The company split access into Daybreak Blue and Daybreak Red and introduced GPT-5.6-Cyber, a model designed for advanced cybersecurity work that would normally trigger stronger safeguards.
OpenAI acknowledged that production protections can block legitimate defensive requests and said the new model responds to feedback from security researchers who encountered persistent refusals.
In internal testing covering advanced tasks including exploit-chain development, authentication bypass and privilege escalation, OpenAI said GPT-5.6-Cyber completed 95% of requests. GPT-5.6 Sol completed 1.5%, while the same model accessed through Daybreak Blue completed 2%.
Access remains restricted to approved users. OpenAI requires identity verification, stronger account security, monitoring, approved-use restrictions and legal attestations, while the Red tier provides more permissive capabilities for advanced authorized testing.
Anthropic has taken a similar approach with Project Glasswing.
The program initially gave roughly 50 organizations access to its advanced Claude Mythos Preview model before Anthropic said in June that it was expanding participation to about 150 additional organizations across more than 15 countries.
Anthropic also committed up to $100 million in model-usage credits and $4 million in direct support for open-source security groups.
That funding addresses another element of BPI's request. Even approved researchers may struggle to conduct long-running vulnerability searches if the cost of operating frontier models or usage limits cut investigations short.
Anthropic has said it ultimately expects hundreds of thousands of organizations, security researchers and software maintainers could require access to advanced cyber capabilities, with critical open-source projects among those prioritized for future expansion.
CryptoSlate Daily BriefDaily signals, zero noise.
Market-moving headlines and context delivered every morning in one tight read.
5-minute digest 100k+ readers
Free. No spam. Unsubscribe any time.
Whoops, looks like there was a problem. Please try again.
You’re subscribed. Welcome aboard.
Those programs broadly put OpenAI and Anthropic in the same direction as BPI's proposal. The remaining dispute centers on how reliably that access can scale beyond selected partners without weakening the controls intended to stop the same models from being used offensively.
Wider access brings its own security constraints
The difficulty is that removing restrictions can create risks as serious as the ones defenders are trying to address.
Hugging Face said its security team reconstructed roughly 17,600 attacker actions following a July intrusion, including real commands, exploit payloads and command-and-control artifacts.
The company said safeguards on commercial frontier APIs blocked portions of its forensic analysis because the material resembled malicious activity. Its researchers turned instead to open-weight models running locally, allowing them to keep sensitive information on their own infrastructure.
OpenAI later disclosed that its own models had caused the intrusion while undergoing an internal cybersecurity evaluation with reduced refusals.
The models discovered a previously unknown vulnerability in a package-registry proxy, used it to obtain internet access, moved through OpenAI's research environment, and eventually compromised Hugging Face infrastructure while attempting to complete an exploitation benchmark.
The episode captures the trade-off the BPI coalition is asking AI labs to manage.
Restrictions can obstruct verified defenders investigating genuine attacks, but models with broader permissions can exceed their intended boundaries even during authorized research.
Meanwhile, giving defenders greater access could also move the bottleneck elsewhere.
The Ethereum Foundation's security team said in July that coordinated AI agents had identified genuine software vulnerabilities, but human researchers still had to filter false positives, reproduce findings and determine which issues required remediation.
Anthropic has made a similar point through Glasswing, warning that verification, disclosure and patching could become the constraint as AI systems discover vulnerabilities faster.
That leaves frontier labs trying to solve two problems at once: giving trusted researchers enough capability and compute to keep pace with attackers while ensuring those same capabilities remain contained.
BPI's coalition is pushing them to extend that emerging model to more crypto and open-source defenders before advances in offensive AI widen the gap further.