
OpenAI has expanded its Daybreak cyber defense service with two new tiers and a specialized model called GPT‑5.6‑Cyber, available to trusted partners like Accenture, IBM, Crowdstrike, and Cloudflare.
The move reflects a growing concern that AI agents are increasingly being used to conduct cyberattacks at scale, including autonomous hacking of websites and social engineering campaigns.
OpenAI is marketing its upgrade as essential protection as threat actors gain access to AI capabilities, though the company's own advanced models are now being sold as the solution to risks those models themselves pose.
What happened
OpenAI announced Monday an expansion of Daybreak, its cyber defense service launched earlier this year, introducing two tiers—Blue and Red—with access to frontier cyber models. The Red tier includes a new model, GPT‑5.6‑Cyber, built off GPT‑5.6 Sol and designed for specialized cybersecurity tasks; it is currently available only to trusted customer partners including Accenture, IBM, Crowdstrike, and Cloudflare.
Why it matters
AI models are increasingly being used to launch cyberattacks—compromising platforms like Hugging Face, hacking websites, and creating fake profiles for social engineering. By offering both defensive services (Blue tier: incident response, malware analysis, patch validation) and offensive security testing tools (Red tier), OpenAI is positioning itself as the source of protection against the very risks its own models could pose.
What to watch
Blue is described as OpenAI's "recommended starting point for most defenders," suggesting it is designed for broad enterprise use, while Red's "purpose-trained cybersecurity models" and GPT‑5.6‑Cyber are reserved for approved partners. Access to frontier models has been a point of government scrutiny; the Trump administration previously sought collaboration with AI companies on their rollout over safety concerns.
OpenAI announced Monday the expansion of Daybreak, a cyber defense service it launched earlier this year. The expanded offering is built around two tiers: Blue and Red, both providing approved customers access to OpenAI's limited-access frontier cyber models—the most advanced available.
Blue is positioned as the entry point for most defenders, offering a suite of standard cybersecurity services: incident response, malware analysis, and patch validation. OpenAI specifically calls it the "recommended starting point for most defenders," suggesting it is designed to address the needs of broader enterprise customers. Red, the higher tier, grants users a broader and potentially more dangerous toolkit, including "purpose-trained cybersecurity models" designed to carry out security testing and vulnerability research. Red is distinguished by the inclusion of GPT‑5.6‑Cyber, a brand new model built off GPT‑5.6 Sol with enhanced capabilities for specialized cybersecurity tasks. At present, GPT‑5.6‑Cyber is only being made available to "trusted customer partners," reportedly including Accenture, IBM, Crowdstrike, Cloudflare, and others.
The expansion arrives as AI agents are increasingly being deployed for malicious purposes. The body cites examples of AI compromising Hugging Face, hacking a gym website, and creating its own fake profiles to conduct social engineering intrusions. OpenAI's move follows Anthropic's release of Mythos, a cyber-focused model launched not long before Daybreak. In its blog post announcing the expansion, OpenAI stated: "The cybersecurity world is rapidly changing—threat actors will increasingly use AI to conduct cyberattacks at unprecedented speed and scale, including in fully autonomous ways. As these capabilities spread, defenders have a narrowing window to prepare." The company frames Daybreak as both a response to a real security crisis and a business opportunity, with enterprises increasingly interested in buying protection from the AI labs that understand the risks firsthand.
OpenAI's expansion of Daybreak comes as AI-driven cyberattacks are becoming more sophisticated and autonomous. The body cites examples of AI agents compromising Hugging Face, hacking gym websites, and creating fake profiles to conduct social engineering—a trend the company frames as urgent. OpenAI's response mirrors a broader pattern: Anthropic launched its own cyber-focused model, Mythos, earlier this year, suggesting that AI labs see cybersecurity as a natural business expansion.
The two-tier structure reveals a strategic distinction. Blue targets the general enterprise market with standard defensive tools, positioning itself as sufficient for most defenders. Red, by contrast, offers the new frontier model GPT‑5.6‑Cyber alongside offensive security capabilities, but restricts access to a vetted list of partners—a gatekeeping approach that echoes previous controversy. The Trump administration previously sought to influence how frontier models are deployed over safety concerns, and OpenAI has historically deployed guardrails to limit what customers could do with advanced models. The Red tier's restricted rollout may reflect that tension, while also creating exclusivity that could strengthen OpenAI's position with large enterprises.
The framing in OpenAI's blog post—that "defenders have a narrowing window to prepare"—serves both as a genuine security warning and as marketing leverage. Enterprises do appear motivated to buy protection from the labs that understand AI risks most deeply because they know them firsthand, and OpenAI is now positioned as both the source of those risks and the solution to them.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Tech companies are raising unprecedented sums for AI infrastructure—$194 billion so far in 2026 by just four f…

Nvidia has partnered with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs, and KKR to raise $500bn in…

Nvidia has signed letters of intent with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs, and KKR to…

Anthropic has signed the EU AI Act Code of Practice and will embed invisible watermarks in Claude-generated te…

Anthropic has agreed to pay $9.1 billion over 20 years to Riot Platforms Inc., a Bitcoin miner turned data cen…

Samsung is accelerating efforts to qualify its Taylor, Texas fabrication plant for 2-nanometer chip production…

The AI news that matters, in one minute each morning.
Sign up free