Here's a strange twist nobody predicted a few years ago: the same companies whose models keep getting caught misbehaving are now the ones selling you protection from AI attacks. And enterprises are lining up to buy.
This week OpenAI expanded Daybreak, its cybersecurity defense platform, adding a new model called GPT-5.6 Cyber and splitting access into two tiers, Blue and Red. It's a direct answer to Anthropic, which beat OpenAI to this space earlier in the year with a cyber-focused model called Mythos.
Why this is happening right now
The timing isn't random. Data breach notices in 2026 have already blown past all of 2025's record total, and a lot of that surge traces back to AI. An IBM study covering 602 organizations found that one in four malicious breaches between March 2025 and February 2026 involved AI in some way, a 56% jump from the year before. Insider incidents alone jumped from three in all of 2025 to 21 in just the first half of this year.
And it's not hypothetical anymore. Recent months have brought a steady drip of AI agents going rogue in public: a Hugging Face breach touching internal datasets and credentials, an AI agent reportedly hacking into a gym's website, and cases of models creating fake profiles to social-engineer their way into systems. The tools built to write code and automate work are, increasingly, also good at breaking into things.
Blue, Red, and who gets what
OpenAI's restructured Daybreak now has two access tiers. Blue is the one OpenAI calls its "recommended starting point for most defenders," covering incident response, malware analysis, and patch validation. It's built for the average security team that wants AI help without needing offensive capabilities.
Red is the sharper tool. It grants access to "purpose-trained cybersecurity models" designed for security testing and vulnerability research, including the new GPT-5.6 Cyber model, built on GPT-5.6 Sol. Right now GPT-5.6 Cyber is only available to a short list of trusted partners, reportedly including Accenture, IBM, CrowdStrike, and Cloudflare.
That gatekeeping mirrors what Anthropic has done with Mythos since launch. Anthropic has kept Mythos tightly restricted, citing safety and national security concerns, and hasn't made it commercially available at all. It has, however, put the model to real work: Mythos reportedly helped Mozilla find and fix more than 270 vulnerabilities in Firefox. Where Mythos leans toward autonomous zero-day discovery at the research level, Daybreak is shaping up as more of a developer-integrated platform with a broader roster of enterprise partners.
The uncomfortable part
OpenAI's own framing gets at the tension here directly. In its announcement, the company said "the cybersecurity world is rapidly changing, threat actors will increasingly use AI to conduct cyberattacks at unprecedented speed and scale, including in fully autonomous ways," adding that defenders have a "narrowing window to prepare."
That's a real problem, but it's also a pitch, and critics haven't been shy about pointing that out. The labs releasing frontier models capable of autonomous hacking are, at the same time, the ones best positioned to sell you the countermeasure. It's a tidy business loop: ship the technology that raises the risk, then charge enterprises for the specialized version that manages it.
None of that makes the defensive work fake. Enterprises have legitimate reasons to want protection from people who built the models in the first place; nobody understands these systems' failure modes better than their own creators. But if you're evaluating whether to adopt Daybreak, Mythos, or whatever comes next, it's worth remembering that the vendor pitching you frontier defense is also the one that put the frontier offense into the wild.
What to watch next
Access to both platforms remains narrow by design, limited to vetted enterprise partners rather than open products. That's likely to change as competitive pressure builds. Also worth watching: the Trump administration has reportedly sought to work directly with AI companies on rolling out frontier cyber models, which puts questions of access and oversight squarely in policy territory, not just product strategy. Whoever controls the guardrails on these tools will shape how the rest of this arms race plays out.
Thumbnail: Computer screen displaying lines of code by Jakub Żerdzicki, License: Unsplash License
Sign in to join the conversation.
Sign In