OpenAI built a model to find zero-days, and made you apply to use it
The same model, asked the same questions, went from completing 1.5% of offensive security tasks to 95%. The difference was training it to.
GPT-5.6-Cyber is built on GPT-5.6 Sol and trained specifically for finding zero-day vulnerabilities and building exploit chains. On OpenAI's own testing it completes 95% of prompts involving exploit chain development, privilege escalation and authentication bypass, against 1.5% for Sol. It is available only through Daybreak Red, the applicant-vetted tier of OpenAI's defender programme, alongside a Daybreak Blue tier giving general models guardrails tuned for defensive work.
Why this one is different
This is the first of the three gates, and the pattern it started is now the industry's actual cyber policy. Anthropic followed on 1 September with Mythos 5.1 and Project Glasswing, Google on the 2nd with Fairwind. Three labs, twenty three days, three separate application processes and no shared standard for who qualifies.
Three labs, twenty three days, and no shared standard for who qualifies.
How we got here
- 2024 to 2025Labs refuse offensive security requests broadly, which frustrates legitimate researchers and stops very little else.
- 10 Aug 2026OpenAI ships a model trained for it, behind Daybreak Red.
- 1 Sep 2026Anthropic's Mythos 5.1 removes classifiers for vetted US organisations under Project Glasswing.
- 2 Sep 2026Google's 3.8 Flash Cyber goes to trusted defenders through the Fairwind Program.
What it does and does not mean
A 95% completion rate is a capability measurement, not a safety one. It says the model is good at this, and says nothing about whether the vetting works, how it is audited, or what happens when an approved account is compromised. Nor does the gate stop an adversary with resources from training their own. What the release established is the governing mechanism for frontier cyber capability, and it is a vendor's application form.