OpenAI's GPT-6 Astra is the first model the company has rated at the Critical level for cybersecurity under its Preparedness Framework. The public version is limited to reviewing code for security problems and helping patch them. OpenAI says it refuses requests to build proof-of-concept exploits.
Daybreak is the programme OpenAI says will give vetted defenders wider access, with fewer restrictions, in the coming weeks. That covers checking vulnerabilities and proof-of-concept fixes, analysing malware and building detections. ExploitBench is reported at 100 percent. Coverage from Progressive Robot and NCIJ in September 2026 focused on the defensive side.
What Critical means
OpenAI's Path to Astra post and the GPT-6 Astra safety overview, published on 3 September 2026, say Astra meets the Critical threshold for cybersecurity. In OpenAI's words, that means that with the right tools and access, the model can find previously unknown security flaws and work out ways to exploit them across many well-protected systems, without a person guiding each step. That's why the way OpenAI released it matters more than any benchmark score.
The public version
As The Hacker News and Progressive Robot sum up OpenAI's approach, the public Astra has tighter cyber safeguards. Secure code review and patching are in. Requests to build proof-of-concept exploits are refused. That's the news for most developers and security engineers using ChatGPT or the API this week. OpenAI is offering the capability, but not an open exploit service.
Daybreak
Daybreak is the other door. OpenAI says it plans to "expand access and roll out less restrictive safeguards in the coming weeks" through Daybreak, so more defensive work becomes possible. Its list is vulnerability and proof-of-concept validation, malware analysis and detection engineering. Organisations that can show they do authorised defensive work apply through OpenAI's Daybreak forms.
Those terms are easy to mishear, so here's what they mean. Detection engineering is helping defenders write and tune the rules and alerts that catch attacks, not teaching attackers to dodge them. Malware analysis means studying malicious files defenders already have, in controlled labs. Vulnerability validation means confirming problems and fixes within agreed rules, not publishing attack guides online.
The word authorised matters. Getting into the programme doesn't replace legal permission, your employer's rules or the norms of responsible disclosure. If your work is code review and patching, the public Astra is the near-term product. If it includes checking vulnerabilities, analysing malware or building detections, Daybreak is the path OpenAI points to.
The benchmark
ExploitBench is the test behind the 100 percent figure in OpenAI's materials and other coverage. It measures whether an AI agent can build exploits from known vulnerabilities, in locked-down test settings. A perfect score is a sign of capability that OpenAI chose to publish. It's not an invitation to try the same thing outside authorised settings.
Two flaws, disclosed responsibly
OpenAI says that during internal testing, the model found and used two previously unknown flaws in V8, the JavaScript engine, as part of a test. Those two flaws are being reported to the people who maintain V8 through coordinated disclosure. We're not giving any more technical detail than that. Defenders will get the official records through the usual advisory channels.
Why OpenAI split it this way
OpenAI's Expanding Daybreak materials talk about a narrowing gap between what top AI models can do in testing and how fast defenders can use similar tools. OpenAI's answer is tiers. Most users get the public model that refuses exploit requests. Vetted defenders get a programme. Its Daybreak for Frontline Defenders messaging also mentions critical infrastructure, with subsidised access, training and a US pilot with MS-ISAC for public-sector and water-system defenders, among commitments reported alongside the launch. Any dollar figures and pilot details are OpenAI's own.
OpenAI also says Astra is much harder to jailbreak than GPT-5.6 Sol on its internal tests, including over longer conversations. It says extra cautious refusals can kick in for users flagged as higher risk. Those are OpenAI's own results. Independent testers will keep checking.
Progressive Robot's security-operations take and NCIJ's coverage both put the focus on operations and policy rather than benchmark bragging. Defenders have plenty to patch already, from new entries on CISA's exploited-bugs list to attacks like StyleSmuggler.
The bottom line
Critical is OpenAI's label. The public Astra reviews and patches code and refuses exploit requests. Daybreak is the defenders' programme, for validation, malware analysis and detection engineering, starting in the coming weeks. The 100 percent ExploitBench score is a headline about capability, not an invitation. Read more on OpenAI's GPT-6 Astra page.
Update: OpenAI has since published Daybreak API documentation, covering Daybreak Blue and Daybreak Red.






The paper
Comments
No notes on this story yet.
Sign in to comment