OpenAI has expanded its Daybreak cybersecurity program into two access levels, creating a more explicit boundary between general defensive work and higher-risk security research.

Daybreak Blue is positioned as the starting tier for most approved defenders. It provides access to frontier general-purpose models including GPT-5.6 Sol with safeguards tailored for authorized defensive tasks such as vulnerability discovery, secure-code review, malware analysis, incident response and patch validation.

Daybreak Red is designed for more advanced work, including authorized vulnerability research, exploit validation and security testing. The tier includes GPT-5.6-Cyber, a model built on GPT-5.6 Sol and trained to reduce refusals on specialized dual-use cybersecurity tasks while improving performance on areas such as vulnerability discovery and exploit-chain development.

The distinction reflects a persistent problem for security teams using general AI systems. Safeguards intended to prevent malicious hacking can also block legitimate defensive requests. OpenAI says Blue removes some system-level cyber guardrails for approved users, while Red goes further by supplying a purpose-trained model for tasks that remain too sensitive or specialized for the general model.

OpenAI reports that GPT-5.6-Cyber completed 95% of requests in an internal evaluation covering advanced scenarios such as exploit-chain development, authentication bypass and privilege escalation. The figure is an OpenAI benchmark rather than an independent measure, and the company’s own published evaluations also show that GPT-5.6-Cyber does not outperform GPT-5.6 Sol on every security task.

Axios independently reported the same Blue/Red split and described the launch as an effort to give vetted defenders access to less-restricted cyber capabilities without making those capabilities generally available. The program remains controlled: OpenAI says access is limited to approved individuals and organizations and is governed through identity checks, account security, monitoring, approved-use restrictions and legal attestations.

That controlled-access model is likely to become more important as cyber-capable AI improves. The strategic question is no longer simply whether a model can find or exploit vulnerabilities, but how providers can make those capabilities useful to defenders without turning advanced offensive techniques into an unrestricted commodity.