GPT-5.6 Cyber
GPT-5.6 Cyber (OpenAI, August 10, 2026): what the release is, why it matters for operators, specs, benchmarks, and the call.

Audience and scope
Audience: ABS readers who follow frontier AI releases and want a clear-eyed read on a model that’s reshaping professional cybersecurity, not a how-to for getting access. Not for: Security researchers shopping for credentials (this won’t help you apply), defenders who think AI red teaming replaces patching, or anyone looking for a model to drop into a normal ChatGPT or API workflow. Last verified: 2026-08-12 Evidence weight: documentation-verified (OpenAI launch post, OpenAI model card, Axios, VentureBeat, AWS ML blog, The Hacker News).
Release, and why you can’t just buy it
GPT-5.6 Cyber dropped on August 10, 2026, announced on OpenAI’s own news index under the title “Expanding Daybreak as the Cyber Defense Window Narrows.” It is a fine-tune of GPT-5.6 Sol (the June 2026 general model), and the third generation of OpenAI’s “Cyber” line — after GPT-5.4-Cyber (April) and GPT-5.5-Cyber (May). The single most important fact about this model: you cannot buy it on ChatGPT or call it through OpenAI’s public API. It only ships through a vetted, application-only program called Daybreak Red, paired for broader defensive use with a sister tier called Daybreak Blue that grants GPT-5.6 Sol with cyber guardrails lifted. OpenAI frames the whole release as a “narrowing window” argument — adversaries are about to weaponize AI for autonomous, large-scale cyberattacks, so defenders need a tool that will actually answer the offensive questions they need answered (reproduce an attack, validate a vendor’s patch, study captured malware) before the bad guys build their own version. The lock-down is the product: identity verification, hardware security keys (required for individual accounts starting September 1, 2026), usage monitoring, legal attestations, and partner vetting. Verbatim from the launch post: “We’re also introducing GPT‑5.6‑Cyber, available through Daybreak Red. Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-risk, dual-use cyber tasks.” ---
Specs that matter for an ABS reader
- Base model: GPT-5.6 Sol fine-tune, “Highest” reasoning level. OpenAI notes Cyber “tends to be more extensive and comprehensive than GPT-5.6 Sol in its reasoning budget, leading to higher token usage.” - Context window: 400,000 tokens input; 128,000 max output. Knowledge cutoff February 16, 2026. Text in/out plus image input — no audio or video. - Pricing (Daybreak Red approval, API only): $12.50 / $1.25 / $75 per million tokens (input / cached input / output). That’s roughly 2.5× the cost of GPT-5.6 Sol ($5 in / $30 out) and 5× GPT-5.4 ($2.50 in). - Long-prompt surcharge: Prompts over 272K tokens are billed at 2× input and 1.5× output for the entire request. - Hosting: Direct API plus Amazon Bedrock (US East / N. Virginia), with zero-operator-access inference, customer-managed KMS keys, and no training on customer data. The pricing and the long-prompt surcharge are the bits that bite. A defender running a 300K-token reverse-engineering session over Cyber pays more than twice what the same prompt would cost on Sol, before counting the longer reasoning budget on top. ---
Benchmarks — and one important asterisk
OpenAI’s headline number is the Advanced Cybersecurity Completion Rate, an internal eval covering exploit-chain development, authentication bypass, and privilege escalation: | Model | Completion rate | |---|---| | GPT-5.6 Sol (default ChatGPT, safeguards on) | 1.5% | | GPT-5.6 Sol via Daybreak Blue | 2.0% | | GPT-5.5-Cyber via Daybreak Red (previous gen) | 57.3% | | GPT-5.6-Cyber via Daybreak Red | 95.0% | Verbatim from OpenAI: “GPT‑5.6‑Cyber completes 95.0% of these requests, compared with just 1.5% for GPT‑5.6 Sol, and 2.0% when used with Daybreak Blue access.” On ExploitGym (intended vulnerability → working exploit) and the internal Zero-Day Discovery eval, Cyber also outperforms both Sol and 5.5-Cyber. But here’s the asterisk: specialization has a ceiling. On OpenAI’s own Vulnerability Discovery & Report Writing eval, GPT-5.6 Sol actually wins — Cyber’s reports are “sometimes shorter, less detailed.” On ExploitBench at 300 turns with sandbox on, Sol (Daybreak Blue) is more token-efficient and wins; the gap narrows by 600 turns. This is not a strict upgrade over Sol — it’s a specialization that wins on its target tasks and loses on adjacent ones. The real-world signal is also strong. OpenAI used GPT-5.6-Cyber to find two previously unknown V8 (Chrome JavaScript engine) vulnerabilities that chained into a heap-sandbox escape, reported to Google and patched as CVE-2026-15903 — one of only four successful zero-day entries to V8 CTF in 2026. The same model also surfaced 5+ vulnerabilities in a popular mobile OS (chain to local priv-esc), 3 critical vulns in a popular database (RCE), and 400+ priv-esc bugs in a popular OS kernel. ---
Strengths
- Refusal rate collapsed from ~98.5% to ~5% on legitimate advanced cyber requests — the model actually does the job it was built for, which is the whole point. - Real-world zero-day production, not just benchmark theatre. CVE-2026-15903 plus hundreds of unreleased vulns across mobile OS, database, and OS kernel give defenders a track record benchmarks alone can’t show. - 400K-token context window is needed to reason across large unfamiliar codebases during vulnerability research. - Tight access architecture (identity verification, hardware-key MFA, monitoring, legal attestations, partner vetting) reads as a feature for any security-conscious enterprise that wants frontier cyber capability without a frontier cyber leak.
