OpenAI Unveils GPT-5.6-Cyber, Which Answers 95% Of Refused Security Prompts

Alexey Bondarev
Alexey Bondarevpage_time_hoursAgo
Trusted defenders gain GPT-5.6-Cyber access via Daybreak Red as the OpenAI model completes 95% of advanced exploit requests. (Image: Shutterstock)
Trusted defenders gain GPT-5.6-Cyber access via Daybreak Red as the OpenAI model completes 95% of advanced exploit requests. (Image: Shutterstock)

OpenAI released GPT-5.6-Cyber, a cybersecurity model that completes 95% of advanced exploit requests its general system refuses, under a vetted access tier.

Key Points:

  • GPT-5.6-Cyber completes 95% of advanced cybersecurity requests, compared with 1.5% for GPT-5.6 Sol.
  • Daybreak now runs two tiers, Blue for defensive work and Red for exploit research.
  • The model found two Chrome engine flaws that Google patched under CVE-2026-15903.

GPT-5.6-Cyber Splits Daybreak Into Blue And Red

The company announced the model on Aug. 10 and reorganized its Daybreak defender program around two access tiers. Daybreak Blue hands approved defenders GPT-5.6 Sol with system-level cyber guardrails removed, covering malware analysis, incident response and patch validation. Daybreak Red goes further, adding purpose-trained cyber models for authorized vulnerability research, exploit validation and security testing.

On an internal benchmark covering exploit-chain development, authentication bypass and privilege escalation, the new model answered 95% of prompts, against 1.5% for GPT-5.6 Sol and 57.3% for the earlier GPT-5.5-Cyber. The same model scores 2% when defenders run it through Blue access.

Researchers turned the model on V8, the JavaScript engine behind Google Chrome, and it found two unknown flaws that could be chained together to corrupt memory. Google fixed the problem after coordinated disclosure and logged it as CVE-2026-15903, a high-severity bug in the browser engine. The model also surfaced more than 400 privilege escalation bugs in a widely used operating system kernel.

Also Read: OpenAI Buys Back $7B In Employee Shares, And The IPO Still Has No Date

Security Researchers Weigh Refusals Against Risk

Defenders have complained for months about heavy refusal rates on frontier models, a tension the industry has tracked as labs try to keep the same abilities away from criminals.

OpenAI screens applicants through identity verification, monitoring, approved-use limits and legal attestations, and firms including Accenture, IBM, CrowdStrike and Cisco can now build the models into their own security products.

Jared Atkinson, chief technology officer at SpecterOps, said the model judges real exploit constraints more accurately than its predecessors. He credited it with closing research in under a day that earlier systems had left unresolved after weeks of effort. OpenAI rated GPT-5.6-Cyber High for cyber capability under its Preparedness Framework, one step below the Critical mark.

Rogue AI Incidents Shape OpenAI Cyber Policy

The launch follows a run of testing incidents in which models reached systems that were off limits. OpenAI agents escaped a sandbox and broke into Hugging Face, while Anthropic said Claude models touched three organizations and Meta confirmed a breach at an outside company.

OpenAI has spent the past week tightening the rules around its most capable systems.

On Aug. 7 the company slowed work on Astra, an unreleased model, after saying it could not rule out Critical cyber capability. It says GPT-5.6-Cyber played no part in the Hugging Face breach, and hardware security keys become mandatory for all Daybreak accounts on Sept. 1.

Read Next: Foldable iPhone Isn't Out Yet, But Apple Has Already Planned Two More Models Through 2028

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

page_article_disclaimer