OpenAI launches GPT-5.6-Cyber for security researchers
Through its Daybreak program, OpenAI opens an offensive-security model to vetted professionals – one that has already found Chrome zero-days.

Illustration · AI-generated (AI IN LIFE)
At a glance
- GPT-5.6-Cyber completes 95% of sensitive security requests vs. 1.5% for GPT-5.6 Sol
- Two tiers: Daybreak Blue (defensive) and Daybreak Red (vulnerability research)
- Finding: two chained Chrome V8 zero-days, including CVE-2026-15903
- Over 400 privilege-escalation findings in kernel code
- Hardware security keys mandatory from September 1, 2026
OpenAI is expanding its Daybreak security program, giving vetted cybersecurity professionals access to a specialized model: GPT-5.6-Cyber. While the standard GPT-5.6 Sol refuses almost all sensitive security requests – completing just 1.5 percent, per OpenAI – the Cyber variant completes 95 percent of them.
The program has two tiers: “Daybreak Blue” provides access to general models with adjusted safeguards for defensive work, while “Daybreak Red” targets advanced vulnerability research and exploit validation. Access requires identity verification; from September 1, hardware security keys become mandatory, alongside sandbox isolation and continuous monitoring.
OpenAI’s published findings show what the model can do: in Chrome’s V8 engine, GPT-5.6-Cyber uncovered two chained zero-day vulnerabilities, including the flaw tracked as CVE-2026-15903, plus critical flaws in mobile operating systems and databases, and over 400 privilege-escalation findings in kernel code.
OpenAI frames the move around a narrowing window for defenders: if AI systems can find vulnerabilities ever faster, authorized defenders should wield that capability first – before attackers do. Critics will still ask how robust the access and abuse controls prove in practice.
FAQ
What is GPT-5.6-Cyber?
A specialized OpenAI model for authorized security researchers that handles sensitive security tasks standard models refuse.
Who gets access?
Only vetted professionals via the Daybreak program – with identity verification and, from September, mandatory hardware security keys.
What has the model already found?
Among other things, two chained zero-days in Chrome’s V8 engine, including CVE-2026-15903, plus critical flaws in mobile operating systems and databases.


