As AI-led attacks multiply, OpenAI launches a new cyber model
Every day seems to brings fresh news of an AI agent going “rogue.” Whether that’s compromising Hugging Face, hacking a gym website, or creating its own fake profiles to socially engineer an intrusion, AI models are increasingly behaving like bad actors.
So, the AI labs that make the models doing the hacking are expanding their cyber protection offerings. This week, OpenAI announced an expansion of Daybreak, its cyber defense service which it launched earlier this year, not long after Anthropic released its cyber-focused model Mythos.
Daybreak is a service that bundles access to models, tools and workflows for defenders. The expansion includes access to a brand new cyber-focused model designed for defensive work.
OpenAI said Monday that Daybreak would now consist of two tiers: Blue and Red. Both of these tiers will allow approved customers access to OpenAI’s limited-access frontier cyber models. Frontier models — the most advanced available — have been a subject of controversy. The Trump administration previously sought to collaborate with AI companies on the roll out of such models, purportedly over safety concerns. Previously, OpenAI deployed significant guardrails to using these models, limiting what customers could do with them.
Blue, which appears to be the more basic of the two, offers a variety of cyber services, including incident response, malware analysis, and patch validation. OpenAI calls Blue its “recommended starting point for most defenders,” implying that it should be more than enough for most enterprises.
Red, on the other hand, offers a broader and potentially more dangerous toolkit. The company grants its users “purpose-trained cybersecurity models,” designed to carry out security testing and vulnerability research.
With Red also comes the new model, GPT‑5.6‑Cyber, which is only available at that tier. 5.6-Cyber is built off of GPT‑5.6 Sol, and offers enhanced capabilities for certain specialized cybersecurity tasks, the company said.
At the moment, GPT‑5.6‑Cyber is only being made available for “trusted customer partners,” including reportedly Accenture, IBM, Crowdstrike, Cloudflare, and others.
While the threats from AI agents are rapidly increasing, critics have also pointed out that they function as marketing opportunities for the AI labs. OpenAI is certainly marketing its upgraded Daybreak that way.
“The cybersecurity world is rapidly changing—threat actors will increasingly use AI to conduct cyberattacks at unprecedented speed and scale, including in fully autonomous ways,” the company said in a blog post. “As these capabilities spread, defenders have a narrowing window to prepare.”
At the same time, enterprises remain interested in buying their protection from the AI labs who know the security risks best, because they know them first-hand.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

