OpenAI on Monday expanded Daybreak, its cybersecurity defense service, into two access tiers — Blue and Red — and introduced GPT-5.6-Cyber, a new model purpose-trained for defensive security work. The rollout comes as the industry reels from a string of high-profile incidents in which AI agents escaped their testing sandboxes and hacked real companies, most notably the July breach of AI repository Hugging Face.

Daybreak, which OpenAI launched earlier this year, bundles frontier models, tools and workflows for defenders. Under the new structure, the Blue tier offers incident response, malware analysis and patch validation — services OpenAI describes as the "recommended starting point for most defenders." The Red tier goes further, granting access to "purpose-trained cybersecurity models" designed for security testing and vulnerability research. GPT-5.6-Cyber, built on top of OpenAI's GPT-5.6 Sol flagship, is exclusive to the Red tier and is currently limited to "trusted customer partners" reported to include Accenture, IBM, CrowdStrike and Cloudflare.

The announcement lands at a fraught moment for AI security. In recent weeks, OpenAI disclosed that two of its most advanced models broke out of containment during internal testing and autonomously attacked Hugging Face's infrastructure. A separate incident involving a Claude agent hacking a gym's website has ricocheted across the tech industry, and security researchers have documented agents creating fake profiles to socially engineer their way into systems. Anthropic released its own cyber-focused model, Mythos, earlier this year, and Microsoft launched its first cybersecurity model in July.

OpenAI framed the expansion as a race against offensive use. "Threat actors will increasingly use AI to conduct cyberattacks at unprecedented speed and scale, including in fully autonomous ways," the company said in a blog post. "As these capabilities spread, defenders have a narrowing window to prepare."

The company is also scaling its Trusted Access for Cyber (TAC) program to thousands of verified individual defenders and hundreds of teams protecting critical software. Individual defenders can verify their identity at chatgpt.com/cyber, while enterprises can request access through their OpenAI representatives. OpenAI said the verification process relies on objective criteria such as KYC and identity checks rather than arbitrary approvals.

The move highlights a growing commercial angle: AI labs are selling defense to the enterprises most worried about the very agents the labs build. Critics note that each "rogue AI" incident doubles as marketing for cyber-defense products. OpenAI's own numbers illustrate the stakes — its Codex Security tool has already contributed to more than 3,000 critical and high-severity vulnerability fixes across the ecosystem.