OpenAI Built a Model That Writes Exploits, and Handed It to a Short List of Companies
GPT-5.6-Cyber answers 95 percent of advanced hacking requests where the normal model answers 1.5 percent. It already found a real Chrome vulnerability and over 400 kernel bugs.
Three days after warning that its next model might reach the highest cyber risk level it has defined, OpenAI has shipped a cybersecurity model anyway, to a controlled list of partners. GPT-5.6-Cyber is available through a new tier called Daybreak Red, and it is built to do the thing every other model refuses: find unknown vulnerabilities and turn them into working exploits.
The access programme now has two levels. Daybreak Blue gives approved defenders the normal frontier model, GPT-5.6 Sol, with the usual safety filters relaxed for legitimate security work such as malware analysis, incident response and code review. Daybreak Red adds the purpose trained models. The difference is stark in OpenAI’s own numbers: on an internal test of advanced requests covering exploit chains, authentication bypass and privilege escalation, GPT-5.6-Cyber completes 95.0 percent, against 1.5 percent for the standard model and 2.0 percent through Daybreak Blue. The previous cyber model managed 57.3 percent.
This is not theoretical. OpenAI used the model on V8, the JavaScript engine inside Chrome, and found two previously unknown flaws that chain together to corrupt memory and break out of the engine’s sandbox. Researchers verified them, reported them to Google, and Google shipped a fix as CVE-2026-15903. The company also lists at least five vulnerabilities in a popular mobile operating system, three critical ones in a widely used database, and over 400 privilege escalation bugs in an operating system kernel, all still being disclosed. Under OpenAI’s own Preparedness Framework the model rates High for cyber capability, below the Critical threshold, though a full system card is still to come.
The reasoning behind this is a race, and OpenAI says so plainly: attackers will use AI for automated attacks, so defenders need the same firepower first. That argument is genuinely contested. Everything that finds a hole faster also opens it faster, and the safeguards here are procedural rather than technical: identity checks, monitoring, legal attestations, approved use restrictions, and mandatory hardware security keys for individual accounts from 1 September. OpenAI also nudges Daybreak customers using Codex away from full access mode toward auto review, which checks risky actions before they run. Early partners include SpecterOps, SentinelOne and Palo Alto Networks.
What this means for you: nothing you can use, and that is deliberate. You cannot get this model, and no consumer chatbot will help you write an exploit. The part worth noticing is second hand: if this works as advertised, the software you already run gets patched faster, because a machine is now reading kernel code for bugs at a pace no human team matches. The flip side is that the same capability leaks over time, through open weight models or through a partner with weak controls. If you look after systems at work, the practical action today is unglamorous and old: patch quickly, because the window between a bug being found and being exploited is getting shorter.
Sources
Source: https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/
OpenAI Adds a 125 Dollar Seat to ChatGPT Business, Because Agents Eat Far More Than Chat Does
Five times the capacity, no five hour limit, five times the price. The standard seat stays at 25 dollars, and the split tells you what changed about how people use these tools.