OpenAI has launched GPT-5.6-Cyber, a new AI model built specifically for cybersecurity research. The model is available through OpenAI’s Daybreak Red program for approved security researchers and organizations working on authorized testing, vulnerability research, exploit validation, and red-team operations.
The launch is significant because GPT-5.6-Cyber is designed to handle some of the hardest cybersecurity tasks, including finding previously unknown vulnerabilities and building exploit chains in controlled environments.
What Is GPT-5.6-Cyber?
GPT-5.6-Cyber is a specialized version of GPT-5.6 Sol.
Unlike a normal AI model, it has been trained specifically for advanced cybersecurity work. OpenAI says it is designed to improve at tasks such as:
- Finding security flaws
- Studying large codebases
- Testing vulnerabilities
- Building exploit chains in controlled environments
- Validating security problems
- Helping researchers create fixes
- Red-team testing
The model is not being released as a general-purpose hacking tool. Access is limited to approved users through Daybreak Red, with identity checks, monitoring, usage restrictions, and legal requirements.
GPT-5.6-Cyber Is Much Less Likely to Refuse Cybersecurity Tasks
One of the biggest differences is how the model handles advanced security requests.
OpenAI created an internal test called Advanced Cybersecurity Completion Rate to measure how often its models complete difficult cybersecurity requests.
GPT-5.6-Cyber completed 95% of the tested requests.
For comparison:
- GPT-5.6-Cyber: 95.0%
- GPT-5.5-Cyber: 57.3%
- GPT-5.6 Sol + Daybreak Blue: 2.0%
- GPT-5.6 Sol: 1.5%
The test included tasks involving exploit development, authentication bypass, privilege escalation and other advanced cybersecurity scenarios.
This does not mean the model is allowed to attack real systems. OpenAI says these capabilities are provided to verified defenders working within authorized environments.
GPT-5.6-Cyber Found New Chrome V8 Vulnerabilities
Perhaps the biggest part of the announcement is the model’s work on real software.
OpenAI used GPT-5.6-Cyber to study V8, the JavaScript engine used by Google Chrome.
The model helped researchers find two previously unknown vulnerabilities that could be combined to corrupt memory and escape the V8 heap sandbox.
OpenAI’s researchers checked the findings and reported them to Google through its vulnerability disclosure process. Google fixed the issue and assigned CVE-2026-15903 to one of the vulnerabilities.
This is an important example of how AI could help security teams find serious bugs before criminals discover them.
The Model Has Found More Than Chrome Bugs
OpenAI says GPT-5.6-Cyber has also helped find security problems in several other types of software.
According to the company, the model helped identify:
- At least five vulnerabilities in a popular mobile operating system
- Three critical vulnerabilities in a popular database
- More than 400 vulnerabilities that could lead to privilege escalation in a popular operating-system kernel
OpenAI says it is working with its Daybreak partners and open-source communities to disclose and fix these problems.
Why This Matters
Finding security bugs is usually a slow process.
Security researchers may have to study millions of lines of code, understand how different parts of a system work, reproduce a problem and then prove that the issue can actually be used.
AI can speed up parts of this process.
A capable cybersecurity model can examine large amounts of code, follow complex paths and test different ideas much faster than a human researcher working alone.
That could allow security teams to find and fix vulnerabilities before attackers have a chance to use them.
OpenAI Is Building a Cybersecurity System Around the Model
GPT-5.6-Cyber is only one part of OpenAI’s larger Daybreak effort.
OpenAI has divided access into two main levels.
Daybreak Blue
Daybreak Blue provides approved defenders with frontier general-purpose models such as GPT-5.6 Sol for defensive work.
It is aimed at tasks such as:
- Security reviews
- Finding vulnerabilities
- Malware analysis
- Incident response
- Patch testing
Daybreak Red
Daybreak Red provides access to specialized cybersecurity models such as GPT-5.6-Cyber.
It is intended for higher-risk authorized work, including:
- Vulnerability research
- Exploit testing
- Penetration testing
- Red-team work
OpenAI says access is controlled through identity checks, account security, monitoring, approved-use rules and legal agreements.
The AI Cybersecurity Race Is Accelerating
The launch comes as AI systems become increasingly capable of working with code and computer systems.
This creates a major shift in cybersecurity.
AI can help attackers find weaknesses faster, but it can also help defenders find those same weaknesses first.
That creates a race:
AI-powered attacks vs. AI-powered defense
OpenAI’s strategy is clearly focused on giving trusted security teams access to advanced AI before attackers can use similar capabilities at scale.
The company says the window for defenders to prepare is becoming smaller as AI-powered attacks become faster and more automated.
GPT-5.6-Cyber Is Not Classified as a Critical Cyber Model
Despite its advanced capabilities, OpenAI says GPT-5.6-Cyber does not reach its Critical cybersecurity threshold.
Under OpenAI’s Preparedness Framework, GPT-5.6-Cyber was assessed at the High level for cybersecurity capability, but below the Critical threshold.
This distinction is important.
The model is powerful enough to find serious security problems, but OpenAI says its evaluations did not show that it had reached the level defined as a critical cyber risk.
Stronger Security Controls Are Still Required
Because GPT-5.6-Cyber has more powerful cyber capabilities, OpenAI is also adding additional controls.
The company recommends that security teams:
- Run AI agents in isolated environments
- Keep them away from sensitive production systems
- Monitor their actions
- Use human review for risky actions
- Clearly define which systems the AI can access
OpenAI is also requiring individual Daybreak accounts to use hardware security keys beginning September 1, 2026, and says additional monitoring improvements are being developed.
What This Means for Cybersecurity
GPT-5.6-Cyber shows how quickly AI is moving from simple code assistance to advanced security research.
The most interesting part isn’t simply that an AI can find a bug.
It is that AI can increasingly take on parts of the work normally performed by experienced security researchers.
That could have a major impact on the industry.
Security teams could use AI to scan more software, investigate more vulnerabilities and create fixes faster.
At the same time, companies will need stronger controls to make sure these powerful systems are used only on systems where the user has permission to test them.
The Bigger Picture
The launch of GPT-5.6-Cyber marks another important step in the AI cybersecurity race.
OpenAI is essentially giving trusted security researchers access to a model that is specifically trained to understand difficult security problems and perform advanced research.
Its work on Chrome’s V8 engine shows the potential: AI can help researchers discover vulnerabilities that might otherwise remain hidden.
But the same capabilities also explain why access is restricted.
As AI becomes better at finding weaknesses, cybersecurity may increasingly become a race between attackers using AI and defenders using even more capable AI.
For now, OpenAI’s message is clear: the goal is to put advanced cyber intelligence in the hands of people trying to find vulnerabilities, fix them and make software safer before attackers can exploit them.









