- OpenAI is widening access to cyber AI models with safeguards.
- Astra is under tighter controls as OpenAI assesses its cyber risks.
OpenAI is expanding access to its most capable cybersecurity models through a network of security vendors and professional services firms, giving approved partners access to tools designed for vulnerability discovery, testing, incident response, and remediation.
The expansion comes as OpenAI separately evaluates whether its upcoming Astra model has reached a level of cybersecurity capability that requires stronger controls. Preliminary testing indicates Astra may be capable of performing increasingly sophisticated cyber tasks autonomously.
Under the Daybreak Cyber Partner Program, OpenAI is working with companies including Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps. Technology partners include Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare.
Approved partners can incorporate OpenAI’s cyber models into security products, managed services, and customer engagements. OpenAI said the models can support work including vulnerability discovery and validation, red teaming, penetration testing, incident response, and remediation.
Controlled access for cyber defence
Access to the underlying models remains with approved security providers rather than being transferred directly to customers. OpenAI said organisations and security practitioners using Daybreak must own, operate, or have permission to test the systems involved, while more sensitive capabilities require additional approval and verification.
OpenAI said safeguards designed to block malicious cyber requests can also restrict legitimate security research because activities such as vulnerability discovery and exploit development can have both defensive and offensive uses. Daybreak gives approved practitioners access under controls that can include identity verification, account security requirements, restricted testing scopes, activity logging, monitoring, approved-use restrictions, and human review.
OpenAI offers two levels of access through the programme. Daybreak Blue uses GPT-5.6 Sol for defensive tasks such as vulnerability triage, secure code review, malware analysis, detection engineering, incident response, and patch validation.
Daybreak Red requires further approval and provides access to GPT-5.6 Cyber for more sensitive work, including penetration testing, red teaming, exploit validation, exploit development, and controlled vulnerability research. OpenAI said GPT-5.6 Cyber was trained specifically to improve performance on specialised security tasks, including identifying previously unknown vulnerabilities and developing exploit chains.
OpenAI said partners can use the models to find vulnerabilities, assess whether they are exploitable, identify affected systems, and support remediation.
OpenAI has tested its specialised cyber models against production software. Researchers using GPT-5.6 Cyber identified two previously unknown vulnerabilities in V8, the JavaScript engine used by Google Chrome, which OpenAI said could be chained together to escape the engine’s heap sandbox.
OpenAI validated the findings and reported them to Google through coordinated vulnerability disclosure. One of the vulnerabilities was assigned CVE-2026-15903, while the second remained under disclosure when OpenAI published details of the work.
OpenAI has also used AI-assisted security research across open-source software. The company said Daybreak-related work has covered 41 open-source projects, identified 858 issues, and produced 263 patches, with 143 accepted upstream by project maintainers.
Several programme participants are also examining how the models can be incorporated into existing security platforms and managed services. IBM is combining the models with its Autonomous Security capabilities, while Cisco is exploring their use for vulnerability triage across its security products and services.
Mark Hughes, global managing partner for cybersecurity services at IBM Consulting, said the work includes identifying and prioritising vulnerabilities.
“By combining OpenAI’s advanced cyber models with IBM’s Autonomous Security capabilities, we help organisations find and prioritise vulnerabilities that matter most,” Hughes said.
Cisco is exploring how the models can be integrated with its platforms and services. CrowdStrike is pairing them with its security data and threat intelligence for red teaming and vulnerability testing.
“OpenAI’s advanced cyber models fundamentally change how we think about vulnerability triage,” DJ Sampath, senior vice president and general manager of AI Software and Platform at Cisco, said. “We’re exploring how to integrate these capabilities with our platforms and services to help organisations act faster on what matters,” Sampath said.
Palo Alto Networks is also integrating OpenAI’s models with its security platforms, while PwC plans to use them within managed cyber defence services and governed security workflows.
Astra raises the capability threshold
OpenAI has assessed GPT-5.6 Sol and GPT-5.6 Cyber at the “High” cybersecurity threshold under its Preparedness Framework, rather than the higher “Critical” level. Models classified at the High level require safeguards before deployment, while a Critical classification triggers additional safeguards during development.
OpenAI said on August 7 that it could not rule out Astra reaching a “Critical” cybersecurity capability level under its internal safety framework. The company said preliminary evaluations, together with assessments from external experts, showed sufficiently strong performance that the higher classification could not yet be excluded.
Under OpenAI’s Preparedness Framework, the Critical cyber threshold includes systems capable of autonomously developing functional zero-day exploits against hardened real-world critical systems. It also covers models capable of devising and executing an end-to-end novel cyberattack against a hardened target after receiving only a high-level objective.
OpenAI responded by strengthening security requirements around Astra and pausing internal activities that did not meet the revised controls. Development has moved into isolated testing environments with restricted network and tool access, stronger protections and encryption for model weights, additional monitoring, and sandboxed execution.
OpenAI is also working with government agencies and selected AI safety organisations to evaluate the model.
The Astra assessment follows incidents involving autonomous AI agents during cybersecurity testing. OpenAI has been investigating cases in which agents escaped their intended containment environments, including after a security incident involving AI platform Hugging Face.
OpenAI, Anthropic, and Meta have also disclosed incidents in which AI systems accessed other companies’ systems during cybersecurity testing. OpenAI said Astra was not involved in the Hugging Face incident.
Despite the additional controls, OpenAI has indicated that it intends to make Astra more broadly available if its safety requirements can be met. CEO Sam Altman said OpenAI does not consider keeping powerful models restricted to a small number of users to be a good strategy.
Daybreak follows a more restricted access structure, with organisations generally receiving the cyber capabilities through approved partners rather than gaining direct access to the underlying models. OpenAI said partners define the scope of each engagement, review findings, and apply human oversight before action is taken.
Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events, click here for more information.
Tech Wire Asia is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
The post OpenAI expands access to cyber AI models with tighter safeguards appeared first on TechWire Asia.
