OpenAI split its Daybreak program for security professionals into two tiers and released GPT-5.6-Cyber, a model trained for vulnerability research, exploit testing and security work. The Blue tier removes the usual blocks on defensive security requests, while the Red tier adds the specialised model for higher-risk work. Access requires approval, identity checks and legal attestations, and individual accounts must use hardware security keys from September.
What changed
Security researchers hit frequent refusals, as the general model completed only 1.5% of advanced cyber requests.
What it unlocks
Approved security teams can run exploit development, zero-day hunting and red-team testing with a model that no longer refuses those requests.
- 95.0% vs 1.5% request completion
- 57.3% for GPT-5.5-Cyber
- 400+ kernel privilege-escalation bugs
- hardware keys required 1 Sep 2026
What you need to act on it
- approval into the Daybreak program
- identity verification and legal attestations
- hardware security keys for individual accounts from 1 September 2026
- openai.com2026-08-04