AI 安全與網路攻防
OpenAI Releases GPT‑5.6‑Cyber on a Limited Basis: High-Risk Request Completion Rate Rises From 1.5% to 95%
OpenAI has placed GPT‑5.6‑Cyber, a model designed specifically to reduce refusal rates in offensive security research, in the approval-gated Daybreak Red program rather than the general API. The company rates its cyber capabilities as High but not Critical, while the full system card has yet to be released.

OpenAI expanded Daybreak on August 10, dividing access to cybersecurity models into Blue and Red tiers. Blue gives approved defenders access to GPT‑5.6 Sol with some system-level safeguards removed. Red provides GPT‑5.6‑Cyber, a GPT‑5.6 Sol–based model retrained for zero-day vulnerability discovery, exploit-chain development, and exploit validation. This is the substantive follow-up to the recent suspension of Astra development after Critical cyber capabilities could not be ruled out: the new model has completed evaluation and is being deployed with restricted access, but it has not entered the general model catalog.
The most striking figures come from OpenAI’s internal Advanced Cybersecurity Completion Rate. The test covers dual-use requests involving authentication bypasses, privilege escalation, exploit chains, and related tasks. GPT‑5.6‑Cyber responded to 95.0% of them, compared with just 1.5% for GPT‑5.6 Sol, 2.0% for GPT‑5.6 Sol in the Daybreak Blue configuration, and 57.3% for the previous-generation GPT‑5.5‑Cyber. This metric measures whether the model completes high-risk requests; it does not measure the correctness of vulnerabilities or exploit code, and the higher completion rate may also come with greater token consumption.
The capability gains are uneven. OpenAI says the new model outperformed comparison models on ExploitGym and an internal zero-day dataset, but it underperformed GPT‑5.6 Sol on vulnerability discovery and report-writing evaluations, possibly because its reports were shorter. Sol also achieved the best result under ExploitBench’s standard 300-round configuration. The company additionally disclosed that the model found two V8 issues that could be chained together, one of which—CVE-2026-15903—was fixed in Chrome 150.0.7871.128. Chrome’s advisory confirms that the out-of-bounds read/write issue was reported by OpenAI Codex Security, while the NVD records a CISA-ADP score of 8.8.
OpenAI classifies the model’s cyber capabilities as High but not Critical, and restricts Red access through identity verification, hardware security keys, usage monitoring, and legal attestations. For defensive teams, the key change is that the model can handle real-world exploit research that previous systems would refuse. However, its internal benchmarks, the still-unreleased system card, and its performance in unfamiliar sandboxes and during long-running agentic operations remain areas that teams must either wait for OpenAI to document or validate independently before deployment.