OpenAI on Monday released GPT-5.6-Cyber, a purpose-trained offensive-security model gated to a hand-picked list of defenders, and simultaneously disclosed that a more powerful model, Astra, was paused last week after crossing the “Critical” cyber-capability tier of its Preparedness Framework. GPT-5.6-Cyber is, per Axios, the first OpenAI system to hit the framework’s “High” threshold. Its predecessor didn’t cross it. Its successor crossed the next one and got shelved.

The internal benchmark numbers make the tiering legible. Built on GPT-5.6 Sol, the cyber variant responds to 95.0 percent of advanced offensive-security prompts on OpenAI’s own evaluation. The base Sol model answers 1.5 percent. Daybreak Blue, the loosened-guardrails tier, sits at 2.0 percent. That gap is the entire product.

The Daybreak partner program, previously a single track, now splits into Blue, which serves GPT-5.6 Sol with “system-level cyber guardrails lifted for authorized defensive work,” and Red, which serves GPT-5.6-Cyber for exploit validation and vulnerability research. BleepingComputer reports approved partners include Accenture, IBM, CrowdStrike, Cisco, Palo Alto Networks and Cloudflare. Individual Daybreak accounts must adopt hardware security keys by September 1.

As proof of concept, OpenAI says it turned the model on Google’s V8 JavaScript engine and surfaced two previously unknown flaws that could be chained to corrupt memory and escape the heap sandbox. Google patched the chain as CVE-2026-15903.

OpenAI’s framing is that “the window for AI-assisted cyber defense was narrowing,” which is true and also happens to justify a permissioned distribution model that concentrates frontier offensive capability inside a handful of incumbent vendors. The Astra pause is the tell: capability the lab itself won’t ship, released selectively one tier down, to the firms already holding the enterprise security budget.

Sources