← All posts

OpenAI built a hacking model. You have to apply to use it

2026-08-15 · 4 min read

On Monday, August 10, @OpenAI announced GPT-5.6-Cyber, a model trained specifically for offensive security work, along with an expansion of its Daybreak cybersecurity program. The company framed it as "putting frontier intelligence in the hands of trusted defenders" before attackers can field the same thing. President Greg Brockman echoed the launch minutes later, and OpenAI researcher @Eric_Wallace_ was blunter about what is under the hood: this is the company's first large-scale attempt to directly improve capabilities like exploit development, and he called it "really quite strong for accelerating defensive work."

Read that again. OpenAI spent years training models to refuse this exact category of request. Now it has trained one to say yes, and the product is deciding who gets to ask.

How Daybreak works

The program has two tiers. Daybreak Blue is the entry point: frontier models with safeguards tuned for defensive work like incident response, malware analysis and patch validation. Daybreak Red is where GPT-5.6-Cyber lives, aimed at vulnerability research, exploit validation and authorized security testing.

Red is not something you sign up for with a credit card. There is no public API model ID. Access requires identity verification and attestations about how you will use it, and starting September 1 a hardware security key becomes mandatory. TechCrunch reports the early partners include Accenture, IBM, CrowdStrike and Cloudflare. OpenAI has published no pricing and, as of this writing, no system card.

The model has receipts. OpenAI says it used GPT-5.6-Cyber in its own research and found two previously unknown vulnerabilities in Chrome's V8 engine that could be chained into memory corruption. One of them now has a CVE. Coverage of the launch also credits the model with surfacing more than 400 privilege-escalation flaws across various systems.

The number that tells the real story

The headline benchmark is something OpenAI calls the Advanced Cybersecurity Completion Rate. Standard GPT-5.6 Sol completes 1.5 percent of advanced cyber tasks. Daybreak Blue manages 2 percent. GPT-5.6-Cyber completes 95 percent.

That looks like a capability leap until you notice what the metric measures: whether the model answers at all. It is mostly a refusal rate turned upside down. And on OpenAI's separate vulnerability discovery evaluation, the ordinary general-purpose model actually scored better than the specialized one.

So the honest description of this product is not "a smarter hacker." It is closer to "the intelligence that was already there, with the guardrails removed for people who pass a background check." That is a genuinely new kind of product. The scarce thing OpenAI is selling is permission, and it has just appointed itself the registrar of who counts as a trusted defender. Whether one vendor should hold that list is a fair question. Nobody else is volunteering to hold it either.

Why now

The timing is not subtle. The last two months have produced a steady drip of AI-driven incidents, including an OpenAI agent that compromised Hugging Face and an agent that invented fake people to social-engineer a real developer. OpenAI's own announcement says threat actors will increasingly use AI to run attacks at speed and scale. The labs are telling us, plainly, that the offense is coming from their technology, and the defense will be a subscription.

Some skeptics noted that warning about AI attacks while selling AI defense is a comfortable position for an AI company. True. It does not make the warning wrong.

What this means if you run a normal business

You will never touch Daybreak Red, and you do not need to. What matters for a small company in the Fox Valley is what this launch implies: the cost of finding a way into systems is dropping fast, and the attacks that reach you will be automated, plausible and cheap. Think phishing emails written well, fake invoices that match your vendor's formatting, credential stuffing that never gets tired.

The defense at our scale is not a frontier model. It is the unglamorous stuff done consistently: multi-factor authentication everywhere, software that actually gets updated, and a written rule that nobody changes payment details on the strength of one email. If you have added AI tools to your own workflows this year, those are part of your attack surface now too, and most owners have never looked at them that way.

That last part is exactly what our free process audit covers. We map where AI and automation already sit in your operation, what they can reach, and which gaps an attacker armed with tools like these would find first.

08 / Start here

Find your worst bottleneck. Free.

A 20 minute call. We map where your week goes and pick out the first process worth automating. You keep the map either way, and there is no deck to sit through at the end.

Email

pgorski@newfacedesign.com

Phone

+1 (773) 627-2176

Based in

Chicago area

Working with clients everywhere