All coverage
Milestone note Aug 10, 2026

OpenAI ships an offensive-capable cyber model — gated behind a new 'Daybreak Red' tier

OpenAI expanded Daybreak into two tiers: Blue, which relaxes guardrails for defensive work like incident response and vulnerability management, and Red, which grants access to purpose-trained models — including the new GPT-5.6-Cyber — for authorized vulnerability research and exploit development. GPT-5.6-Cyber completes 95.0% of those requests versus 1.5% for the base model. Both are now on Amazon Bedrock for eligible customers.

OpenAI expanded its Daybreak cybersecurity programme into two access tiers. Daybreak Blue relaxes standard guardrails so defenders can use the models on real security work — incident detection and response, investigations, vulnerability management, security assessments. Daybreak Red goes further, granting vetted users purpose-trained cybersecurity models for authorized vulnerability research, exploit validation and security testing, including a new model, GPT-5.6-Cyber, built on GPT-5.6 Sol and available only at that tier. OpenAI reports GPT-5.6-Cyber completes 95.0% of specialized cyber requests, against 1.5% for GPT-5.6 Sol and 2.0% with Blue access. The company framed the release around a narrowing window for defenders as AI-driven attacks multiply. AWS made both models available to eligible customers on Amazon Bedrock the following day.

Why it matters

Read the two announcements together and the shape of OpenAI's position becomes clear: three days after pausing internal work on Astra because it could not rule out "critical" cyber capability, it shipped a model trained to find zero-days and build exploit chains — to approved customers, through a cloud marketplace. That is not a contradiction so much as a policy: the capability is treated as too dangerous to run loose internally and too valuable to withhold from defenders, so it moves behind access control instead of behind a delay. The 95.0% versus 1.5% gap is the number that matters, because it quantifies exactly how much capability the guardrails were holding back — and therefore what the Red tier hands over. Everything now rests on vetting, and gated distribution has a well-documented failure mode: eligibility lists leak, and Bedrock widens the surface by design.

What to watch

What the eligibility criteria for Red actually are and who publishes them, whether misuse of Red-tier access is reported, and whether rival labs match the tiering or stay with blanket refusals.

Who's involved