OpenAI hands a specialised hacking AI to a small club of security firms

GPT 5.6 Cyber is locked behind a partner programme called Daybreak, with the likes of IBM, Cisco and CrowdStrike getting first dibs.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of an abstract dark web browser window glowing on a desk, with translucent neon login form fields dissolv
Share

Key points

  • OpenAI has built a new artificial intelligence model called GPT 5.6 Cyber, aimed at finding and fixing security holes in company systems.
  • The model is not available to the public; only approved partners including Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group and SpecterOps can use it.
  • Security vendors on the list include Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet and Cloudflare.
  • Access is split into two flavours: Daybreak Blue for defensive work and Daybreak Red for offensive testing.
  • OpenAI says customers never touch the model directly, and partners handle identity checks, logging and human oversight.

OpenAI has released a new version of its chatbot technology built specifically for cybersecurity work, and almost nobody gets to use it.

The model is called GPT 5.6 Cyber. It is designed to hunt for software flaws, test whether those flaws can actually be broken into, and help clean up after an attack. First reported by BleepingComputer, it will only be handed to a short list of approved consulting firms and security vendors.

The consulting side includes Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group and SpecterOps. On the product vendor side you have Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet and Cloudflare.

Regular ChatGPT users will not see it in the dropdown.

Why is OpenAI keeping this one locked up?

Because general-purpose AI models have already been caught helping criminals write malware, phish victims and scan for weak spots. Handing out a model tuned specifically for offensive security to anyone with a credit card would be, in the polite phrasing of a postmortem, a risk not worth taking.

OpenAI says access to the underlying model stays with the approved partner. The customer buying a penetration test, which is where a security firm is paid to attack a client's systems the way a real hacker would, never gets to prompt the thing directly.

In practice, that means a bank hiring PwC to check its systems is buying PwC's judgment wrapped around the AI, not the AI itself.

What can GPT 5.6 Cyber actually do?

OpenAI lists five jobs: spotting vulnerabilities, working out whether a weakness can really be exploited, finding which systems are affected, writing fixes, and helping push those fixes into production.

Access comes in two lanes under a programme OpenAI calls Daybreak.

Version Purpose Typical work
Daybreak Blue Defensive Incident response, patching, threat hunting
Daybreak Red Offensive Red teaming, penetration testing, exploit validation

Red teaming, for the uninitiated, is when a hired crew acts like real attackers to see what breaks. It is the part of security work most likely to go sideways if you give a machine too much rope, which is presumably why OpenAI calls it "closely governed."

The company says safeguards will include identity checks on operators, agreed testing boundaries, activity logging, monitoring, and a human signing off before anything acts on findings.

Does this actually change anything for defenders?

Maybe. The pitch is that a mid-sized enterprise no longer has to build its own specialist AI security team to get useful output from one. It rents that capability through a consultancy or a vendor it already pays.

The failure mode here is obvious enough. A model that is good at finding exploitable bugs is, by definition, good at finding them for whoever holds the keys. OpenAI is betting that a small vetted partner list plus logging plus human review is enough to keep it on the defensive side of the ledger.

One thing the post-mortem will say, if this goes wrong, is that the boundary between "approved partner" and "leaked API key" turned out to be thinner than the marketing suggested. Cybersecurity providers and consultancies can apply to join the programme. Everyone else waits.

Operational takeaway: if your security vendor starts pitching AI-driven pentests in Q1, ask them plainly whether Daybreak Red is behind it and who reviews the output before it hits your network.

© 2026 Threat Vectr