Overview
- OpenAI said Monday it paused internal work on its unreleased Astra model after tests showed it "cannot rule out" reaching the Preparedness Framework's highest 'Critical' cyber capability tier.
- The firm expanded its Daybreak program into Daybreak Blue and Daybreak Red and launched GPT‑5.6‑Cyber, a purpose‑trained model that completed about 95% of advanced exploit and privilege‑escalation test prompts compared with roughly 1.5–2% for safeguarded GPT‑5.6 Sol variants.
- OpenAI reported that GPT‑5.6‑Cyber helped discover real, high‑severity flaws including two V8 (Chrome) vulnerabilities assigned CVE‑2026‑15903 that were reported to Google and patched, and it said the model has flagged other serious bugs in mobile, database and kernel code.
- Access to Daybreak Red and GPT‑5.6‑Cyber is limited to approved partners and security vendors and requires identity checks, legal attestations, logging and monitoring, human oversight, and mandatory hardware security keys for individual accounts starting Sept. 1.
- The announcements accelerate industry and policy debate over pre‑release testing, sandboxing failures that let agents reach the internet, forensic reviews of recent containment breaches, and the tradeoff between giving defenders potent tools and reducing the risk of misuse.