OpenAI Reportedly Set to Preview GPT-6 Cyber at DevDay

A specialized cybersecurity model for penetration testing and red teaming could debut at OpenAI’s San Francisco DevDay on September 29

Alex Barrientos Avatar
Alex Barrientos Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • OpenAI may preview GPT-6 Cyber at DevDay, targeting penetration testing and red teaming.
  • Access requires application review, identity verification, and a FIDO2 hardware security key under Daybreak Red.
  • OpenAI commits $1 billion in subsidized Daybreak access to protect essential services and infrastructure.

Fortune, citing people familiar with OpenAI’s plans, reports that OpenAI could preview GPT-6 Cyber within days. The most likely venue is its DevDay event in San Francisco on September 29, 2026, though OpenAI has not confirmed the model or the announcement.

The timing carries weight. According to an EY survey, 96% of senior security leaders view AI-enabled cyberattacks as a significant threat, and roughly 48% believe at least a quarter of their recent incidents were AI-enabled. A specialized model for defensive security work would arrive directly into that pressure.

What GPT-6 Cyber Is Reportedly Designed to Do

Fortune describes a model built specifically for authorized vulnerability research, not general-purpose use.

According to Fortune and people familiar with OpenAI’s plans, GPT-6 Cyber is intended to support penetration testing, which means simulated attacks on systems an organization owns or has explicit permission to test. It would also reportedly support red teaming, a form of structured adversarial testing designed to find weaknesses before attackers do. Malware analysis, exploit validation, and patch validation are also among the reported use cases, though “automated patch verification” has not been independently confirmed in the available GPT-6 Cyber reporting.

Fortune also describes an unnamed companion product designed to help customers deploy the model securely and automate cybersecurity workflows. Its architecture, pricing, supported integrations, and technical design remain unknown.

The model is not expected to be broadly available immediately. Fortune reports a wider launch within months rather than days.

Who Gets Access and How

OpenAI’s Daybreak program gates access behind application review, identity verification, and hardware security keys.

OpenAI’s existing Daybreak documentation confirms a tiered access framework for authorized cybersecurity work. The broader Blue tier covers defensive tasks on systems users own or are authorized to test.

Under the more restricted Red tier, applicants must submit an application and pass identity verification. They must also hold an eligible paid plan, Advanced Account Security, and at least one FIDO2 hardware security key, a physical device used to confirm identity. Meeting those individual requirements does not by itself guarantee Red tier access; model-specific approval is a separate step.

OpenAI’s published Daybreak documentation lists GPT-5.6-Cyber as available under the Red tier with that additional approval. It does not independently confirm GPT-6 Cyber. Reported testing of GPT-6 Cyber through Daybreak Red, according to Fortune’s sources, currently involves a limited group of customers.

OpenAI has stated it is committing $1 billion in subsidized Daybreak access over six months to protect essential services and digital infrastructure. How many organizations will qualify, what the eligibility criteria look like, and how OpenAI will measure defensive outcomes remain open questions.

The Problem No Access Tier Fully Solves

A model capable of finding vulnerabilities faster can also help the wrong people exploit them faster.

The dual-use reality is straightforward. A tool that helps a security team work faster on vulnerability analysis could offer the same speed advantage to someone with worse intentions. OpenAI’s tiered access design, with application review, identity verification, and model-specific approvals, is a direct structural response to that risk.

Whether OpenAI confirms GPT-6 Cyber at DevDay on September 29 is the first question worth watching. The second is what the model’s actual benchmarks, pricing, and stay safe conditions look like once they are public.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →