OpenAI has expanded its Daybreak programme for vetted cybersecurity defenders and launched GPT-5.6-Cyber, a specialised model trained to reduce refusals on advanced offensive security tasks.

Daybreak now offers two tiers. Daybreak Blue gives approved defenders access to the general-purpose GPT-5.6 Sol with standard safeguards relaxed for authorised work such as vulnerability discovery and incident response. Daybreak Red, aimed at advanced vulnerability research and exploit development, provides access to GPT-5.6-Cyber.

OpenAI said GPT-5.6-Cyber completes 95% of requests on an internal benchmark measuring willingness to assist with exploit-chain development, authentication bypass and privilege escalation scenarios, against 1.5% for standard GPT-5.6 Sol and 57.3% for the previous GPT-5.5-Cyber.

AI Contracts Decoded: What Fortune 500 Legal Veterans Know That You Don’t
When Microsoft refuses to negotiate indemnification with their biggest customers, what does that mean for your AI vendor contracts? When IBM data shows 97% of AI breaches stem from compliance failures—most being supply chain-related—who holds liability? When employees download shadow AI tools with zero cybersecurity controls, what recourse does your company have? None. Cathy Mulrow-Peattie brings perspective most outside counsel lack: Fortune 500 in-house experience at MasterCard and Omnicom, General Counsel at an AI startup, now advising enterprises. She starts with business goals before technology, technology before contracts—because she’s been in the hot seat when governance fails. You’ll learn: • Why 10-year AI contracts create risk and 90-day pilots with exit strategies are essential • The IP paradox: machine-generated outputs aren’t copyrightable but terms of use matter • How LLM providers retain “certain uses” of your data and when private instances become mandatory • Why contractual risk allocation to key vendors is your only viable strategy Key topics: Supply chain due diligence • The 97% compliance failure rate • Shadow AI liability traps • Benchmarking gaps • Hallucination disclaimers • GDPR/CCPA requirements • NY DFS Part 500 • Acceptable use policies • Dark web data sourcing • Evolutionary AI governance For: CISOs, CIOs, Chief Legal Officers, and compliance leaders navigating AI vendor relationships Contractual realities from someone who’s negotiated with Microsoft, advised Fortune 500s, and managed governance failures.

Using the new model, OpenAI researchers found two previously unknown vulnerabilities in Chrome's V8 JavaScript engine, since patched by Google and assigned CVE-2026-15903, alongside vulnerabilities in a mobile operating system, a widely used database and an operating system kernel.

Under OpenAI's Preparedness Framework, GPT-5.6-Cyber was assessed as High for cybersecurity capability, below the Critical threshold. OpenAI confirmed that GPT-5.6-Cyber played no role in the earlier Hugging Face security incident, and that no other models currently planned for release were involved either.

The company is requiring hardware security keys for all Daybreak accounts from 1 September 2026 and is pushing Codex users toward auto-review mode to limit destructive actions.


AI Contracts Decoded: What Fortune 500 Legal Veterans Know That You Don’t
When Microsoft refuses to negotiate indemnification with their biggest customers, what does that mean for your AI vendor contracts? When IBM data shows 97% of AI breaches stem from compliance failures—most being supply chain-related—who holds liability? When employees download shadow AI tools with zero cybersecurity controls, what recourse does your company have? None. Cathy Mulrow-Peattie brings perspective most outside counsel lack: Fortune 500 in-house experience at MasterCard and Omnicom, General Counsel at an AI startup, now advising enterprises. She starts with business goals before technology, technology before contracts—because she’s been in the hot seat when governance fails. You’ll learn: • Why 10-year AI contracts create risk and 90-day pilots with exit strategies are essential • The IP paradox: machine-generated outputs aren’t copyrightable but terms of use matter • How LLM providers retain “certain uses” of your data and when private instances become mandatory • Why contractual risk allocation to key vendors is your only viable strategy Key topics: Supply chain due diligence • The 97% compliance failure rate • Shadow AI liability traps • Benchmarking gaps • Hallucination disclaimers • GDPR/CCPA requirements • NY DFS Part 500 • Acceptable use policies • Dark web data sourcing • Evolutionary AI governance For: CISOs, CIOs, Chief Legal Officers, and compliance leaders navigating AI vendor relationships Contractual realities from someone who’s negotiated with Microsoft, advised Fortune 500s, and managed governance failures.
Share this post
The link has been copied!