OpenAI released GPT-5.6-Cyber, a specialized model designed to help security teams identify software vulnerabilities before malicious actors exploit them. The model answers up to 98.5 percent of cybersecurity queries that standard safety filters would normally block, enabling defenders to conduct thorough penetration testing and vulnerability research.

The system has already demonstrated real-world impact. OpenAI reports that GPT-5.6-Cyber uncovered two previously unknown Chrome vulnerabilities during testing, showing the model's capacity to surface genuine security flaws that could otherwise remain hidden from defenders.

OpenAI frames this as a necessary response to shrinking detection windows. The company argues that as attack tools become more accessible and automated, defenders need every advantage to stay ahead. By providing an AI system trained specifically for security research, OpenAI attempts to shift the balance back toward defensive capabilities.

Access to GPT-5.6-Cyber requires identity verification, a gating mechanism intended to prevent abuse while ensuring legitimate security professionals can use the tool. This distinction between defensive and offensive use remains contentious in the AI safety community. OpenAI's approach assumes verified identity reliably correlates with responsible intent, an assumption that history shows is often incorrect.

The move reflects broader industry tension around dual-use AI capabilities. Tools designed for defensive security work can equally serve offensive purposes if repurposed. By naming the vulnerability discovery process and limiting access through identity checks, OpenAI acknowledges this risk while betting on procedural controls.

The release comes as enterprise security teams increasingly leverage AI for vulnerability management. However, GPT-5.6-Cyber's high success rate on previously blocked queries raises questions about what safety guardrails were relaxed and why. If the model answers 98.5 percent of security queries, it suggests OpenAI substantially reduced restrictions compared to its standard models.

The two Chrome vulnerabilities