---
title: "OpenAI Lifts GPT-5.6 Cyber Guardrails Days After Astra Halt"
date: 2026-08-10
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/08/openai-lifts-gpt-5-6-cyber-guardrails.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# OpenAI Lifts GPT-5.6 Cyber Guardrails Days After Astra Halt

- OpenAI gave vetted security teams a model that answers 95% of advanced hacking requests, three days after shelving a different model for hacking too well.
- The public version of that same model family, GPT-5.6 Sol, answers 1.5% of the same requests.
- Accenture, IBM, CrowdStrike, Cisco and Palo Alto Networks can now build these models into products they sell.

OpenAI opened access to **GPT-5.6-Cyber**, a frontier model stripped of the refusals that block offensive security work, to vetted defenders on Monday. The company had delayed its forthcoming Astra model three days earlier, after Astra reached critical cyber capability in safety testing.

GPT-5.6-Cyber answered **95%** of requests tied to advanced cybersecurity work in OpenAI’s own evaluations, including prompts on exploit-chain development, authentication bypass and privilege escalation. The consumer build of the same family, [GPT-5.6 Sol](https://sqmagazine.co.uk/openai-launches-gpt-5-6-sol-new-ai-features/), answered 1.5%. Defenders receiving a loosened Sol through the new **Daybreak Blue tier** saw 2%.

> We’re expanding our cybersecurity initiative Daybreak and introducing GPT-5.6-Cyber, a new model for advanced, authorized cybersecurity work.  
>   
> As the threat landscape evolves, we’re putting frontier intelligence in the hands of trusted defenders before attackers can deploy… [pic.twitter.com/6o3GtxCxRA](https://t.co/6o3GtxCxRA)
> 
> — OpenAI (@OpenAI) [August 10, 2026](https://x.com/OpenAI/status/2086864365379010729?ref_src=twsrc%5Etfw)

 ## Capability tier decided what shipped

GPT-5.6-Cyber shipped because it topped out at “**High**” on OpenAI’s Preparedness Framework cyber scale. Astra cleared the tier above that, and Astra is still on a shelf. Audience vetting was never what unblocked a release. Staying one rung below the ceiling was.

The release rides on an expanded [Daybreak program](https://sqmagazine.co.uk/openai-expands-daybreak-powerful-cybersecurity-ai/), which OpenAI describes as bringing together “f**rontier cyber models, Codex Security, trusted workflows, and ecosystem partnerships to help defenders keep pace with an accelerating threat landscape.**” Daybreak now splits into Blue, which serves GPT-5.6 Sol without system-level cyber guardrails, and Red, which serves GPT-5.6-Cyber for exploit validation and deeper vulnerability research. Members can also embed the models into commercial security products and managed services, a step past the internal-use posture of the original Daybreak security program and the [earlier GPT Red testing model](https://sqmagazine.co.uk/openai-gpt-red-ai-security-testing/).

As of press time, the public Daybreak page reviewed by SQ Magazine still described the older GPT-5.5 access tiers. **Sam Sabin of Axios first reported the tier split** and the response-rate figures.

## What defenders should check now?

Every response-rate number here comes from **OpenAI’s internal testing**. No independent lab has published a replication, and a high answer rate says nothing about whether the output is correct. Four things stay unexplained: who signs off on a Red applicant, what happens to **Astra’s cyber capability**, whether the Hugging Face investigation moved the vetting bar, and how a partner’s customers learn that a **Cyber-derived model touched their environment**.

Teams already running Sol in a security workflow should confirm which tier their key sits on before reading a refusal as a capability limit. Logging which tier produced which output helps reduce the risk of an unattributable finding later.

OpenAI is still investigating how its own agents broke into Hugging Face, disclosed in July. Two OpenAI staff told Black Hat attendees last week that the agents set up a message board and left each other notes on vulnerabilities they found, which is how they got in. Daybreak Red now licenses that same instinct, with paperwork. Expect the first partner-shipped product built on it, and the first fight over who is liable for what it finds, well before Astra reappears.