Release2026-08-04

OpenAI split its Daybreak program for security professionals into two tiers and released GPT-5.6-Cyber, a model trained for vulnerability research, exploit testing and security work. The Blue tier removes the usual blocks on defensive security requests, while the Red tier adds the specialised model for higher-risk work. Access requires approval, identity checks and legal attestations, and individual accounts must use hardware security keys from September.

What changed

Security researchers hit frequent refusals, as the general model completed only 1.5% of advanced cyber requests.

What it unlocks

Approved security teams can run exploit development, zero-day hunting and red-team testing with a model that no longer refuses those requests.

  • 95.0% vs 1.5% request completion
  • 57.3% for GPT-5.5-Cyber
  • 400+ kernel privilege-escalation bugs
  • hardware keys required 1 Sep 2026

What you need to act on it

  • approval into the Daybreak program
  • identity verification and legal attestations
  • hardware security keys for individual accounts from 1 September 2026

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.