OpenAI ships a model trained to stop refusing: GPT-5.6 Cyber answers 95% of hacking prompts, and almost nobody can buy it
OpenAI announced GPT-5.6 Cyber on 10 August 2026, and the headline figure is unusual: it is not a capability score but a compliance rate. On the company's own Advanced Cybersecurity Completion Rate — how often a model answers prompts about exploit chains, authentication bypass and privilege escalation rather than declining — the new model responds to 95.0% of them. GPT-5.6 Sol behind standard guardrails answers 1.5%. Last year's GPT-5.5 Cyber managed 57.3%.
The model is built on GPT-5.6 Sol and further trained for zero-day discovery and exploit development. Its usefulness has already been demonstrated on live software: OpenAI used it to study V8, Chrome's JavaScript engine, and found two previously unknown bugs that chain into an escape from the heap sandbox. Google patched them as CVE-2026-15903. OpenAI also reports at least five vulnerabilities in a widely used mobile operating system, three critical flaws in a popular database, and more than 400 privilege-escalation issues in an OS kernel — all now in coordinated disclosure.
What makes the release notable is not that the model is stronger, because in places it is not. On ExploitBench 3, a harder V8 task with sandbox protections left on, ordinary GPT-5.6 Sol solves more within the standard 300-turn budget; the gap only narrows at 600 turns. On OpenAI's internal vulnerability-report evaluation, Cyber scores below Sol, which the company blames on shorter, thinner write-ups. Under the Preparedness Framework it lands at High for cyber capability — the same rating as Sol — and below the Critical threshold.
What changed is who gets to ask. GPT-5.6 Cyber exists only inside Daybreak Red, the offensive tier of an access programme OpenAI expanded the same day; Daybreak Blue, the defensive tier, keeps the general-purpose models with guardrails tuned for defence. Entry requires identity verification, approved-use restrictions, monitoring and legal attestations, and from 1 September 2026 every individual Daybreak account must use a hardware security key. Early partners named by OpenAI include Accenture, IBM, Capgemini, EY, KPMG, PwC, Palo Alto Networks, CrowdStrike, Cloudflare, Akamai, Fortinet, Sophos and SpecterOps.
The technical shape is narrower than Sol's: a 400,000-token context window against Sol's 1,050,000, output up to 128,000 tokens, text and image in, text out, knowledge to 16 February 2026. It runs on the Responses endpoint only, with no chat completions, batch or fine-tuning, and lists at USD 12.50 per million input tokens and USD 75 per million output — two and a half times Sol's price. A full system card has been promised at a later date.
GPT-5.6 Cyber →