GPT-5.6 Cyber
OpenAI · USA · 2026
OpenAI's first model tuned to say yes to offensive security work — and the first it will not sell to the general public.
GPT-5.6 Cyber is a specialised variant of GPT-5.6 Sol, announced on 10 August 2026 and trained for one job: authorised vulnerability research, exploit validation and security testing. It is the first OpenAI model whose headline improvement is a lower refusal rate rather than a higher benchmark score. The number OpenAI leads with is its own Advanced Cybersecurity Completion Rate — how often a model actually answers prompts about exploit-chain development, authentication bypass and privilege escalation instead of declining. GPT-5.6 Cyber answers 95.0% of them. The same prompts put to GPT-5.6 Sol behind standard guardrails get 1.5%, and 2.0% under the defensive Daybreak Blue tier. The previous generation, GPT-5.5 Cyber, managed 57.3%. Raw capability moved less than the willingness did, and OpenAI publishes the losses as well as the wins. On ExploitGym 2 — turning known vulnerabilities into working exploits — Cyber beats both Sol and GPT-5.5 Cyber. On ExploitBench 3, a harder V8 exploitation task with sandbox protections left on, plain GPT-5.6 Sol solves tasks more token-efficiently within the standard 300-turn budget; the gap narrows only when agents are given 600 turns. On OpenAI's internal vulnerability-report evaluation Cyber scores below Sol, which OpenAI attributes to the model writing shorter, less detailed reports. Under the Preparedness Framework it is rated High for cyber capability, the same as Sol, and below the Critical threshold. Field results are the stronger argument. OpenAI used the model on V8, Chrome's JavaScript engine, and found two previously unknown bugs that chain into a heap-sandbox escape; Google fixed them as CVE-2026-15903. The company also reports at least five vulnerabilities in a widely used mobile operating system, three critical database flaws, and more than 400 privilege-escalation issues in a popular OS kernel, all going through coordinated disclosure. Access is the defining constraint. The model exists only inside Daybreak Red, the offensive tier of OpenAI's cyber partner programme, gated by identity verification, approved-use restrictions, monitoring and legal attestations; from 1 September 2026 every individual Daybreak account must use a hardware security key. Named early partners include Accenture, IBM, Capgemini, EY, KPMG, PwC, Palo Alto Networks, CrowdStrike, Cloudflare, Akamai, Fortinet, Sophos and SpecterOps. Technically it is a smaller-context, dearer sibling of Sol: a 400,000-token window against Sol's 1,050,000, 272,000 tokens of input, 128,000 of output, text and image in, text out, knowledge to 16 February 2026. It runs only on the Responses endpoint — no chat completions, no batch, no fine-tuning — and costs USD 12.50 per million input tokens and USD 75 per million output, two and a half times Sol's rate. A system card with fuller evaluations has been promised for a later date.
▸News
▸Videos
No videos yet.
▸Reviews
No reviews yet. Be the first!