OpenAI's Daybreak programme splits into Blue and Red tiers for offensive-security access
Expanded on 10 August into two tiers. Daybreak Red grants access to GPT-5.6-Cyber, which responds to 95% of sensitive queries covering exploit-chain development, authentication bypass and privilege escalation — capability normally refused outright, released to a vetted tier instead.
Refusal has been the industry's answer to offensive-security capability: train the model to decline, publish the refusal rate, treat the number as a safety metric. A tier where the model answers 95% of exactly those queries is a different policy, and it is the more honest one.
The reasoning is defensible. Defenders need the same capability attackers have, refusal-trained models are worked around by anyone motivated, and a blanket refusal mostly inconveniences the legitimate security researcher while barely slowing the adversary. Gating on identity rather than on question is how every other dual-use capability is handled.
It moves the safety property from the model to the access-control system. The question stops being "will the model refuse" and becomes "is the vetting good, is the tier boundary enforced, and what happens when credentials for Red are stolen or sold". Those are ordinary security problems, which is both reassuring and not.
The precedent is what will be argued about. A vetted tier for exploit development is a template that applies to every other capability currently handled by refusal, and the argument for it in each case will sound much like this one.
imFounder — AI Updates August 2026: 15 Explosive Stories to Know → · AI Weekly — AI News Today, August 15 →