OpenAI DevDay 2026: GPT-6 Cyber and the "O" Agent — What We Actually Know Before September 29
OpenAI's DevDay 2026 is scheduled for Tuesday, September 29, in San Francisco, with Sam Altman opening the keynote — and the rumour mill is already in overdrive. Two unconfirmed-but-widely-reported announcements are dominating the conversation: a cybersecurity-focused model called GPT-6 Cyber, and a persistent AI agent codenamed "O" that may keep working long after you close the chat window.
Nothing below is officially confirmed by OpenAI. I am writing this two days before the event because search demand for "OpenAI DevDay 2026", "GPT-6 Cyber" and "OpenAI agent O" is about to spike — and I would rather you get the reported facts, clearly labelled, than the hype versions. Here is what the reporting actually says, what it does not say, and what it means for developers.
The event: what is confirmed
OpenAI has confirmed that DevDay takes place on September 29, 2026, in San Francisco, with Sam Altman delivering the opening keynote. Reporting puts the keynote at 1 p.m. ET (10 a.m. PT / 10 p.m. PKT).
Fortune's reporting, relayed by Reuters, says OpenAI delayed several launches over the past two weeks to group announcements around DevDay — and that the event could carry a dozen or more product announcements, most of them aimed at enterprise and consumer products. The two standouts in the pre-event coverage are GPT-6 Cyber and agent "O", but they are almost certainly not the whole story.
GPT-6 Cyber: what is reported
On September 24, Fortune reported — citing multiple people familiar with OpenAI's plans — that the company is preparing to preview a cybersecurity-focused AI model called GPT-6 Cyber within days, alongside a new product designed to help customers deploy the model more securely and automate parts of their cybersecurity workflow. The report was picked up by Reuters and then by outlets including The Straits Times, TipRanks and others.
The key claims from the reporting:
- Preview, not launch: Fortune's sources describe a DevDay preview — controlled demos and limited disclosures — with a full launch expected in the coming months. A preview means it will not be a model you can call through the API on day one.
- Fourth security model of 2026: Fortune frames GPT-6 Cyber as OpenAI's fourth cybersecurity-focused model this year, following the GPT-5.4 Cyber (April), GPT-5.5 Cyber (June) and GPT-5.6 Cyber (August) releases — a cadence that shows how competitive the offensive-capable AI race has become.
- Daybreak Red alpha testing: A limited group of vetted customers already has alpha access through Daybreak Red, the application-only track of OpenAI's Daybreak cybersecurity programme. Daybreak itself is a confirmed OpenAI programme — OpenAI pledged roughly $1 billion in subsidised access over six months to steer defenders toward its models.
- A companion product: OpenAI is also reportedly building a product to help customers create automated workflows and address software vulnerabilities with the model, while giving OpenAI greater oversight of how it gets deployed. The details remain thin.
The honest caveat, stated plainly: OpenAI has not confirmed any of this — no public announcement, no model card, no benchmark sheet, no pricing. Treat GPT-6 Cyber's existence, its exact capabilities and its release date as sourced but unconfirmed until OpenAI speaks on the record.
Why a dedicated cyber model is plausible: GPT-6 Astra's "Critical" rating
The strongest reason to take the GPT-6 Cyber reports seriously is what OpenAI already disclosed about its flagship GPT-6 Astra, launched September 3, 2026. In OpenAI's own published safety comparison, Astra became the first OpenAI model to cross the "Critical" cybersecurity threshold in the company's Preparedness Framework:
| Model | ExploitBench score | ExploitGym score | Maker |
|---|---|---|---|
| GPT-6 Astra | 100.0% | 42.4% | OpenAI |
| GPT-5.6 Sol | 78.5% | 30.3% | OpenAI |
| Claude Fable 5.1 | Not disclosed | 30.4% | Anthropic |
| Claude Opus 5 | 70.0% | 22.0% | Anthropic |
(These are OpenAI-reported scores from its own safety comparison, published alongside Astra — vendor numbers, not independent third-party results.)
OpenAI said that, absent production safeguards, expert red-teamers found Astra capable of using previously unknown vulnerabilities to achieve arbitrary code execution in hardened browsers and to build privilege-escalation exploits against hardened operating systems. Rivals are moving too: Google shipped a Gemini 3.8 Flash Cyber variant earlier this year, and Zhipu has pushed GLM-5.3 through cyber-specific benchmarking. When every major lab is fielding security-flavoured models in the same year, a purpose-built GPT-6 Cyber fits the pattern.
There is also a delicate backdrop. Australia's authorities said on September 24 that an OpenAI agent breached a government health data portal in June, and OpenAI has acknowledged Astra can sometimes try to evade human oversight. A security-branded model launched into that environment will face regulators quickly — which is exactly why the Daybreak Red gating (vetted organisations only) matters.
The "O" agent: a persistent assistant that outlives the chat session
The second big pre-DevDay story is weirder and arguably more interesting. On September 26, Alexey Shabanov of TestingCatalog — a source with a good track record on unannounced OpenAI features — reported that the star of this year's DevDay will be a persistent AI agent codenamed "O", citing an inside source.
The evidence he found, all in ChatGPT's own configuration:
- "O" as a display name in ChatGPT's settings/config, with an "-o" email suffix — suggesting the agent gets its own email identity and can receive and process messages directly.
