Three days after pausing its forthcoming Astra model over a possible 'Critical' cybersecurity rating, OpenAI on August 10 announced GPT-5.6-Cyber and split its Daybreak program into two tiers, a sequence the company says is consistent but that critics are reading as an uneasy balancing act. OpenAI split its cybersecurity program into two access tiers and released a new purpose-trained model alongside them on August 10, 2026. Daybreak Blue opens frontier general-purpose models, including GPT-5.6 Sol, to approved defenders for everyday security work, while Daybreak Red gates the new GPT-5.6-Cyber model behind tighter vetting for vulnerability research, exploit validation, and security testing. The division resolves a practical frustration OpenAI had acknowledged for months: many cyber defenders have been experiencing high refusal rates across frontier AI models as the labs try to balance giving defenders the tools they need while not accidentally leaking those abilities to malicious hackers.
The model's most consequential disclosure came before its announcement. OpenAI used GPT-5.6-Cyber to investigate V8, the JavaScript engine used by Chrome, uncovered two previously unknown vulnerabilities that could be chained to corrupt memory and escape the V8 heap sandbox, validated the findings, reported them to Google through coordinated vulnerability disclosure, and Google fixed the vulnerability, assigning it CVE-2026-15903. The vulnerability involved an optimizing compiler error that skipped a safety check during integer conversion. The Chrome findings were not isolated: the model has also been credited with finding at least five vulnerabilities in a popular mobile operating system, three critical flaws in a widely used database, and over 400 privilege-escalation issues in a popular operating system kernel, with disclosures ongoing. On benchmarks, GPT-5.6-Cyber answered 95.0 percent of prompts on OpenAI's Advanced Cybersecurity Completion Rate benchmark, compared with the consumer build of GPT-5.6 Sol, which answered 1.5 percent, while defenders receiving a loosened Sol through Daybreak Blue saw 2 percent.
The single fact that allowed the launch to proceed is the rating. Under OpenAI's Preparedness Framework, both GPT-5.6 Sol and GPT-5.6-Cyber were assessed as High for cybersecurity capability and below the Critical threshold. High means the model can ship, but only with safeguards that sufficiently minimize the associated risk of severe harm before deployment; Critical means development itself pauses until Critical-standard safeguards exist. Under the framework, a model reaches Critical if it can independently develop zero-day exploits against hardened real-world systems without human intervention, or devise and execute novel cyberattack strategies given only a high-level goal. Early adopters have reported tangible gains: security firm SpecterOps has already reported significant workflow acceleration, with CTO Jared Atkinson noting the model resolved specialist vulnerability-research work in under a day that had previously taken weeks.
Skeptics, however, are not fully satisfied by the framework's arithmetic. The dual announcements underscore a tension building across frontier AI labs: models are becoming powerful enough to chain together exploits, escape test environments, and attack live systems, while the very same capabilities are desperately needed by defenders trying to secure code against increasingly sophisticated threats. The access controls are strict but not unprecedented: to mitigate misuse risks, OpenAI is mandating hardware security keys for all individual Daybreak accounts starting September 1, 2026, and access to Daybreak Blue and Red is restricted to approved individuals and organizations conducting authorized security work, gated by identity verification, monitoring, and legal attestations. A partner program covers 16 cybersecurity providers, including IBM, CrowdStrike, Accenture, Cisco, and Cloudflare. OpenAI also noted that pricing for GPT-5.6-Cyber stands at $12.50 per million input tokens and $75 per million output tokens.
A model that finds Chrome zero-days before its own launch announcement is a useful defender's tool and a precise demonstration of exactly why Astra is still grounded.