OpenAI released GPT-5.6-Cyber, a model trained to locate zero-days and construct exploit chains, and made it reachable only through a new tier of its Daybreak programme. The company announced it on its own site. One day earlier, the same company said it had halted internal work on Astra because preliminary evaluations could not demonstrate that the unreleased model sits below the Critical cyber threshold in OpenAI’s Preparedness Framework.
Those two decisions do not contradict each other. A frontier general model held back under new containment and a scoped product handed to vetted customers are different objects, and OpenAI treats them differently for reasons it can defend. The sequence is still the story. Inside roughly a day, OpenAI said its most capable unreleased system was too strong at cyber to proceed as planned, then shipped a model purpose-built for offensive security work to an approved list.
The tiers, exactly as described. Daybreak Blue grants access to general-purpose frontier models, GPT-5.6 Sol among them, with safeguards fitted to authorized defensive work rather than the production screening layer. OpenAI calls it the right starting point for most defenders and names the intended uses: malware analysis, incident response, patch validation, secure code review, and vulnerability discovery. The company says its production system screens cybersecurity requests to prevent misuse and also blocks legitimate defensive tasks. Blue removes that screen.
Daybreak Red grants access to the cybersecurity models OpenAI trained for the purpose, covering authorized vulnerability research, security testing, and exploit validation. GPT-5.6-Cyber lives here. It builds on GPT-5.6 Sol and was trained on two axes at once: better performance on specialized cyber tasks, and fewer refusals on high-risk dual-use requests.
The refusal figures are the substance of the post. OpenAI built an internal evaluation it calls the Advanced Cybersecurity Completion Rate, which counts how often a model answers prompts involving authentication bypass, privilege escalation, and exploit-chain development. GPT-5.6-Cyber answers 95.0 percent of them. GPT-5.6 Sol answers 1.5 percent. Sol accessed through Daybreak Blue answers 2.0 percent. The previous GPT-5.5-Cyber answered 57.3 percent, a rate OpenAI says security researchers found obstructive.
That Blue number deserves a second look. Moving from 1.5 to 2.0 percent means removing the production guardrail buys almost nothing on this particular eval. The unlock is not in the access tier. It is in the weights, and the weights are behind Red. The benchmark is OpenAI’s own, no external replication is offered, and the post publishes no methodology beyond a footnote.
Now the part the announcement leaves open. It uses “approved defenders,” “trusted defenders,” and “authorized” throughout, and defines none of them. No eligibility criteria appear. No application process, no vetting standard, no revocation policy, no named launch partners, no pricing, and no availability date. Readers who want to know whether their security team qualifies will not learn it from this post. That vagueness is not a small omission when the product is exploit development.
Which leaves OpenAI holding a role it was never granted. A vendor that gates offensive capability behind its own approval queue becomes the licensing authority for who may possess that capability. No export regime issues the licence. No accreditation body audits the reviewer. No regulator hears an appeal from a rejected applicant. OpenAI wrote the Preparedness Framework it graded Astra against, and it now writes the eligibility rules it will grade customers against. Both documents are internal, and both carry external consequences.
The counterargument is honest and should not be waved off. Attackers do not submit applications. If autonomous offensive tooling reaches criminal groups first, defenders operating under refusal-heavy models start every engagement behind, and no amount of governance elegance closes that gap. Parity is a real security requirement. Someone has to decide who gets the parity, and today that someone is a company selling the capability.
For security leaders, the operational question is procurement, not philosophy: ask OpenAI what Blue and Red approval actually require, in writing, before your 2027 tooling budget assumes either tier is available to you.
Announced by OpenAI in a post published on its own site.