days after OpenAI hit pause on Astra for getting too good at finding zero-days, they shipped GPT-5.6-Cyber — a model fine-tuned to stop refusing security work.
brake and gas, same week.
Daybreak is now split: Blue for defenders on GPT-5.6 Sol, Red for the orgs cleared to touch the real thing. Cyber only lives in Red.
the number that should make you sit up — in OpenAI's own hard cyber eval, GPT-5.6-Cyber finished 95%. vanilla GPT-5.6 Sol with normal guards? 1.5%. not an upgrade, a different animal.
they say it already caught ~400 live vulns, including two in Chrome's V8. one's patched, one's still under disclosure.
here's the tension i can't shake: they pulled Astra for "critical" risk, then productized cyber capability for "trusted defenders" only. caution, or the cleanest pivot of the year?
defenders needed this yesterday. but "trusted" is a line someone gets to draw. who's in, who's out.
real caution or the smartest PR move of 2026?

Top comments (0)