OpenAI Ships a Cyber Model That Answers 95% of Hacking Requests, Days After Restricting a Different One
OpenAI released GPT-5.6-Cyber, a cyber-permissive model for vetted defenders, three days after delaying Astra over critical hacking capability.

OpenAI expanded its Daybreak cybersecurity program Monday with GPT-5.6-Cyber, a model built to handle offensive security requests that its consumer models normally refuse.
The company also opened it to vetted enterprise defenders including Accenture, IBM, CrowdStrike, Cisco, and Palo Alto Networks.
The release comes just three days after OpenAI paused parts of Astra’s development over possible “Critical” cyber capabilities, creating an apparent contradiction: restricting one model for being too capable at hacking while releasing another designed to be more permissive.
A 95% Completion Rate Built by Design, Not Accident
OpenAI’s own announcement showed the gap clearly: GPT-5.6-Cyber completes 95.0% of requests involving exploit-chain development, authentication bypass, and privilege escalation, compared with just 1.5% for standard GPT-5.6 Sol with its safety guardrails active.
That’s not a marginal tuning difference; it’s a model intentionally retrained to say yes where its sibling says no.
OpenAI said the model has already uncovered two previously unknown vulnerabilities in Chrome’s V8 JavaScript engine, including one Google patched as CVE-2026-15903.
It also found more than 400 vulnerabilities in a popular operating system kernel and several critical flaws in a widely used database, which the ChatGPT owner says it is working to disclose with the affected vendors.
Access Now Extends Into Commercial Security Products
According to TechCrunch, the expanded Daybreak program splits into two tiers, Blue for general-purpose defensive work like malware analysis and patch validation, and Red for the new Cyber model’s more specialized vulnerability research and exploit validation.
The outlet also flagged a detail worth sitting with: OpenAI’s own blog post framed the release around a genuine security rationale, warning that threat actors will increasingly use AI to conduct cyberattacks at unprecedented speed and scale.
While critics have separately noted that rogue-agent incidents this summer have doubled as marketing opportunities for the very labs building the models involved.
Both things can be true at once, and OpenAI’s Monday announcement leans into that tension rather than around it, treating a narrowing “defense window” as the justification for widening access to its most permissive cyber model yet.
The Sequence Isn’t a Reversal, It’s a Boundary Being Drawn
What makes the Astra-then-Cyber timing coherent rather than contradictory is that both decisions run through the identical Preparedness Framework threshold, just on opposite sides of it.
Axios reported that GPT-5.6 Cyber was independently rated at the High cyber capability tier, matching its parent model GPT-5.6 Sol and sitting one step below the Critical threshold that triggered Astra’s pause.
OpenAI also said Cyber improved on some specialized tasks but did not cross that line.
The takeaway is that OpenAI isn’t lowering its safety bar; it’s releasing a model close to the threshold while holding back the one that crossed it.
The approach mirrors Anthropic’s Mythos, which was restricted to a small vetted group after reaching a similar capability threshold, suggesting the industry is moving toward tiered access with government-adjacent vetting.
Whether this approach holds once dozens of enterprise partners embed these models into commercial products, rather than a handful of research labs testing them in isolation, is the harder question this rollout does not yet answer.
Source: Expanding Daybreak as the Cyber Defense Window Narrows



