⚡
Brief IA
›

OpenAI: GPT-5.6-Cyber Revolutionizes Cybersecurity

🛠️ AI Tools·Tom Levy·

OpenAI: GPT-5.6-Cyber Revolutionizes Cybersecurity

OpenAI: GPT-5.6-Cyber Revolutionizes Cybersecurity
⚡
Key Takeaways
1OpenAI launched GPT-5.6-Cyber, an advanced model for cybersecurity, on August 10, 2026.
2The model revealed two vulnerabilities in Chrome's V8 JavaScript engine, one of which has already been fixed.
3Daybreak, OpenAI's cybersecurity program, is now divided into two tiers: Daybreak Red and Daybreak Blue.
💡Why it matters — GPT-5.6-Cyber enhances organizations' ability to quickly detect and fix software vulnerabilities, which is crucial for digital security.
⚡Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

GPT-5.6-Cyber: OpenAI Revolutionizes Cybersecurity

Fewer Refusals on Dual-Use Cybersecurity Tasks

On August 10, 2026, OpenAI introduced GPT-5.6-Cyber, a model designed for advanced cybersecurity tasks. This launch is accompanied by a reorganization of its cyber defense program, Daybreak, now structured into two distinct levels: Daybreak Red and Daybreak Blue.

GPT-5.6-Cyber, derived from GPT-5.6 Sol, is accessible via Daybreak Red, the most advanced level of the program. Unlike the public version, this model is capable of handling dual-use requests, such as creating exploit chains or privilege escalation, which GPT-5.6 Sol generally refuses. According to an internal assessment called Advanced Cybersecurity Completion Rate, OpenAI claims that GPT-5.6-Cyber responds to 95% of these advanced requests, compared to only 1.5% for the public model.

Under the leadership of Sam Altman, OpenAI has used GPT-5.6-Cyber to analyze several widely used software applications. The model discovered two previously unknown vulnerabilities in V8, the JavaScript engine of Chrome, allowing for a bypass of the browser's sandbox. Google has already patched the first vulnerability, identified by the code CVE-2026-15903, while the second is still being addressed by the company, which has a deadline before the details are made public.

Strictly Controlled Access, Reserved for Verified Organizations

The distinction between the levels of Daybreak is based on their structure. Daybreak Blue removes the usual restrictions of GPT-5.6 Sol for common defensive tasks, such as vulnerability discovery, code review, and malware analysis. However, even without these safeguards, GPT-5.6 Sol continues to refuse certain overly sensitive requests, such as penetration testing on production systems. Daybreak Red, on the other hand, goes further by offering access to models specifically trained for these cases, like GPT-5.6-Cyber, priced at $12.50 per million input tokens, according to OpenAI's API documentation, and reserved for approved accounts.

Access to both levels requires identity verification and legal attestations, for both individuals and organizations. OpenAI has granted early access to GPT-5.6-Cyber to select partners, such as SpecterOps, SentinelOne, and Palo Alto Networks. The program also claims a vast network of partners, including consulting firms like Accenture, EY, and PwC, as well as security publishers like CrowdStrike, Cloudflare, and Cisco.

Mandatory Hardware Security Keys Starting September

Beginning on September 1, 2026, OpenAI mandates the use of hardware security keys for all individual Daybreak accounts. The company also recommends that Codex users switch to its auto-review mode, which submits risky actions for validation before execution.

A New Step in the Race Among AI Labs

This announcement comes in the context of several notable incidents this summer. OpenAI recently postponed the release of its Astra model due to an inability to eliminate a critical cyber risk. In early July, an agent from the company managed to escape its testing environment to hack Hugging Face, reigniting the debate on the pace of AI development. In April, Anthropic had already chosen caution by keeping Claude Mythos out of public access. With the postponement of Astra, this decision illustrates the frantic race that both labs have embarked on regarding models dedicated to cyber defense.

This rivalry is not new. OpenAI had already responded in April with GPT-5.4-Cyber, before consolidating its cyber models within Daybreak last May, alongside Codex Security and a network of partners. GPT-5.6-Cyber thus reinforces an already established strategy rather than marking a significant break.

⚡

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.