The threshold was always going to be crossed
OpenAI built a capability classification system, then shipped a model that trips it. That was the only way this could end, and the interesting question is what replaced refusal as the control.
GPT-5.6-Cyber completes 95 percent of advanced cybersecurity requests where standard GPT-5.6 Sol completes 1.5 percent. It ships behind Daybreak Red, the vetted tier.
A framework that never says no is not a framework
Capability thresholds were introduced with an implied promise: past a certain line, a lab stops. What has actually happened is that the line is reached, the model ships, and the mitigation is access control rather than non-release.
It is worth being precise about why that is not simply hypocrisy. OpenAI's argument is that attackers will have these capabilities regardless, and withholding them from defenders makes the asymmetry worse. Given a narrowing defence window, that is a coherent position — arguably the correct one.
The control moved, and got quieter
Refusal is a property of the model and is testable from outside. Vetting is a property of a business process and is not. When the safety story moves from the weights to the access-review queue, the public loses the ability to audit it at exactly the moment the stakes rise.
The step function makes this concrete: GPT-5.5-Cyber sat at 57.3 percent, the new model at 95. One release cycle nearly doubled the fraction of offensive-security work a model will complete.
The market is already responding
Corma raised $60 million to be a frontier lab for defence only. When general labs ship offensive capability behind vetting, the differentiated position is no longer capability access — it is being the vendor whose incentives are structurally defensive.
Whether that distinction survives a sales quota is the open question. The techniques do not differ; only the contract does.
OpenAI — Expanding Daybreak as the Cyber Defense Window Narrows → · VentureBeat — OpenAI launches GPT-5.6-Cyber with reduced refusals, 95% completion on advanced cybersecurity tasks →