- GPT-5.6-Cyber is a version of GPT-5.6 Sol trained to be far more permissive on cybersecurity work. Announced on August 10, 2026.
- It is not publicly available. Only verified security firms and researchers in the Daybreak Red tier can use it.
- In testing it answered 95% of advanced cyber requests. Standard GPT-5.6 Sol answered just 1.5%.
- It sits at the High capability level under OpenAI’s Preparedness Framework. The delayed Astra model is the one at the Critical threshold.
OpenAI has announced a noticeably less restricted model for cyber defenders: GPT-5.6-Cyber. It is a variant of GPT-5.6 Sol tuned for cybersecurity workflows, and it is closed to ordinary ChatGPT users.
The timing is not accidental. Three days earlier the company said it could no longer rule out critical hacking capabilities in its upcoming model Astra and delayed the release. So OpenAI is pumping the brakes on its most dangerous model while simultaneously arming defenders.
What Is GPT-5.6-Cyber?
GPT-5.6-Cyber is not a new architecture. It is a derivative of GPT-5.6 Sol with relaxed refusal boundaries for legitimate security work and expanded offensive-simulation capability.
The problem it solves is familiar to anyone doing vulnerability research: frontier models kept treating security professionals like malicious attackers. A pentest team probing privilege escalation on their own client’s system would hit “I can’t help with that” over and over. GPT-5.6-Cyber removes exactly that friction.
Supported work includes exploit-chain development, authentication bypass, privilege escalation, and validating whether real vulnerabilities are actually exploitable.
Response Rates: 95% vs 1.5%
The most striking number is how often each model engages with advanced cybersecurity requests. From OpenAI’s own testing:
| Model / Access | Response rate on advanced cyber requests |
|---|---|
| GPT-5.6-Cyber (Daybreak Red) | 95% |
| GPT-5.6 Sol, Daybreak Blue build | 2% |
| GPT-5.6 Sol (standard) | 1.5% |
That gap shows how different the operating policy is, and it also explains why the model is not open to everyone.
Daybreak Blue and Daybreak Red
OpenAI also restructured Daybreak, its program that puts cyber models in defenders’ hands. There are now two tiers:
| Daybreak Blue | Daybreak Red | |
|---|---|---|
| Model | GPT-5.6 Sol | GPT-5.6-Cyber |
| Difference | System-level cyber guardrails removed | Purpose-trained for cyber, far more permissive |
| Use | Broad defensive workflows, code review, patching | Red teaming, penetration testing, exploit validation |
| Oversight | Standard verification | Identity verification, defined test scopes, logging, human oversight |
One important detail: access to the underlying model stays with the approved partner and is never handed to the end customer. Partners define the boundaries of each engagement and review findings with their own expertise before anything is acted on.
Benchmarks: What the Numbers Say
GPT-5.6 Sol, the base for GPT-5.6-Cyber, left the previous generation well behind on security evaluations:
| Benchmark | GPT-5.5 | GPT-5.6 Sol |
|---|---|---|
| ExploitBench2 (vulnerable code to code execution) | 47.9% | 73.5% |
| ExploitGym (2-hour cap, real vulnerability to exploit) | 15.1% | 24.9% |
| ExploitGym (6-hour cap) | - | 33.7% |
| SEC-Bench Pro | - | 71.2% |
| Internal CTF evaluation | - | 96.7% |
ExploitBench2 jumps by nearly 26 points at a comparable output-token budget. On ExploitGym, extending the time limit from two hours to six pushes the score from 24.9% to 33.7%. More time on task means more working exploits, which is equally true for defenders and attackers.
Keep in mind these scores belong to GPT-5.6 Sol. GPT-5.6-Cyber exposes the same underlying capability with far fewer refusals.
How the Daybreak Program Works
OpenAI’s Daybreak walkthrough shows the program targets the whole loop, from finding a vulnerability to shipping the patch:
OpenAI’s framing is blunt: a vulnerability report does not protect anyone. Protection comes from understanding whether a weakness is actually exploitable, identifying the systems at risk, and getting a fix into production. That is where Daybreak partners come in.
The Astra Crisis in the Background
What makes GPT-5.6-Cyber interesting is the context it launched into. On August 7, OpenAI said internal evaluations of its upcoming model Astra meant it could no longer rule out Critical cyber capability.
Under the framework, Critical means the model can find and develop functional zero-day exploits of all severity levels in many hardened real-world systems without human intervention, or devise and execute end-to-end novel attack strategies given only a high-level goal.
In response the company moved Astra into isolated test environments, restricted network and tool access, hardened model-weight protections, and paused internal work that did not meet the strengthened controls. It also deployed universal monitoring that inspects the model’s chain of thought and can interrupt high-risk activity.
GPT-5.6-Cyber sits one rung below that: High, not Critical. That distinction is exactly why one model ships to defenders while the other is on hold.
Conclusion
GPT-5.6-Cyber formalizes something AI labs now openly accept: attackers already use these capabilities, so restricting defenders does not create safety, it just tilts the balance. The answer on offer is not opening capability to everyone, but routing it to verified hands.
That is also the contested part. The gatekeeper is now the model provider. OpenAI and its partners largely decide who is deemed worthy of defending themselves.
What do you think? Is limiting cyber models to verified organizations the right balance, or does it leave small teams exposed? Let us know in the comments! 👇
