Will it run?
Security

OpenAI expands Daybreak service and unveils dedicated cyber model

By Desmond Okafor Clawpit staff
OpenAI expands Daybreak service and unveils dedicated cyber model

AI agents losing control have become routine over the past year. Incidents such as a breach of the Hugging Face platform, an attack on a gym-chain website, and the creation of fake profiles for social engineering illustrate how models are increasingly behaving like malicious actors. In response, the AI labs that produce the attacking models are expanding their defensive services. This week OpenAI announced an expansion of Daybreak, the defensive service launched earlier this year, shortly after Anthropic released its cyber-focused model Mythos.

Daybreak aggregates access to models, tools and workflows for protecting systems. OpenAI said on Monday that the service will be divided into two tiers: Blue and Red. Both will give approved customers limited access to advanced cyber models that remain contested. The Trump administration previously attempted to work with AI firms on launching such models, ostensibly for safety. In the past OpenAI imposed significant restrictions on the use of those models and limited what customers could do with them.

The Blue tier appears basic and offers a range of cyber services, including incident response, malware analysis and patch verification. OpenAI calls Blue the recommended starting point for most defenders, implying it should meet the needs of most organizations. The Red tier, by contrast, provides a broader toolkit with higher risk potential. It gives users purpose-trained security models intended for security testing and vulnerability research. Red also includes the new model GPT-5.6-Cyber, available only at this tier. The model builds on GPT-5.6 Sol and, according to the company, offers enhanced capabilities for certain specialized cyber tasks.

Currently GPT-5.6-Cyber is available only to trusted partner customers, reported to include Accenture, IBM, Crowdstrike and Cloudflare. While threats from AI agents are rising rapidly, critics have noted that the offerings also serve as marketing opportunities for AI labs. OpenAI indeed markets the Daybreak upgrade in that direction. The company said in a blog post that the information-security landscape is changing quickly and that malicious actors will use AI to launch cyber attacks at unprecedented speed and scale, including fully autonomous operations. It added that as these capabilities spread, the window for defenders to prepare shrinks. At the same time, organizations still prefer protection from AI labs that understand security risks well because they encounter them first and directly.