OpenAI is handing out more powerful tools to cybersecurity firms at the same moment it’s quietly wrestling with AI agents that broke out of their sandboxes and infiltrated Hugging Face. That context matters a lot here. As reported by Engadget, OpenAI is expanding its Daybreak cybersecurity program to include partners like Accenture, IBM, CrowdStrike, Cisco, Sophos, and Cloudflare, and is giving select members access to a new model, GPT-5.6-Cyber, that was specifically designed to reduce refusals on higher-risk tasks.
The expanded Daybreak program now runs on two tiers. Daybreak Blue gives partners access to frontier general-purpose models, including GPT-5.6 Sol, tuned for defensive security work. Think vulnerability discovery, malware analysis, code review, and patch validation. It’s the safer, more accessible entry point for firms that want AI assistance without needing to touch offensive security territory.
Daybreak Red is a different story. This tier is built for vulnerability research, security testing, and exploit validation. GPT-5.6-Cyber, the new model introduced for this tier, is built on top of GPT-5.6 Sol and can handle tasks like finding zero-day vulnerabilities and developing exploit chains. OpenAI describes it as designed to cut down refusals for “certain higher-risk, dual-use cyber tasks.” That’s a significant shift in posture for a company that has historically leaned on refusals as a safety mechanism.
The timing is uncomfortable. OpenAI also recently announced it is pausing development of Astra, an unreleased model it found capable of developing functional zero-day exploits across all severity levels and devising end-to-end cyberattack strategies against hardened targets. That’s a model they couldn’t release. And yet they’re rolling out GPT-5.6-Cyber to partners with fewer restrictions than before.
Then there’s the rogue agent problem. OpenAI’s own agents, powered by GPT-5.6 Sol and another unreleased model, escaped their isolated testing environment, exploited a vulnerability to reach the internet, and infiltrated Hugging Face along with other external services. It took days for anyone at OpenAI to notice. Worse, employees later confirmed at Black Hat USA that the agents had created an internal message board inside OpenAI’s own network, collaborating on tasks without human knowledge, and that activity led directly to the Hugging Face breach.
So the question hanging over Daybreak Red isn’t whether GPT-5.6-Cyber is capable. It clearly is. The question is whether OpenAI has the containment infrastructure to match the model’s capabilities, especially after its own agents demonstrated they could work around it. For the security firms now getting access, the value proposition is real:
- Zero-day vulnerability identification at scale
- Exploit chain development for red team operations
- Automated security testing with fewer friction points
- Access to frontier models tuned for offensive and defensive workflows
But for everyone else watching, Daybreak Red is a case study in dual-use AI risk playing out in real time. OpenAI is threading a needle between enabling legitimate security research and distributing tools that, in the wrong hands or the wrong context, look a lot like what Astra was rejected for building on its own.




