Open AI3 mins read

OpenAI Expands Daybreak as AI-Led Cyberattacks Multiply

OpenAI is expanding its Daybreak cybersecurity defense program and adding GPT-5.6-Cyber, a new cyber-focused AI model for approved defensive users.

What OpenAI Announced

OpenAI is expanding Daybreak, its AI cybersecurity defense program, and rolling out a new cyber-trained AI model with it. The new model, GPT-5.6-Cyber, is described as a cyber-focused model designed for defensive work and specialized cybersecurity tasks. The move comes as AI agents are increasingly being discussed in connection with rogue or malicious behavior.

Daybreak Now Has Blue and Red Tiers

OpenAI said Daybreak will now include two tiers: Blue and Red. Both tiers give approved customers access to OpenAI’s limited-access frontier cyber models. Blue includes services such as incident response, malware analysis, and patch validation, and OpenAI calls it the recommended starting point for most defenders. Red offers a broader toolkit for security testing and vulnerability research, including purpose-trained cybersecurity models.

GPT-5.6-Cyber Is Limited to Trusted Customers

GPT-5.6-Cyber is available only through the Red tier. TechCrunch reports that the model is currently being made available to “trusted customer partners,” including reportedly Accenture, IBM, CrowdStrike, Cloudflare, and others. The restricted rollout reflects the sensitivity around frontier cyber models and the guardrails OpenAI has previously placed on their use.

Why the Timing Matters

The article frames OpenAI’s move against a backdrop of rising AI-led security incidents, including examples involving Hugging Face, a gym website, and social engineering activity. OpenAI said threat actors will increasingly use AI to conduct cyberattacks at “unprecedented speed and scale,” including fully autonomous attacks. At the same time, TechCrunch notes that critics see these threats as marketing opportunities for AI labs, even as enterprises remain interested in buying protection from the companies building the models.

Discover More

    Cybersecurity-themed illustration used for a report on AI-generated exploit scripts targeting industrial control systems
    AI speeds ICS attacks

    U.S. agencies warn AI-generated exploit scripts are raising risks for exposed Siemens S7 industrial controllers.

    CybersecurityIndustrial Control Systems
    A T-Mobile store in Times Square with bright pink T-Mobile signage.
    T-Mobile Cut Off Hackers

    T-Mobile reportedly stopped Salt Typhoon activity by physically severing a compromised system’s connection.

    CybersecurityT-Mobile