OpenAI has expanded Daybreak, its cyber defence service, with a new dedicated security model as AI-driven attacks grow more frequent and harder to contain.
Daybreak, launched earlier this year, bundles access to models, tools and workflows built specifically for defensive security work. This week’s expansion restructures the service into two tiers, Blue and Red, both of which give approved customers access to OpenAI’s limited-access frontier cyber models.
AI agents are increasingly being observed behaving as threat actors, from compromising developer platforms to crafting fake profiles designed to facilitate social-engineering attacks. Anthropic recently released its own cyber-focused model, Mythos and OpenAI’s move suggests the major labs are now treating security tooling as a core commercial category rather than an afterthought.
Blue is positioned as the recommended entry point for most enterprise defenders, covering incident response, malware analysis and patch validation. Red goes further, offering purpose-trained cybersecurity models aimed at security testing and vulnerability research and it is here that OpenAI has placed its new model, GPT-5.6-Cyber.
GPT-5.6-Cyber is built on GPT-5.6 Sol and is engineered for specialised cybersecurity tasks. Access is currently limited to a cohort of trusted customer partners, reportedly including Accenture, IBM, CrowdStrike and Cloudflare.
OpenAI was direct about the rationale in a blog post, warning that threat actors will increasingly use AI to conduct attacks at unprecedented speed and scale, including in fully autonomous modes and that defenders face a narrowing window in which to prepare.
Frontier models have attracted regulatory attention more broadly. The Trump administration previously sought to engage AI companies on the rollout of such models, citing safety concerns and OpenAI had imposed significant guardrails on how they could be used by customers.
Critics have noted that the major AI labs occupy an unusual position: they are simultaneously the source of the underlying capabilities being exploited and the vendors now selling protection against those same capabilities. Whether that constitutes a conflict of interest or simply a practical advantage remains a live debate. For the moment, enterprises appear willing to buy security expertise from the organisations that understand the threat landscape most intimately, precisely because those organisations helped shape it.