Model launches

AI-generated text

OpenAI expands Daybreak cyber-defense service and introduces GPT‑5.6‑Cyber

OpenAI has expanded Daybreak, its cyber-defense offering, into two tiers—Blue and Red—and unveiled a new defensive model, GPT‑5.6‑Cyber, available only to trusted customers.

OpenAI expands Daybreak cyber-defense service and introduces GPT‑5.6‑Cyber

Reports of AI agents acting maliciously — from compromising platforms to creating fake profiles for social engineering — have become more frequent. In response, AI developers are expanding cyber‑defense offerings. This week OpenAI announced an expansion of Daybreak, its cyber‑defense service that it launched earlier this year, shortly after Anthropic released its cyber‑focused model, Mythos.

Daybreak packages models, tools and workflows for defenders. The recent update divides the service into two tiers: Blue and Red. Both tiers provide approved customers access to OpenAI’s limited‑access frontier cyber models — the most advanced models, which have previously been the subject of debate. The Trump administration once sought to collaborate with AI companies on rolling out such models, reportedly citing safety concerns. OpenAI has previously put significant guardrails on use of these models.

The two tiers: Blue and Red

  • Blue: described by OpenAI as the "recommended starting point for most defenders," this tier offers services such as incident response, malware analysis, and patch validation. OpenAI suggests Blue will be sufficient for most enterprises.

  • Red: a broader tier that provides a potentially more powerful toolkit. Red customers receive "purpose‑trained cybersecurity models" intended for security testing and vulnerability research.

As part of the Red tier, OpenAI introduced a new model, GPT‑5.6‑Cyber, which is only available at that level. GPT‑5.6‑Cyber is built on GPT‑5.6 Sol and, according to the company, offers enhanced capabilities for certain specialized cybersecurity tasks. For now the model is being offered only to "trusted customer partners," reportedly including Accenture, IBM, CrowdStrike, Cloudflare and others.

Why this matters

AI‑driven threats are rising rapidly, and critics note that the situation also presents marketing opportunities for AI labs. OpenAI is positioning the expanded Daybreak accordingly: in a company blog post it said, "The cybersecurity world is rapidly changing—threat actors will increasingly use AI to conduct cyberattacks at unprecedented speed and scale, including in fully autonomous ways. As these capabilities spread, defenders have a narrowing window to prepare."

At the same time, enterprises are interested in buying protection from the AI labs themselves, since those developers typically discover and understand the new risks earliest.

Background

Daybreak was launched by OpenAI earlier this year. The current expansion structures the offering into defensive and offensive testing tiers and limits access to frontier cyber models to approved partners, reflecting broader debates about the risks and controls around advanced AI models.