GPT-5.5-Cyber¶
Development line: project:gpt-5-5-cyber · thread gpt-5-5-cyber
Last event: 2026-06-23 · 1 dated since 2026-06-23 · Researched: 2026-09-05 · confidence: high
What it is¶
GPT-5.5-Cyber is a legacy OpenAI model for approved defenders doing authorized red teaming, exploit validation, penetration testing, and controlled vulnerability research.
Capabilities:
- Cyber workflows: runs specialized authorized security operations.
- Refusals: lowered for higher-risk defensive tasks.
- API identifier: uses
gpt-5.5-cyber-previewin the Responses API.
Prior GPT-5.5-Cyber approval does not grant Daybreak Red. New advanced access requires separate approval.
We use Daybreak Blue for ordinary defensive work. We use Daybreak Red with GPT-5.6-Cyber for new advanced deployments. We retain GPT-5.5-Cyber only where an existing entitlement is required.
Development line¶
- 2026-06-23 — OpenAI Daybreak security communication linked to GPT-5.5-Cyber. On 2026-06-23, the GPT-5.5-Cyber thread linked to an official OpenAI Daybreak page. The link points to an official security page in the project history. The technical claims have not been researched.
What changed¶
- 2026-05-07 — GPT-5.5-Cyber entered limited preview for critical-infrastructure defenders. It reduced refusals rather than adding material cyber capability over GPT-5.5.
- 2026-06-23 — the full GPT-5.5-Cyber release reached trusted defenders in limited release. It added stronger vulnerability-finding and patching performance.
- 2026-08-10 — Daybreak Red introduced GPT-5.6-Cyber as the current specialized model for advanced authorized work. GPT-5.5-Cyber moved to legacy access terms.
How to use this¶
As of 2026-06-23, we treat this communication as a review cue for GPT-5.5-Cyber. We do not change implementation or deployment practice until we research and verify the linked source.
- Define an internal security scope covering systems you own or hold explicit permission to test. Request Daybreak access as an individual or organization. — https://help.openai.com/en/articles/20001258-openai-daybreak-trusted-access-for-cyber-overview
- Start ordinary AppSec, incident-response, malware-analysis, and patch-validation work with Daybreak Blue rather than the legacy model. — https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/
- Obtain separate Daybreak Red approval for authorized exploit development, red teaming, or penetration testing. Use
gpt-daybreak-red-latestorgpt-5.6-cyberthrough the approved API project. — https://developers.openai.com/api/docs/models/gpt-daybreak-red-latest - Test existing GPT-5.5-Cyber entitlements with a direct Responses API request using
gpt-5.5-cyber-preview. Model-listing visibility does not prove access. — https://help.openai.com/en/articles/20001259-trusted-access-for-cyber-common-issues-and-troubleshooting
Best practices¶
- Keep Trusted Access inside an internal workspace. Never route customer-facing, downstream, or third-party traffic through it. — https://help.openai.com/en/articles/20001258-openai-daybreak-trusted-access-for-cyber-overview
- Use Daybreak Blue as the default tier. Escalate to Daybreak Red only for advanced authorized work that requires specialized capability. — https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/
- Run security workflows in isolated environments. Review elevated tool actions with auto-review, and keep human oversight on high-risk tasks. — https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/
- Treat access as scoped and safeguards as active. Approval does not remove all refusals, and it never authorizes testing systems without explicit permission. — https://help.openai.com/en/articles/20001258-openai-daybreak-trusted-access-for-cyber-overview
Superseded by this¶
- 2026-08-10 — GPT-5.5-Cyber is no longer the current specialist choice for new advanced cyber deployments. GPT-5.6-Cyber is the Daybreak Red model.
- 2026-09-05 — Daybreak Blue with GPT-5.6 Sol supersedes earlier guidance starting teams on GPT-5.5 with Trusted Access. Existing GPT-5.5-Cyber approvals stay under their original terms and do not move to Daybreak Red.
Still unknown¶
- The event record is dated 2026-06-23, while the linked first-party announcement is dated 2026-06-22. We retain the event date as 2026-06-23 and track the source date separately.
- OpenAI labels GPT-5.5-Cyber legacy in current support guidance. They publish no universal retirement date, and they do not guarantee continued availability for previously approved accounts.
Sources¶
| source | title | read |
|---|---|---|
| https://openai.com/index/daybreak-securing-the-world/ | Daybreak: Tools for securing every organization in the world | 2026-09-05 |
| https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/ | Scaling Trusted Access for Cyber with GPT-5.5 and GPT-5.5-Cyber | 2026-09-05 |
| https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/ | Expanding Daybreak as the Cyber Defense Window Narrows | 2026-09-05 |
| https://help.openai.com/en/articles/20001258-openai-daybreak-trusted-access-for-cyber-overview | OpenAI Daybreak - Trusted Access for Cyber Overview | 2026-09-05 |
| https://help.openai.com/en/articles/20001259-trusted-access-for-cyber-common-issues-and-troubleshooting | OpenAI Daybreak - Common Issues and Troubleshooting | 2026-09-05 |
| https://developers.openai.com/api/docs/models/gpt-daybreak-red-latest | Daybreak Red Model | 2026-09-05 |
| https://openai.com/zh-Hans-CN/index/daybreak-securing-the-world/ | Daybreak:为世界各地的机构提供安全防护 | 2026-09-05 |
Agent brief¶
- Subject:
project:gpt-5-5-cyber, threadgpt-5-5-cyber, 1 dated events 2026-06-23 → 2026-06-23. - Practical note: As of 2026-06-23, treat this security-related official communication as a review cue for GPT-5.5-Cyber; do not change implementation or deployment practice until the linked source is researched and verified.
- Confidence: high. Dated supersedes above are the authority for what is obsolete.