Practical guides to protect yourself, your family, and your business from AI-driven scams, deepfakes, and emerging cyber threats.
On 7 August 2026, OpenAI confirmed it had slowed work on Astra, its next frontier model, because internal testing could not rule out that Astra had crossed into the critical cyber tier of the company's own Preparedness Framework. Critical, in that framework, means a model capable of finding zero-day vulnerabilities on its own and running an end-to-end attack against a hardened target from nothing more than a stated objective.
On 10 August, the same company shipped GPT-5.6-Cyber, a model trained specifically to refuse less often when asked to build exploit chains, escalate privileges and bypass authentication. Both moves are defensible on their own terms. Set side by side, they say something precise about where AI security has landed, and the clearest way to see it is a single number OpenAI published itself.
GPT-5.6-Cyber is built on GPT-5.6 Sol, OpenAI's existing frontier model, and the company is explicit that what separates the two is not raw capability but willingness. To measure that, OpenAI built an internal benchmark it calls the Advanced Cybersecurity Completion Rate, which counts how often a model answers prompts about exploit-chain development, authentication bypass and privilege escalation rather than declining them. GPT-5.6 Sol answers 1.5 percent of them. GPT-5.6-Cyber answers 95 percent.
That gap is the whole story. A refusal is not a missing skill. It is a trained-in policy sitting on top of a skill the model already has, and OpenAI has now published a measurement of how much sits underneath. The June 2026 predecessor, GPT-5.5-Cyber, answered 57.3 percent, so the loosening is deliberate and incremental rather than a slip. Since the capability itself was never the constraint, the only control left is who receives the permissive version. OpenAI's answer is Daybreak Red, a restricted tier limited to vetted partners including Accenture, Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, IBM, Palo Alto Networks, PwC and Sophos. Vetting is now the safety mechanism.
Start with what is concretely true today. A commercial model found a high-severity bug in the browser running on nearly every desktop in your organization, plus a second bug that turned it into a sandbox escape, and by OpenAI's account a kernel gave up four hundred privilege-escalation paths. Whatever you make of AI marketing, that is a real change in the rate at which vulnerabilities surface. The consequence for your own planning is not that attackers have acquired a magic model. It is that the interval you have been implicitly relying on, the weeks between a flaw becoming public and a reliable exploit existing for it, is being compressed from both directions at once. A patch program built around a thirty-day window for internet-facing systems rests on an assumption about attacker effort, and that assumption is being retired in public. There is a second, quieter exposure worth raising internally. Roughly ten large consultancies and security vendors now hold offense-grade model access, and several of them plausibly run assessments inside your environment. That is a supply chain relationship you have never audited, governed by a control you do not own, which is OpenAI's vetting process. The systemic point is what the company concedes by acting this way at all. OpenAI wrote that models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment, then shipped anyway on the argument that getting frontier capability to defenders faster is worth the trade. The title it gave the announcement, about expanding Daybreak as the cyber defense window narrows, tells you which way it thinks that window is moving.
Nobody was breached here. A company published a benchmark, and the benchmark made something explicit that had been comfortable to leave vague: the distance between a frontier model that will not help you write an exploit and one that will is a policy decision worth ninety-three and a half percentage points, and the vendor can make it whenever it chooses. Bring that to your next security meeting, because it reframes the question your roadmap is answering. The thing to plan around is not whether AI can write exploits at scale. It is who currently decides that it may, and how long you expect that list to stay short. OpenAI's announcement sets out the benchmark and the access tiers, and Google's Chrome stable channel update documents the V8 fix.


