OpenAI just shipped a model built to write exploits
OpenAI's GPT-5.6-Cyber completes 95 percent of exploit-development requests. Here is what a gated hacking model means for your patch window.
OpenAI now sells access to a model that develops working exploit chains. The gate around it is a vetting program. Our read: the gate matters less than the number 95.
What OpenAI shipped
Last week OpenAI announced GPT-5.6-Cyber, a version of its frontier model tuned for offensive security work. In OpenAI’s own testing it completes 95 percent of advanced requests like exploit-chain development, privilege escalation, and authentication bypass, per SecurityWeek. The safeguarded base model completes 1.5 percent of the same requests. Last year’s GPT-5.5-Cyber managed 57.3 percent.
Access runs through Daybreak Red, a program for vetted security teams. It requires identity verification, legal attestations, and from September 1, hardware security keys. Accenture, Palo Alto Networks, CrowdStrike, Fortinet, and Cloudflare are among the first partners.
The model has already found real bugs. Reporting on the launch credits it with two Chrome V8 flaws (CVE-2026-15903) that chain into a sandbox escape, plus five vulnerabilities in a mobile operating system. OpenAI rates the model High on its own Preparedness Framework, one step below Critical.
The gate is not the control
We read this launch as a confirmation, not a fix. The offensive capability lives in the base model. Refusal training was the only thing between a paying customer and a working exploit, and the gap between 1.5 and 95 percent comes down to policy. The capability was already there.
Vetting keeps honest researchers honest. It does not stop leaked accounts, and it does not slow the open-weight models that already skip the queue. In our report on AI-driven hacking we argued that exploit development is moving onto a scaling curve. A commercial model at 95 percent completion raises that curve for everyone, including the labs that will ship a rival next quarter.
Exploits now arrive in hours, not weeks
I read exploit write-ups for a living, and this month still stands out. Researchers at A Security used publicly available AI models to build a zero-click exploit chain against Zoom in under 24 hours. Anthropic’s evals saw Claude models breach three real companies. AI agents ran a four-day intrusion against Taiwan’s government.
The common thread is speed. The time from disclosure to weaponized exploit used to be measured in weeks. Plan for hours.
What you do this week
Treat “a patch exists” and “we have patched” as two different risk states, and measure the gap between them in days. We recommend a 72-hour patch window for internet-facing systems and seven days for the rest. If you do not know which of your systems face the internet, start there: a vulnerability scan gives you that list before an AI model builds it for someone else.
Talk to Christian Vik if you want our read on what a 24-hour exploit cycle means for your patch process.
Drafted with AI assistance, reviewed and edited by Christian Vik and the FM editorial team.