[OpenAI](#/company/openai) released GPT-5.6-Cyber on August 10, a version of GPT-5.6 Sol trained specifically to do the offensive-security work the public model is built to refuse — finding zero-day vulnerabilities and building working exploit chains against real software. On the company's own Advanced Cybersecurity Completion Rate benchmark, GPT-5.6-Cyber completes 95.0% of those requests. GPT-5.6 Sol, under its standard public safeguards, completes 1.5%. The prior generation, GPT-5.5-Cyber, launched June 22 and managed 57.3% on the same test — this is the second such model OpenAI has shipped in under two months, each one narrowing the gap between what a defender can ask for and what the model will do.
The gap isn't an accident — it's the product. Access to that capability now runs entirely through Daybreak, OpenAI's gated cybersecurity program, expanded the same day into two tiers. Daybreak Blue gives vetted defenders GPT-5.6 Sol with its system-level cyber guardrails removed, for malware analysis, vulnerability detection and incident response — the everyday work of a security team, just unblocked. On the same benchmark, Blue-tier access completes 2.0% of advanced requests, barely above the public model's 1.5% — evidence that most of the gap to GPT-5.6-Cyber's 95.0% is purpose-built capability, not just a removed guardrail. Daybreak Red gates GPT-5.6-Cyber itself behind stricter vetting, reserved for exploit validation and vulnerability research rather than routine defense. Both require identity verification, account-security checks, usage monitoring and a legal attestation of authorized use; individual accounts must add a hardware security key starting September 1, 2026, and organizations apply through a separate, heavier-weight track.
Advanced Cybersecurity Completion Rate, by access tier
| GPT-5.6 Sol public, standard safeguards | Daybreak Blue vetted defenders, guardrails removed | GPT-5.5-Cyber prior generation, launched June 22 | GPT-5.6-Cyber Daybreak Red only | |
|---|---|---|---|---|
| Completion rate on advanced cyber requests | 1.5% | 2.0% | 57.3% | 95.0% |
| Primary use case | General assistant, standard refusals | Malware analysis, incident response | Exploit-chain research (prior gen) | Zero-day discovery, exploit validation |
The capability isn't hypothetical. OpenAI says GPT-5.6-Cyber has already identified two previously unknown vulnerabilities in Chrome's V8 engine — one assigned CVE-2026-15903, an out-of-bounds read/write flaw serious enough to allow arbitrary code execution inside the browser sandbox — plus five vulnerabilities in a popular mobile operating system, including privilege-escalation chains, and flaws OpenAI describes as critical in a widely used database. Google has since shipped a fix for the Chrome flaw. The CVE itself is independently listed in third-party vulnerability-tracking databases, with its own technical detail separate from OpenAI's announcement; that GPT-5.6-Cyber specifically is what found it is OpenAI's own account, not something Google's advisory or the database entry attributes to any tool.
Three days after “critical”
The timing sits next to a separate disclosure. On August 7, OpenAI said it had paused internal work on parts of Astra — an unrelated model family built for extended multi-agent reasoning, not a cybersecurity product — after the system reached what OpenAI calls a “critical cybersecurity threshold” under its Preparedness Framework: the ability to independently identify and carry out cyberattacks against well-defended, real-world systems, not a benchmark result. It was the first OpenAI model to trip that specific bar, and the company added isolated testing, restricted access and outside stress-testing around the affected capabilities.
GPT-5.6-Cyber is a different model family and, by OpenAI's own rating, a lower capability tier: High, not Critical, on the same Preparedness Framework scale. High means a model can remove existing bottlenecks to scaling cyber operations or automate discovery of operationally relevant vulnerabilities against reasonably hardened targets; Critical means it can do that against hardened real-world systems independently, with no human in the loop. OpenAI has not said the Astra pause and the GPT-5.6-Cyber launch are connected, and this piece found no evidence they share a checkpoint. What's verifiable is the calendar: a capability pause at the top of the scale, then a deliberate, access-gated release three days later at the tier just below it.
- Aug 7, 2026 — OpenAI discloses Astra tripped the Preparedness Framework's Critical cybersecurity threshold; pauses affected internal work.
- Aug 10, 2026 — OpenAI releases GPT-5.6-Cyber (rated High) through the new Daybreak Red tier.
- Sep 1, 2026 — Hardware security keys become mandatory on individual Daybreak accounts.
The Preparedness Framework is OpenAI's own internal gate, not a regulatory one — no US or EU rule currently requires a lab to test for or disclose a cybersecurity capability threshold before release. That makes this week's sequence a voluntary test case for whether a lab will actually act on its own framework rather than just publish one: pausing Astra's affected capabilities cost OpenAI a public admission of an internal safety trigger; shipping GPT-5.6-Cyber a few days later, gated rather than withheld, is the same framework producing a different verdict for a lower-rated capability. Both outcomes rest on OpenAI's own scoring, evaluated by OpenAI, against a rubric OpenAI wrote.
What's checked, and what's OpenAI's word
Reading the release against what's independently checkable
- CVE-2026-15903 is a real, exploitable Chrome V8 vulnerability.
- GPT-5.6-Cyber specifically is what found CVE-2026-15903 and the mobile-OS flaws.
- GPT-5.6-Cyber completes 95.0% of advanced cybersecurity requests, versus 1.5% for the public model.
- GPT-5.6-Cyber and GPT-5.6 Sol are rated High, not Critical, on the Preparedness Framework.
The Daybreak Cyber Partner Program — which includes Accenture, CrowdStrike, Cisco, IBM and Palo Alto Networks — lets those firms embed Daybreak-gated models into their own commercial security products. SpecterOps chief technology officer Jared Atkinson, an early tester, said the model "has completed work in under a day that earlier models had not resolved after weeks." OpenAI also ran a five-day "Patch the Planet" sprint in which more than 30 open-source projects used Daybreak access to find and fix vulnerabilities in their own code — the defensive case the program is named for. OpenAI has not published the substantive criteria by which a Daybreak Red application is approved or denied, beyond the identity and legal-attestation requirements above, and has not described a mechanism for an organization to learn whether a partner-embedded, Daybreak-derived model was used against its own systems.
The case for skepticism
OpenAI frames the release as a race against a narrowing window — giving vetted defenders frontier capability before it reaches attackers by other means. The Astra pause, five days earlier, is the company's own evidence that the same framework can also say no. Whether Daybreak's access controls hold up is not yet independently tested; whether the underlying framework does, now has one real data point.
- OpenAI released GPT-5.6-Cyber on August 10, gated behind a program called Daybreak.
- It completes 95% of advanced hacking requests OpenAI's public model refuses at 1.5%.
- It has already found a live Chrome flaw (CVE-2026-15903) and mobile-OS vulnerabilities.
- It ships three days after a related model, Astra, was paused for tripping a stricter, 'critical' threshold.
- Caveat: the 95%/1.5% gap is OpenAI's own benchmark — no independent lab has replicated it.
