OpenAI expands 'Daybreak' cyber program: New tools, partnerships, and a cyber-focused GPT-5.5 aim to help 'patch the world'
The company has added new tools, signed up partners, and released its GPT-5.5-Cyber model more widely
OpenAI has expanded its Daybreak cybersecurity initiative to cover fixing vulnerabilities, not just identifying them.
The AI developer has introduced a series of new tools, and signed up a host of partners to lead the scheme, including Accenture, Check Point, Cisco, CrowdStrike, IBM, and more.
"Vulnerability reports, on their own, do not protect anyone. The value comes from validating the issue, understanding its impact, developing and testing a patch, coordinating disclosure, and helping teams deploy the fix," said the firm.
"We are investing alongside our partners to improve these latter steps, in order to turbocharge defenders and convert model capability into real-world risk reduction."
OpenAI said it has tweaked models to discover and generate patches for critical vulnerabilities in major browsers, network infrastructure, and operating systems such as FreeBSD and the Linux kernel.
To scale the effectiveness of these capabilities, it's launching an update to the Codex Security plugin.
This aims to speed up the process of discovering and patching vulnerabilities in existing systems, as well as automatically preventing new vulnerabilities from ever reaching production.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
OpenAI touts GPT-5.5-Cyber capabilities
Notably - and following an initial permissive-only preview - OpenAI confirmed plans to launch the full version of GPT‑5.5‑Cyber through a continued limited release.
The company is also working with researchers, maintainers, enterprises, and partners for its Patch the Planet initiative, founded with Trail of Bits to help widely used open source projects move from findings to fixes.
More than 30 open source projects have committed to participate so far, including:
- cURL
- Go
- Python
- Sigstore
- pyca/cryptography
OpenAI leans on partners
Elsewhere, the new OpenAI Daybreak Cyber Partner Program allows participating organizations to use GPT‑5.5 with Trusted Access for Cyber in the security products and services they provide.
This, the firm said, allows their customers to get the benefits of the model’s defensive capabilities and make their software more resilient, but still keeps direct model access in the hands of participating partners.
“Organizations are looking for practical ways to apply AI to strengthen cyber defence while maintaining strong governance and safety controls,” said Ryan Kalember, chief strategy officer at Proofpoint.
“By incorporating GPT-5.5 through the OpenAI Cyber Partner Program into Proofpoint’s products, services, and AI-powered security workflows, we can help security teams improve threat investigation, decision-making, and efficiency as they protect their people, data, and AI agents."
Government engagement
OpenAI said it's also been working with government bodies in Australia, Canada, France, Germany, Japan, the Republic of Korea and the EU, on cyber testing, evaluation, and standards.
"We also have a growing and trusted partnership with the UK government around cyber testing and evaluation, and other areas of mutual interest," said the firm.
"We plan to work directly with eligible operators of critical infrastructure, including government networks, to develop safeguards tailored to the systems they operate."
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
MSPs urged to patch immediately after N-able issues hotfix for N-central ‘god mode’ flawNews The authentication bypass flaw in N-central could grant threat actors ‘god mode’ access
-
Red Hat launches new open source project to drive AI governanceNews The asago open source project will allow enterprises to automate compliance processes and bolster security
-
Anthropic joins OpenAI in admitting loss of control in cybersecurity testsThe company found Claude AI had escaped containment three times and targeted other organizations
-
'It delivers world-class performance at 50 percent of the cost of leading models': Microsoft unveils cut-price AI for security with latest in-house model launchNews Pairing the MAI security model with GPT-5.4 gives benchmark leading results at half the cost, according to the tech giant
-
Hugging Face CEO calls for ‘radical transparency’ in wake of OpenAI attackNews The AI library chief has called for investment to help “build powerful cyber defenses”, as alleged weaknesses in OpenAI’s monitoring emerge
-
An ‘unprecedented cyber incident’: How OpenAI models breached Hugging Face – and why it could herald a ‘new phase of AI-powered cyber crime’News The incident should serve as a stark warning on the dangers of AI agents, according to cyber experts
-
The case for the channel in an AI-driven security marketIndustry Insights AI won't replace channel partners; SMB cybersecurity still relies on trust
-
Cisco just launched two cyber-focused small language models: Antares-350M and Antares-1B aim to supercharge codebase analysis – and they run at a “fraction of the compute expense” of popular frontier modelsNews The Antares models unveiled by Cisco aim to cut costs in codebase analysis
-
Cyber professionals are flocking to AI tools, but they’re getting tired of fixing mistakes and reviewing outputsNews Cyber pros are spending significantly more time validating AI outputs and deciding when to trust AI-generated recommendations
-
The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious codeNews Research shows agents can be fooled into executing malicious code while performing security reviews of third-party software