Site navigation

OpenAI Brings Frontier AI Models to Cyber Defence With Daybreak

Graham Turner

,

OpenAI Daybreak
The initiative builds on the company’s Trusted Access for Cyber programme and aims to make software more resilient by design.

OpenAI has announced Daybreak, a new cyber defence initiative designed to help developers build more secure software from the start of the development process.

The initiative is based on OpenAI’s frontier large language models and its AI-coding assistant, Codex. Unveiled on May 12, Daybreak builds on the company’s Trusted Access for Cyber (TAC) programme, which reserves access to certain frontier models for a selective number of organisations.

While TAC is primarily focused on enabling vetted users to use LLMs to identify and fix vulnerabilities, Daybreak is intended to address software risk earlier in the development lifecycle. OpenAI described the initiative as its “vision to change the way software is built and defended”.

“Daybreak is the first glimpse of sunlight in the morning. For cyber defense, it means seeing risk earlier, acting sooner, and helping make software resilient by design,” the company said in a blog post.

The initiative currently includes three of OpenAI’s latest models: the general-purpose version of GPT-5.5; GPT-5.5 with TAC, which offers more precise safeguards for verified defensive work in authorised environments; and GPT-5.5-Cyber. Daybreak also features Codex Security, a code-review assistant based on Codex that is currently available only as a research preview.

OpenAI said Daybreak is based on the idea that the next phase of cyber defence should be built into software from the beginning, rather than limited to finding and patching vulnerabilities after they emerge.

“It starts from the premise that the next era of cyber defense should be built into software from the beginning by not only finding and patching vulnerabilities, but being resilient to them by design,” OpenAI said.

The company said AI can now help cyber defenders reason across codebases, identify subtle vulnerabilities, validate fixes, analyse unfamiliar systems, and move from discovery to remediation faster. However, it also acknowledged that those same capabilities can be misused.

“Because those same capabilities can be misused, Daybreak pairs expanded defensive capability with trust, verification, proportional safeguards, and accountability,” OpenAI said.

“The goal is simple: accelerate cyber defenders and continuously secure software.”

The initiative brings together OpenAI models, Codex as an agentic system, and partners across what the company described as the security flywheel. OpenAI said this could allow defenders to bring secure code review, threat modelling, patch validation, dependency risk analysis, detection, and remediation guidance into everyday development processes.

Codex Security

As part of Daybreak, OpenAI has highlighted how software developers and cybersecurity defenders could use the system to scan codebases, identify vulnerabilities, fix them, and add regression tests.

In a series of short videos posted on social media, the company showed Codex Security using 10 subagents to scan a codebase and support security review. Other potential uses include triaging vulnerability backlogs, prioritising issues by severity, impact or exploitability, and deploying agents to open pull requests.

OpenAI also said Daybreak could help automate vulnerability detection, validation, and response. This could include monitoring for the latest CVEs, deploying an agent to investigate their impact on a business, and searching logs for evidence of exploitation.


Recommended reading


The company said the initiative is intended to help defenders focus on the threats that matter, reducing hours of analysis to minutes while using tokens more efficiently. It also said Daybreak could support patching at scale by generating and testing patches directly in repositories, with scoped access, monitoring, and review.

Another focus is verification. OpenAI said Daybreak will allow results and audit-ready evidence to be sent back to existing systems, helping organisations track and verify remediation.

OpenAI said it is working with industry and government partners in the coming weeks as it prepares to deploy increasingly cyber-capable models as part of an iterative deployment approach.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data