AIToday
Large Language ModelsOpen-Source AIAI Safety & Alignmentr/artificialPublished: Aug 18, 2026, 13:01 JST2 min read

OpenAI paused cyber model; two labs shipped it anyway

OpenAI paused cyber model; two labs shipped it anyway

Key takeaway

  • One week after OpenAI paused internal development of a model it could not rule out possessed cyber-attack capabilities, two separate labs released models with those capabilities anyway—but through opposite gates. OpenAI launched GPT-5.6 Cyber on Aug 10, restricted to 16 partners, with its own eval showing 95% compliance with offensive-security requests.

  • On Aug 14, Zhipu released GLM-5.3 with open weights, giving any developer access to the same class of capability.

  • The contrast illustrates a widening split in how the AI industry handles dual-use risks.

3 Key Points

  1. What happened

    One week after OpenAI paused internal work on a model it could not rule out was cyber-capable, the capability shipped through two different routes. OpenAI released GPT-5.6 Cyber on Aug 10, a security-specialized model gated behind a "Daybreak Red" tier accessible only to 16 named partners (with individual accounts requiring hardware keys from Sept 1). Separately, Zhipu released GLM-5.3 on Aug 14, marketed on "emergent cyber capabilities," with open weights promised in approximately 2 weeks.

  2. Why it matters

    OpenAI's internal eval shows GPT-5.6 Cyber answers 95% of offensive-security requests that the standard model refuses 98.5% of the time—demonstrating a significant shift in what the model will help with. The two companies chose opposite access models: OpenAI restricted the capability to a small gated group and withheld weights; Zhipu published open weights, making the cyber capability available to any developer. This contrast reflects a fundamental disagreement on how to handle dual-use AI risks.

  3. What to watch

    OpenAI's hardware-key requirement takes effect Sept 1 for individual GPT-5.6 Cyber accounts. Zhipu's open weights are expected in approximately 2 weeks from Aug 14. GLM-5.3 claims 84.5% on CyberGym (vendor-reported), compared to Wiz's Atlas system at 90.9%—a gap that may shape how developers choose between the two models.

Ask the AI about this article →

Context & Analysis

OpenAI's decision last week to pause internal work on a model it could not rule out possessed cyber capabilities reflected genuine uncertainty about whether deploying such a system could enable harmful attacks. The pause was intended to buy time for safety review and policy decisions. Yet this week, the exact capability shipped anyway—not once, but twice, and on a collision course of opposite philosophies.

OpenAI's response was to gate access sharply: GPT-5.6 Cyber reaches only 16 named partners and will require hardware-key authentication from Sept 1 onward for individual users. The company withheld model weights entirely, giving customers findings and conclusions but not the ability to run or modify the model themselves. The eval data—95% compliance vs. 98.5% refusal—underscores that OpenAI has indeed built something materially more compliant with offensive-security requests.

Zhipu took the opposite path. GLM-5.3, released four days later, is explicitly marketed on "emergent cyber capabilities" and promised open weights in roughly two weeks. That choice puts the full model in the hands of any developer worldwide with no gating, no hardware key, no partner approval. The gap in claimed performance (84.5% on CyberGym vs. Wiz's Atlas at 90.9%) matters, but the access model is the real story: one company chose containment, the other chose transparency.

FAQ

How much better is OpenAI's cyber model at helping with offensive security?
OpenAI's internal eval shows GPT-5.6 Cyber answers 95% of offensive-security requests, compared to the standard model refusing 98.5% of the time.
Who can access OpenAI's GPT-5.6 Cyber model?
Access is gated to 16 named partners. Starting Sept 1, individual accounts require hardware keys.
When will Zhipu's open weights be available?
Zhipu promised open weights in approximately 2 weeks from Aug 14.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Nvidia revives Rubin CPX chip with major redesignYahoo Finance AI · 2h ago
  • AI advice followed by 79%, but well-being unchangedITmedia AI+ · 5h ago
  • Enterprises face agent governance gapSiliconANGLE AI · 8h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleGroq raises $350M to expand AI cloud platform