Weaknesses and risks
- Specialization has a ceiling. Sol beats Cyber on report-writing and token efficiency at short horizons. Cyber is a specialist, not a strict upgrade. - Token cost is roughly 2.5× Sol’s, plus a higher reasoning budget. Power tools, but the meter runs fast. - Single leaked identity = offensive capability. The whole program assumes access controls hold. One compromised user (insider, stolen hardware key, account takeover) and the bad guys get a frontier cyber model. Sam Sabin at Axios framed the release against the backdrop of the July 2026 Hugging Face breach — caused by an earlier internal model, not Cyber, but the narrative is unmistakable: the guardrail is increasingly around the model. - Optics baggage. This lands two weeks after the disclosed Hugging Face breach and days after OpenAI delayed its more capable “Astra” model over cyber-risk concerns. Cyber only reached the “High” cyber capability threshold under OpenAI’s Preparedness Framework — short of “Critical” — which is exactly the band OpenAI is willing to ship behind Daybreak Red and not the band they’re willing to ship behind Daybreak Blue. - Partner concentration risk. Accenture, IBM, CrowdStrike, Cisco, Palo Alto Networks, Cloudflare, SentinelOne, Snyk, and Intel are the named Daybreak Cyber Partners. If you ever pay a third-party pen-test or IR firm, expect them to be running (or comparing against) GPT-5.6-Cyber within months — and pricing to drift down. ---
The operator call
For most ABS readers — e-commerce operators, SMB owners, solo founders — this is a watching model, not
Sources
- OpenAI — Expanding Daybreak as the Cyber Defense Window Narrows — primary launch post; 95% / 1.5% benchmark numbers, V8 / CVE-2026-15903 disclosure, SpecterOps quote.
- Axios — OpenAI gives cyber defenders a less-restricted new model — Daybreak Blue vs. Red tiers, partner list, Astra delay, Hugging Face context.
- VentureBeat — OpenAI launches GPT-5.6-Cyber with reduced refusals, 95% completion — pricing ($12.50 / $1.25 / $75), qualifying criteria, Cyber line history.
- The Hacker News — OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards — trade-press framing of reduced safeguards and dual-use positioning.
- AWS — Daybreak Red & Daybreak Blue on Amazon Bedrock — Bedrock availability, zero-operator-access inference, customer-managed KMS.
- OpenAI API model card — GPT-5.6-Cyber — exact specs (400K context, 128K max output, Feb 16 2026 cutoff, pricing, Daybreak application).
Sources
- OpenAI — Expanding Daybreak as the Cyber Defense Window Narrows
- Axios — OpenAI gives cyber defenders a less-restricted new model
- VentureBeat — OpenAI launches GPT-5.6-Cyber with reduced refusals, 95% completion
- The Hacker News — OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards
- AWS — Daybreak Red & Daybreak Blue on Amazon Bedrock
- OpenAI API model card — GPT-5.6-Cyber



Submit a take
Have a different read on this? Drop a comment below — your email isn't published, and I read every one. Nothing leaves the site until I approve it.