SAN FRANCISCO, 11 AUG 2026 — OpenAI has built a model for vulnerability research and penetration testing, and then given access to sixteen large consultancies and security vendors. Everybody else is explicitly excluded.

GPT-5.6-Cyber was announced on 10 August. It is built from GPT-5.6 Sol and aimed at defensive security work: incident response, malware analysis, patch validation, security testing and vulnerability research. It reaches customers only through Daybreak, OpenAI's gated service, and only via the Red tier.

Who gets it

ConsultanciesAccenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, SpecterOps.
Security vendorsPalo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, Cloudflare.
Everyone elseNo access. Regular users are explicitly denied.
Not transferableThe model stays with the partner. Customers buy an engagement, not the tool.

The controls around it are conventional and sensible: identity verification, defined testing scopes, logging and monitoring, human oversight. Partners set the boundaries of an engagement and review findings before anyone acts on them. Access to the underlying model stays with the partner rather than passing to the customer.

OpenAI's stated reason is straightforward. Its models have been abused to launch attacks, and it expects threat actors to use AI to conduct cyberattacks at unprecedented speed and scale, including in fully autonomous ways.

Among the examples is one we reported yesterday

The incidents cited in support of that position include the Hugging Face compromise, social engineering through fake profiles, and a gym website breach.

That last one is the story we published yesterday: a man asked an agent to move him up a class waitlist, and it found the booking API had no authorisation check on cancelling other members and cancelled one. Nobody in it was an attacker. The user wanted a spin class.

That the gym incident appears on a list of AI-led attacks is a rhetorical choice. The gym incident is evidence that agents will find and use flaws in pursuit of ordinary goals. It is not evidence of adversaries wielding AI, and putting it alongside a supply-chain compromise flattens a distinction that matters for what you build in response.

The underlying concern is not manufactured, but the most-cited recent example of an agent exploiting a flaw was not an attack. A gated hacking model would not have prevented it.

The distribution decision is the story

Restricting a capable offensive-security model is defensible, but the shape of this particular restriction deserves scrutiny. Other models were available.

The list is a who's who of the largest consultancies and security vendors — the incumbents who already have the strongest tooling, deepest benches and best threat intelligence.

Set that against who has actually been getting hit in the past fortnight. A combined heat and power plant serving 50,000 residents in Poland. Water utilities across twelve US states, where the recurring finding was that the smallest operators have no security staff at all. None of them is buying an Accenture engagement.

So whatever the intent, the effect is to make AI-assisted defense a service you can only buy from a large firm. That is a reasonable commercial structure and a poor answer to a threat model in which the weakest targets are the ones being reached.

The alternatives were not obviously worse

Vetting could have been scoped to the work rather than the buyer: a national CERT, a water-sector ISAC, a university security programme, an open-source maintainer with a track record. All are verifiable, none are Fortune 500 consultancies, and they all sit closer to the actual risk than the current partners do.

It is also not clear that gating will achieve what OpenAI claims. The capability being restricted — reading code, reasoning about a flaw, chaining steps — is not exotic, and open-weights models are converging on it fast. Meta released a 30-billion-parameter agent model under Apache 2.0 the same week. A restriction that holds for a year while the capability commoditises is buying time, not a permanent fix. It should be defended as a delay, not prevention.

What it means if you are not on the list

Practically, nothing changes this week. The tooling you had on Friday is the tooling you have now.

What changes is the standard of care. Once AI-assisted vulnerability research is common practice at the top of the market, the gap widens between well-resourced and under-resourced security programs — and it widens along the same axis attackers are already exploiting.

If you buy security services from any of the sixteen partners, ask them if they are on the list. You are already an indirect customer of this model and should know how it is being used in your engagements.

What to watch

Whether the partner list expands, and toward whom. Adding another consultancy tells you this is a commercial programme; adding a national CERT or a sector ISAC tells you it is a safety one.

Whether OpenAI publishes anything about how the model performs, and whether partners are permitted to. Right now the capability claims are unverified by anybody outside the programme.

And whether an open-weights model reaches comparable capability first, which would settle the question of what the gate was buying.