OpenAI hands a specialised hacking AI to a small club of security firms
GPT 5.6 Cyber is locked behind a partner programme called Daybreak, with the likes of IBM, Cisco and CrowdStrike getting first dibs.

Key points
- OpenAI has built a new AI model called GPT 5.6 Cyber, aimed at finding and fixing security holes in company systems.
- The model is not public; only approved partners including Accenture, IBM, Capgemini, Cognizant, EY, KPMG and PwC can use it, alongside specialist firms NCC Group and SpecterOps.
- Security vendors on the list include Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai and Fortinet, plus Cloudflare.
- Access splits into two tracks: Daybreak Blue for defensive work and Daybreak Red for offensive testing.
- OpenAI says customers never touch the model directly; partners handle identity checks, logging and human oversight.
OpenAI has released a version of its AI technology built specifically for cybersecurity work, and almost nobody gets to use it.
The model is called GPT 5.6 Cyber. It's designed to hunt for software flaws, test whether those flaws can actually be exploited, and help clean up after an attack. First reported by BleepingComputer, it goes only to a short list of approved consulting firms and security vendors. Regular ChatGPT users won't see it in the dropdown.
Why is OpenAI keeping this one locked up?
General-purpose AI models have already been caught helping criminals write malware or scan for weak spots. Handing a model tuned specifically for offensive security to anyone with a credit card would be, in the polite phrasing of a postmortem, a risk not worth taking.
OpenAI says access to the underlying model stays with the approved partner. The customer buying a penetration test, where a security firm is paid to attack a client's systems the way a real hacker would, never gets to prompt it directly. A bank hiring PwC to audit its systems is buying PwC's judgment wrapped around the AI, not the AI itself.
What can GPT 5.6 Cyber actually do?
OpenAI lists five jobs: spotting vulnerabilities, working out whether a weakness can really be exploited, finding which systems are affected, developing fixes, and pushing those fixes into production.
Access comes through a programme OpenAI calls Daybreak.
| Version | Purpose | Typical work |
|---|---|---|
| Daybreak Blue | Defensive | Incident response, patching, threat hunting |
| Daybreak Red | Offensive | Red teaming, penetration testing, exploit validation |
Red teaming is when a hired crew acts like real attackers to find what breaks. It's the part of security work most likely to go sideways if you give a machine too much rope, which is presumably why OpenAI calls Daybreak Red "closely governed."
Safeguards will include identity verification, agreed testing boundaries, activity logging and a human signing off before anything acts on findings.
Does this actually change anything for defenders?
Maybe. The pitch is that a mid-sized enterprise no longer has to build its own specialist AI security team to get useful output from one. It rents the capability through a consultancy or vendor it already pays. Our 6 August piece on what 300,000 real-world security tests revealed about AI hacking tools made exactly this point: the hard lesson isn't about finding weaknesses, it's about knowing which ones matter. GPT 5.6 Cyber is OpenAI's answer to that problem, routed through firms that are supposed to supply the judgment layer.
The failure mode is obvious enough. A model good at finding exploitable bugs is, by definition, good at finding them for whoever holds the keys. OpenAI is betting that a small vetted partner list plus logging plus human review keeps it on the right side of the ledger.
The postmortem, if this goes wrong, will note that the boundary between "approved partner" and "leaked API key" turned out to be thinner than the marketing suggested. Cybersecurity providers and consultancies can apply to join the programme. Everyone else waits.
Operational takeaway: if your security vendor starts pitching AI-driven pentests, ask them plainly whether Daybreak Red is behind it and who reviews the output before it reaches your network.



