OpenAI announced on 10 August that it is splitting its Daybreak security programme into Blue and Red tiers and shipping GPT-5.6-Cyber, a model tuned for offensive security work, to Red-tier customers.
The gap between the tiers
Blue covers incident response, malware analysis, secure code review and patch validation. Red covers vulnerability research, exploit validation and security testing — the work a general-purpose model refuses. On OpenAI's Advanced Cybersecurity Completion Rate eval, GPT-5.6-Cyber completes 95.0% of requests, against 1.5% for the general GPT-5.6 Sol, 2.0% under Blue access and 57.3% for last generation's GPT-5.5-Cyber.
What is actually holding the line
The safeguard is no longer the model's refusal behaviour — that has been deliberately removed. It is customer vetting. Distribution is limited to trusted partners, and from 1 September every individual Daybreak account, Blue or Red, must authenticate with a hardware security key.
The numbers are self-reported
The completion rates come from an internal OpenAI benchmark with no third-party replication, and the eval measures whether the model attempts and completes a task, not whether the output works. Partner names circulating in coverage come from press reporting rather than OpenAI's announcement.
Limited access is not general availability
GPT-5.6-Cyber is not on the public API. The programme's shape — a model that will do the work, plus an approved list — is now the template other labs will be measured against.
The argument for it
OpenAI's framing is that the defender's window is closing: attackers already use models for this work, so refusing to build capable defensive tooling concedes the asymmetry. The counter is that an approved list is a weaker control than a refusal, because it fails open the moment an account is compromised — which is presumably why the hardware key requirement shipped alongside it.
