, you are not buying the model. You are buying an engagement in which the model is one of the supplier's tools. That puts the weight on the contract. Our view is that three questions belong in your next procurement. Which access level does the supplier hold? What is the test scope, written down and signed? Who at the supplier reviews the findings before they reach you? OpenAI writes that safeguards may include identity verification, defined test scopes, logging, monitoring and human oversight. "May" is not the same as "does", and that difference is yours to settle.
The numbers should shape your expectations too. OpenAI measures GPT-5.6-Cyber as better than GPT-5.6 Sol at turning known vulnerabilities into working exploit code. On OpenAI's own evaluation of vulnerability discovery and report writing, the same model comes out worse than GPT-5.6 Sol. If your supplier works in Daybreak Red, it is worth knowing that the report you end up holding is still a human product, and that the model alone does not lift it. The same numbers say something about what happens if access ends up in the wrong place. A model that answers 95.0 percent of the requests in that measurement is useful inside authorized work, and dangerous outside it. Our view is that the hardware security key requirement taking effect on 1 September 2026 is a floor you should require of every supplier that tests you, whether or not they use Daybreak. If you have an agreement already running, raise it at the next review rather than waiting for the renewal.
Berigo recommends
- Ask the supplier that performs security testing for you whether they have Daybreak access, and if so at which level.
- Put the test scope, the logging and the human review into the engagement agreement in writing before testing starts.
- Require that accounts with access to models of this kind are protected with hardware-based security keys.
- Ask to see an anonymized example report, so that you know what you are actually being delivered.
- Shorten the time from a fix being published to it being installed in your own systems.
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch