Skip to content
Beveiligingsnieuws

GPT-5.6-Cyber: new AI model for cybersecurity

GPT-5.6-Cyber

OpenAI has announced a new AI model focused on cybersecurity: GPT-5.6-Cyber. The model is intended for “advanced, authorized cybersecurity work” and is designed to help researchers with specialized tasks, such as identifying vulnerabilities and building exploit chains. At the same time, OpenAI wants to limit the model’s use to prevent misuse by organizing access only through trusted partners.

According to OpenAI, earlier versions often refused dual-use requests more frequently—questions that can be legitimate as well as harmful. GPT-5.6-Cyber, therefore, is specifically aimed at reducing those blockades. In this article, we lay out the key features, the underlying rationale, and the potential impact on the security landscape.

Why GPT-5.6-Cyber was developed

OpenAI explains that the model is built on GPT-5.6-Sol. That foundation is already “high-quality,” but OpenAI says that a relatively high refusal rate creates problems when security teams want to run penetration tests in production-like environments and when prompts fall under dual-use cybersecurity. In practice, such dual-use requests can range from defensive analysis to steps that could also be exploited for harm.

So the goal of GPT-5.6-Cyber is twofold: better results for authorized security research and less real-world friction caused by refusals. OpenAI links this to feedback from security researchers who reported persistent “refusals” with the earlier models.

More completion on exploit chains and escalation

OpenAI says internal tests show a clear improvement. In prompts related to exploit chain development, privilege escalation, and authentication bypass, GPT-5.6-Cyber would achieve a 95% completion score. As a comparison, OpenAI cites only 1.5% for GPT-5.6-Sol in the same category of prompts.

OpenAI also compares GPT-5.6-Cyber with GPT-5.5-Cyber. The earlier model would, according to OpenAI, complete only 57.3% of requests. By doing so, the vendor argues, GPT-5.6-Cyber helps teams work through the kind of red-teaming or assessment tasks researchers need—so long as the use is authorized and within appropriate boundaries.

Authorization, lower refusals, and dual-use risk

One notable detail is the combination of “risky dual-use tasks” and a lower refusal ratio. With this, OpenAI indicates that GPT-5.6-Cyber is configured differently from the general variant. The model was developed for advanced security work, but the setup remains geared toward controlled use.

The core remains the same: certain prompts can serve both defense and attacks. OpenAI tries to manage that tension by not making the model broadly available, but instead routing it through a partner program.

What GPT-5.6-Cyber found (according to OpenAI)

According to OpenAI, GPT-5.6-Cyber produced indications of security issues during tests. The reporting says the model would have discovered a high-severity vulnerability in the V8 JavaScript engine used by Chrome.

In addition, there would have been findings in a mobile operating system (without naming which one), a database, and the kernel of an operating system. The exact CVEs or technical details are not specified in the source, but it emphasizes that the model was tested at the level of vulnerability detection and assessment.

Performance in exploit development and vulnerability analysis

OpenAI claims GPT-5.6-Cyber performs strongly in areas such as:

  • developing arbitrary code execution exploits
  • finding and evaluating known vulnerabilities
  • identifying new zero-days

In practice, this means the model is designed not only to provide conceptual guidance, but also to be usable for step-by-step security tasks—provided it falls under “authorized” use.

Daybreak: access through trusted partners

To prevent misuse, OpenAI announces that GPT-5.6-Cyber will be available only through trusted partners as part of the Daybreak Cyber Partner program.

Daybreak enables organizations to build and resell cybersecurity solutions, using OpenAI’s AI. With the latest announcement, OpenAI adds two levels of access:

  • Daybreak Blue: access to Sol and other general frontier models, with “guardrails” tailored to defensive cybersecurity activities.
  • Daybreak Red: access to cybersecurity models, including the new GPT-5.6-Cyber.

In this way, OpenAI makes a clear separation between broader defensive use cases and the more riskier security ecosystem in which models like GPT-5.6-Cyber are categorized.

A broader trend: cyber AI becoming more autonomous

The introduction of GPT-5.6-Cyber doesn’t come in isolation from other concerns in the field. In the days leading up to this announcement, OpenAI—according to the reporting—pointed to a coming model Astra that may reach a ‘critical’ cybersecurity risk threshold.

If a model reaches that “critical” status, it could independently build zero-day exploits and design and carry out end-to-end cyberattacks based solely on a high-level goal. Such claims tie into earlier incidents where cybersecurity models, in test environments, could have compromised real organizations.

If you want to include this context, the following read also fits your knowledge base: Astra-model: concerns about autonomous cyberattacks. That article looks at what can go wrong once AI is less of an assistant and moves further toward autonomous execution.

What this means for security teams

For defenders and security engineers, GPT-5.6-Cyber is especially relevant as a signal: OpenAI is aiming for better usability of AI in authorized research, including exploit chains, privilege escalation, and bypass scenarios. This could help security teams validate faster, prioritize better, and reach more reproducible analyses more quickly.

At the same time, this requires strong governance. Not only because the model runs through Daybreak and partner routes, but also because deployments of such AI should ideally be tied to test and authorization procedures. Think bounded environments, logging, approved targets, and clear rules on what is and isn’t allowed.

Want to know how researchers and platforms handle the risk of vulnerabilities and exploit chains across the broader AI and security domain? Read also: AI attacks, Metabase 0-day, and backdoors. This helps you see the difference between “AI for defense” and AI that can instead amplify misuse signals.

Practical points to keep in mind when working with models like this

Even though GPT-5.6-Cyber is intended for authorized cybersecurity work, security teams are still wise to follow a few consistent steps when using it:

  • Work with defined targets: decide in advance what you will test and which systems are in scope (and out of scope).
  • Limit scope and data: avoid unnecessary exposure of sensitive information.
  • Use validation: always have outputs reviewed by human experts and through technical checks.
  • Record decisions: document prompts, intent, and next steps for auditability.

By applying frameworks like these, you can benefit from better completion rates and faster security workflows—without automatically accepting all risks that come with dual-use prompts.

Conclusion

GPT-5.6-Cyber, according to OpenAI, is a step toward AI that fits better with authorized cybersecurity research. Where GPT-5.6-Sol often refused dual-use-like security prompts, GPT-5.6-Cyber should deliver higher completion scores—especially for exploit chains, privilege escalation, and authentication bypass.

OpenAI also emphasizes that access runs through the Daybreak partner program, with a clear separation between defensive and cybersecurity models. For security teams, this could mean more efficiency in assessments—while also providing an additional reason to take governance, scoping, and validation seriously.

Source: https://www.securityweek.com/openai-unveils-new-cybersecurity-model-gpt-5-6-cyber/