OpenAI suspended a model due to cybersecurity concerns on Friday. By Monday, it released a new version that is trained to be less restrictive.
OpenAI launched GPT-5.6-Cyber on Monday. This model, which builds upon GPT-5.6 Sol, is designed for zero-day discovery and exploit-chain development. The company claims it has also been trained to decline fewer high-risk dual-use cyber requests. Access is available exclusively through Daybreak, OpenAI's vetted cybersecurity program that is currently being expanded. Axios reporter Sam Sabin was the first to report on this news.
Just three days prior, OpenAI postponed the release of Astra because it could not eliminate the risk of critical cyber capabilities. This sequence might seem like a reversal, but it isn’t, and the reasoning behind it reveals where the industry has actually set its boundaries.
Two divisions within one program
Daybreak is now divided into two branches. Daybreak Blue features general-purpose frontier models, including GPT-5.6 Sol, but without system-level cyber guardrails. OpenAI suggests this as the starting point for defensive initiatives such as vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.
Daybreak Red contains purpose-trained cyber models, where GPT-5.6-Cyber is located, aimed at authorized vulnerability research, exploit validation, and security testing.
Sol was introduced in June, distributed to 20 government-approved partners only. This pattern has been consistent throughout the year: access to capabilities is granted via a specific channel rather than a general download page.
The key metric is the refusal rate
OpenAI shares an internal metric known as the Advanced Cybersecurity Completion Rate, which monitors how often a model fulfills requests in areas like exploit-chain development, authentication bypass, and privilege escalation.
GPT-5.6-Cyber has a completion rate of 95.0%, while its predecessor, GPT-5.5-Cyber, had a rate of 57.3%. Sol accessed through Daybreak Blue achieves 2.0%, while Sol with standard safeguards reaches only 1.5%.
Thus, the primary change is not in intelligence but in compliance. The same foundational model, addressing the same type of tasks, now provides responses rather than declining requests.
What was revealed
OpenAI tested GPT-5.6-Cyber on V8, the JavaScript engine used in Chrome, and identified two previously unknown vulnerabilities capable of corrupting memory and escaping the engine’s sandbox. Google was informed through a coordinated disclosure, issued a fix, and these vulnerabilities are now marked as CVE-2026-15903, which is a confirmed public benefit with a documented trail, a rarity in this field.
The company also reported at least five vulnerabilities in a widely used mobile operating system, three critical ones in a popular database, and over 400 privilege-escalation flaws in a commonly used OS kernel. The specific products involved have not been disclosed, as the disclosure process is still ongoing with partners and open-source maintainers.
The benchmarks do not indicate a clean sweep
Two results from OpenAI’s own tests contradict the performance of the new model. In vulnerability discovery and report writing, GPT-5.6-Cyber performs worse than plain Sol, a situation the company attributes to shorter and less detailed reports.
In the 300-turn standard setting on ExploitBench, Sol accessed through Daybreak Blue performs the best and uses fewer tokens. The difference narrows in the 600-turn setting.
Together, these findings suggest the specialized model excels in narrow offensive tasks but is not consistently superior in surrounding tasks. OpenAI acknowledges this in its post.
Where the framework actually draws a boundary
According to its Preparedness Framework, OpenAI rates Sol as High on cyber capability, below the Critical threshold, and assigns the same rating to GPT-5.6-Cyber. Both are classified as High but fall short of Critical. A system card will be released later.
This provides clarity: Astra was delayed because OpenAI could not certify it as non-Critical, while GPT-5.6-Cyber is approved because it does not meet that threshold. The framework governs capability but not access, and it is this aspect that has changed this week.
OpenAI has also issued a specific denial, stating that GPT-5.6-Cyber did not contribute to the incident where its agents breached Hugging Face, and no other models are planned for an upcoming release. The investigation into that incident is still ongoing.
The controls in place
Access to Daybreak is contingent on identity verification, account security, monitoring, approved usage restrictions, and legal attestations. Each Daybreak account must implement a hardware security key by September 1, 2026.
OpenAI is also moving Codex users from full-access mode to auto-review, promising additional monitoring in the coming weeks and prioritizing alignment training for the next Daybreak releases. Their communication on this matter is notably straightforward.
“Models operating with reduced safeguards pose risks beyond standard model utilization, whether from misuse or misalignment.”
Why defenders desired this change
Other articles
OpenAI suspended a model due to cybersecurity concerns on Friday. By Monday, it released a new version that is trained to be less restrictive.
OpenAI launched GPT-5.6-Cyber via Daybreak, just three days after halting Astra due to significant cyber risks. It fulfills 95% of the requests that Sol denies.