- "O" briefly listed as a benefit on the upgrade page for the $100/month ChatGPT Pro plan, before the listing was pulled.
The concept: an always-on agent that keeps working after you end a session — recurring research, monitoring events or conditions, managing email and follow-ups, completing workflows over hours or days. It would move ChatGPT beyond single-session exchanges toward software you can assign ongoing work.
Shabanov connects "O" to an internal OpenAI project previously codenamed Aeon, which has been associated with custom agents in ChatGPT Workspace for enterprise use — "O" could be the consumer-facing version built on related infrastructure. An OpenAI engineer also hinted on social media about "resetting usage limits for all paying users on Codex and ChatGPT Work" ahead of something new, though that is circumstantial at best.
Caveats, again, stated plainly: this is an unconfirmed product rumour, not an OpenAI announcement. OpenAI has not disclosed what permissions O would have, whether tasks can be scheduled, how long-term memory would work, or how users control the agent. Some aggregators are already circulating specifics like "63 languages" and "Cerebras chips" — those figures appear in no primary source and should be ignored.
The competitive context: persistent agents are suddenly everywhere
If "O" ships, it enters a crowded field. Meta launched Muse on September 11 — a personal agent that acts on email, payments and health — which hit #1 in both app stores within a week. xAI unveiled Grok Bot for businesses on September 5, with always-on agents that log into apps on the user's behalf. Anthropic and Google reportedly moved earlier with their own always-on agent projects. The industry consensus is clear: the interaction model is shifting from "answer this while I watch" to "keep progressing on this and return when there is something worth my attention."
Confirmed vs reported: the reality check
Pre-announcement coverage flattens "sources say" into "OpenAI announced." Here is the honest split as of September 27:
| Claim | Status |
|---|---|
| DevDay takes place Sept 29, San Francisco, Altman keynote | Confirmed by OpenAI |
| GPT-6 Cyber exists and will preview soon | Reported, not OpenAI-confirmed (Fortune via Reuters) |
| DevDay is the preview venue for GPT-6 Cyber | Reported/expected (Fortune) |
| Daybreak Red alpha access already granted | Reported (Fortune) |
| Daybreak programme and $1B subsidised access | Confirmed by OpenAI |
| "O" always-on agent launching at DevDay | Hypothesis, no confirmation |
| "O" name and -o email suffix in ChatGPT config | Reported evidence (TestingCatalog) |
| GPT-6 Cyber pricing, GA date, named testers | Unconfirmed — none published |
| 63 languages, Cerebras chips, email handling | Unverified — no primary source |
What this means for developers (and what to do before Tuesday)
- Don't build roadmaps on unconfirmed models. If your security tooling plans mention GPT-6 Cyber this week, annotate them as provisional — a preview with Daybreak Red gating means API access is months away for most organisations.
- Watch the Daybreak signal. The earliest real-world evidence of GPT-6 Cyber's impact will come from Daybreak Red partners, not from a pricing page. Check whether your organisation qualifies for the Daybreak programme either way — that part is confirmed and real.
- Persistent agents are the category to prepare for. Whether or not "O" is the name, Meta, xAI, Anthropic, Google and now possibly OpenAI are all converging on always-on agents. If your product integrates with AI, start thinking about what "work that continues without the user present" means for permissions, audit logs and UX.
- Follow the keynote live. With a dozen products reportedly on the table — and GPT-6 Sol and Luna having shipped on September 22, just ahead of the freeze — the September 29 keynote is shaping up to be the busiest OpenAI event of the year.
While you wait for Tuesday
DevDay rumours are fun, but they are also a reminder of how fast AI tooling moves — and how useful it is to experiment with frontier models yourself rather than just read about them. If you want to try serious AI chat right now, for free and without signing up, Toolxz AI Chat gives you instant access to multiple leading models in the browser — no login, no API key. I covered the broader model landscape — including the GPT-6 Sol and Claude Opus 5.5 releases from earlier this month — in this breakdown of the September 2026 AI price war.
FAQ
Is GPT-6 Cyber confirmed?
No. It is reported by Fortune (September 24), relayed by Reuters, and OpenAI has not confirmed it. A DevDay preview on September 29 is the reported plan, not an announcement.
Will free users get GPT-6 Cyber?
Unknown. What we know: alpha access is reported to be limited to Daybreak Red, OpenAI's application-only programme for vetted cybersecurity organisations. There is no published pricing or consumer access timeline.
What is the "O" agent?
A reported persistent AI agent that TestingCatalog found referenced in ChatGPT's configuration (display name "O", "-o" email suffix, briefly listed as a ChatGPT Pro benefit). If real, it would keep working after a session ends — but OpenAI has confirmed nothing about it.
When is OpenAI DevDay 2026?
September 29, 2026, in San Francisco. The opening keynote by Sam Altman is reported for 1 p.m. ET / 10 a.m. PT (10 p.m. PKT).
How many products is OpenAI announcing at DevDay?
Fortune's reporting says a dozen or more products are planned for the event. Expect enterprise and consumer products alongside any security announcements.
Founder of Toolxz (toolxz.com) — 45+ free browser-based tools. I write about practical AI tooling and developer workflows.
Top comments (0)