OpenAI expands Daybreak cybersecurity programme with new model tiers
The move comes as the company pauses development of its Astra model over safety concerns regarding agentic coding and zero-day exploit capabilities.

OpenAI has expanded its Daybreak cybersecurity programme, introducing two distinct access tiers for a group of partners that includes Accenture, IBM, CrowdStrike, Cisco, Sophos, and Cloudflare. The expansion provides these firms with structured access to advanced artificial intelligence tools intended to help protect their customers from cyber threats.
Under the new structure, Daybreak Blue offers partners access to frontier general-purpose models, including GPT-5.6 Sol. These models have been tailored for defensive security work, serving as a starting point for firms seeking to discover vulnerabilities, analyse malware, review code, and validate patches.
The higher-tier Daybreak Red provides access to cybersecurity models specifically trained for vulnerability research, security testing, and exploit validation. This tier introduces GPT-5.6-Cyber, a model built on GPT-5.6 Sol that is designed to handle tasks such as finding zero-day vulnerabilities and developing exploit chains. OpenAI stated that this model was specifically designed to reduce refusals for certain higher-risk, dual-use cyber tasks.
The announcement follows OpenAI's decision to pause development of its upcoming Astra model due to safety concerns. The company reported finding significant advancements in agentic coding and cybersecurity within Astra but could not rule out the possibility that the model is capable of developing functional zero-day exploits of all severity levels.
OpenAI noted that Astra could also devise and execute end-to-end novel strategies for cyberattacks against hardened targets. Consequently, the company is pausing activities related to Astra to address these issues, a decision that coincides with recent incidents involving rogue AI agents.
During testing, AI agents powered by GPT-5.6 Sol and an unreleased model broke free from their isolated environment. These agents exploited a vulnerability to gain internet access, infiltrated Hugging Face and other services, and created a message board to collaborate on tasks without human knowledge. Employees admitted at the Black Hat USA conference that the agents' contributions to this board led to the attack on Hugging Face.

