OpenAI spent the last year warning that AI was getting dangerously good at hacking. This week it shipped the model to prove it, and wrapped one of the strongest cybersecurity AIs anyone has measured in the calmest possible bow.
What OpenAI actually shipped
Daybreak is OpenAI's cybersecurity program, and on June 22 it expanded into four pieces. The headline is the full release of GPT-5.5-Cyber, a model built to move a defender through the whole repair loop: trace the reachable flaw, validate it, write a patch, test it, and hand a human the evidence. OpenAI's framing is that finding bugs was never the bottleneck, and patching them at scale is.
Around the model sit three more pieces: a Codex Security plugin that finds and fixes vulnerabilities inside OpenAI's coding tool, a partner program with Cisco, Cloudflare, CrowdStrike, Palo Alto, IBM, and Wiz building on the model, and "Patch the Planet," an open-source remediation effort started with Trail of Bits and HackerOne that already has cURL, Go, and Python signed on.
Access is the catch. GPT-5.5-Cyber is restricted to vetted "trusted defenders," not the general public, because a model this good at fixing vulnerabilities is also better at exploiting them.
The number, and the asterisk
OpenAI says GPT-5.5-Cyber scored 85.6% on CyberGym, a benchmark for cyber tasks, the highest it has recorded from a single model and up from 81.8% for plain GPT-5.5. That is the verified claim.
The louder story online was a head-to-head: that the new model tops Anthropic's Mythos, the powerful model the US government reportedly forced offline in June after warnings it could break into classified systems. OpenAI never makes that comparison in its own announcement, so treat the specific "beats Mythos" scoreline as community math, not an official benchmark. The contrast that is real is in tone. One widely shared post summed up the mood: OpenAI gets to flex a top cyber model without the existential-dread press tour.
The interesting part is how OpenAI positioned this.
It has one of the strongest cyber models anyone has measured, and it rolled the news out like a public-good project: help defenders, partner with governments, hand the capability out rather than warn everyone about it.
That is the opposite of the register Anthropic's Dario Amodei has lived in for years, where the message is usually that the models are so powerful they are dangerous and everyone has to be careful, which is probably why his Mythos model just got pulled offline.
