Open AI3 mins read

OpenAI Expands Daybreak as AI-Led Cyberattacks Multiply

OpenAI is expanding its Daybreak cybersecurity defense program and adding GPT-5.6-Cyber, a new cyber-focused AI model for approved defensive users.

What OpenAI Announced

OpenAI is expanding Daybreak, its AI cybersecurity defense program, and rolling out a new cyber-trained AI model with it. The new model, GPT-5.6-Cyber, is described as a cyber-focused model designed for defensive work and specialized cybersecurity tasks. The move comes as AI agents are increasingly being discussed in connection with rogue or malicious behavior.

Daybreak Now Has Blue and Red Tiers

OpenAI said Daybreak will now include two tiers: Blue and Red. Both tiers give approved customers access to OpenAI’s limited-access frontier cyber models. Blue includes services such as incident response, malware analysis, and patch validation, and OpenAI calls it the recommended starting point for most defenders. Red offers a broader toolkit for security testing and vulnerability research, including purpose-trained cybersecurity models.

GPT-5.6-Cyber Is Limited to Trusted Customers

GPT-5.6-Cyber is available only through the Red tier. TechCrunch reports that the model is currently being made available to “trusted customer partners,” including reportedly Accenture, IBM, CrowdStrike, Cloudflare, and others. The restricted rollout reflects the sensitivity around frontier cyber models and the guardrails OpenAI has previously placed on their use.

Why the Timing Matters

The article frames OpenAI’s move against a backdrop of rising AI-led security incidents, including examples involving Hugging Face, a gym website, and social engineering activity. OpenAI said threat actors will increasingly use AI to conduct cyberattacks at “unprecedented speed and scale,” including fully autonomous attacks. At the same time, TechCrunch notes that critics see these threats as marketing opportunities for AI labs, even as enterprises remain interested in buying protection from the companies building the models.

Discover More

    Illustration for The Decoder article about OpenAI agents and RubyGems cybersecurity incident
    OpenAI Agents and RubyGems

    A reported AI-agent campaign hit RubyGems with malicious packages, public-data scraping, and attempted API key theft.

    OpenAICybersecurity
    METR's president, Chris Painter, and CEO, Beth Barnes.
    METR’s AI Safety Moment

    Why the AI safety lab METR is becoming a key outside evaluator for OpenAI, Anthropic, Google, and Meta.

    AI SafetyOpenAI
    OpenAI's new Agents API gives developers the infrastructure behind Codex and ChatGPT
    OpenAI Agents API Beta

    Developers can now build long-running cloud agents using OpenAI’s public beta Agents API.

    OpenAIAI Agents