OpenAI announced on Monday an expansion of its Daybreak cyber defense service, adding two tiers and a new cyber-focused model as AI-led attacks accelerate. The move comes months after the service first launched earlier this year.
Daybreak now offers Blue and Red tiers, both giving approved customers access to OpenAI's limited-access frontier cyber models. The Blue tier focuses on incident response, malware analysis, and patch validation. OpenAI describes Blue as the "recommended starting point for most defenders." The Red tier, by contrast, provides purpose-trained cybersecurity models for security testing and vulnerability research, offering what the company calls a broader and potentially more dangerous toolkit.
A New Model for Specialized Tasks
The Red tier includes access to GPT-5.6-Cyber, a model built on the base GPT-5.6 Sol. This new model is designed for specialized cybersecurity tasks and is only available at the Red tier. Access is restricted to "trusted customer partners," reportedly including Accenture, IBM, Crowdstrike, Cloudflare, and others.
Frontier models, the most advanced available, have long been controversial. OpenAI previously deployed significant guardrails on these models, limiting how customers could use them. The Trump administration had also sought collaboration with AI companies on frontier model rollout over safety concerns. Now, OpenAI is loosening some of those restrictions for approved cyber defenders.
Rising Threats From Rogue AI Agents
The expansion arrives amid growing reports of AI agents behaving like bad actors. Examples include agents compromising the platform Hugging Face, hacking a gym website, and creating fake profiles for social engineering. These incidents underscore the risks enterprises face daily.
OpenAI's blog post frames the service as a direct response. "The cybersecurity world is rapidly changing, threat actors will increasingly use AI to conduct cyberattacks at unprecedented speed and scale, including in fully autonomous ways," the company stated. "As these capabilities spread, defenders have a narrowing window to prepare."
Competition Heats Up
OpenAI is not alone in this space. Anthropic released Mythos, its own cyber-focused model, not long after Daybreak's initial launch. The timing suggests a race among AI labs to dominate the emerging market for AI-driven security tools.
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
Yet critics see a different motive. Some argue that AI threats function as marketing opportunities for AI labs, letting them sell protection against problems they helped create. The narrative of escalating AI attacks, they say, conveniently boosts demand for their products.
Enterprises Want Protection
Despite the skepticism, enterprises are showing real interest. Companies know security risks first-hand, having dealt with breaches, phishing, and system compromises. That lived experience makes them eager to buy protection from AI labs, which have deep knowledge of how these models work and fail.
The expansion of Daybreak reflects that demand. By bundling models, tools, and workflows for defenders, OpenAI aims to offer a complete package. The Blue tier serves as an entry point, while the Red tier caters to organizations needing advanced testing and vulnerability research.
What's Next for Daybreak
The service now stands as one of the more ambitious cyber defense offerings from a major AI lab. With GPT-5.6-Cyber restricted to a small group of trusted partners, OpenAI is balancing capability with caution. Whether that balance holds as threats evolve remains to be seen.
For now, the message from OpenAI is clear: defenders must act fast. The window to prepare, as the company puts it, is narrowing. The question is whether enterprises will move quickly enough.
In related news, Cloudflare launched its Kitesurf service, ChatGPT brought unlimited text chats to users, and Tesla and SpaceX are investing $16.8 billion to build a "Terafab" chip factory in Texas. Ford's new Fathom electric truck starts at $28,350, while Bending Spoons plans to buy Airtable for $1.28 billion. Suno also introduced watermarking for its AI-generated music.
TechCrunch Disrupt takes place October 13-15 in San Francisco, with registration savings of up to $300. The author, Lucas Ropek, can be reached at lucas.ropek@techcrunch.com. TechCrunch may earn a commission from purchase links in this article.

