// blog · analysis · frontier-models2026-08-11source: OpenAI / reporting

The threshold was always going to be crossed

OpenAI built a capability classification system, then shipped a model that trips it. That was the only way this could end, and the interesting question is what replaced refusal as the control.

GPT-5.6-Cyber completes 95 percent of advanced cybersecurity requests where standard GPT-5.6 Sol completes 1.5 percent. It ships behind Daybreak Red, the vetted tier.

A framework that never says no is not a framework

Capability thresholds were introduced with an implied promise: past a certain line, a lab stops. What has actually happened is that the line is reached, the model ships, and the mitigation is access control rather than non-release.

It is worth being precise about why that is not simply hypocrisy. OpenAI's argument is that attackers will have these capabilities regardless, and withholding them from defenders makes the asymmetry worse. Given a narrowing defence window, that is a coherent position — arguably the correct one.

The control moved, and got quieter

Refusal is a property of the model and is testable from outside. Vetting is a property of a business process and is not. When the safety story moves from the weights to the access-review queue, the public loses the ability to audit it at exactly the moment the stakes rise.

The step function makes this concrete: GPT-5.5-Cyber sat at 57.3 percent, the new model at 95. One release cycle nearly doubled the fraction of offensive-security work a model will complete.

The market is already responding

Corma raised $60 million to be a frontier lab for defence only. When general labs ship offensive capability behind vetting, the differentiated position is no longer capability access — it is being the vendor whose incentives are structurally defensive.

Whether that distinction survives a sales quota is the open question. The techniques do not differ; only the contract does.

OpenAI — Expanding Daybreak as the Cyber Defense Window Narrows → · VentureBeat — OpenAI launches GPT-5.6-Cyber with reduced refusals, 95% completion on advanced cybersecurity tasks →