OpenAI expands Daybreak Cyber Partner Program to security firms

OpenAI announced an expansion of its Daybreak Cyber Partner Program, which puts its frontier cyber models into the hands of security and technology companies rather than giving individual organizations direct access. The company frames this as closing a defense gap: attackers can already find vulnerabilities and build exploits at machine speed, while most security teams cannot access the frontier models that would let them do the same on defense, and even once a vulnerability is found, the harder work is judging which ones actually matter and getting a fix into production.

The program now includes security and services partners Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group and SpecterOps, alongside technology partners Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet and Cloudflare. These firms already have relationships with the organizations they protect and knowledge of those organizations' systems; OpenAI says folding its models into that existing work, rather than asking each customer to build its own AI security program, is the point of the arrangement. Depending on the engagement, partners can use the models for vulnerability discovery and validation, red teaming, penetration testing, incident response, and remediation across complex enterprise systems.

Access runs through a system called Daybreak Access, split into two tiers. Daybreak Blue covers a broad range of defensive security workflows. Daybreak Red is reserved for more specialized, closely governed work such as red teaming and penetration testing. Critically, the underlying models stay with the approved partner and are not handed directly to the end customer: partners set the boundaries of each engagement, review the findings the models produce, and apply their own judgment before anyone acts on them. OpenAI says safeguards around this controlled access can include identity verification, defined testing scopes, logging, monitoring and human oversight, depending on the work involved.

The announcement does not name a launch date, disclose pricing or licensing terms for Daybreak Access, identify the specific cyber models involved, or say how many organizations are currently using the program or how long the listed partners have been part of it. OpenAI directs organizations that want Daybreak capabilities to contact their existing cybersecurity provider or OpenAI's sales team, and points prospective new partners to openai.com/daybreak/partners.

Key facts

  • OpenAI is expanding the Daybreak Cyber Partner Program, giving named security and technology firms access to its frontier cyber models rather than giving customers direct access.
  • Partners include Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group and SpecterOps on the security and services side, and Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet and Cloudflare on the technology side.
  • Access runs through Daybreak Access in two tiers: Daybreak Blue for broad defensive workflows, and Daybreak Red for closely governed work such as red teaming and penetration testing.
  • Model access stays with the approved partner, not the end customer; partners set engagement boundaries, review findings and apply their own expertise before action is taken.
  • OpenAI did not disclose pricing, a launch date, specific model names, or how many organizations currently use the program.

Why it matters

OpenAI is positioning this as a response to an asymmetry it says favors attackers: AI already lets attackers find vulnerabilities and build exploits faster than most defenders can respond, while frontier models capable of matching that speed on defense have mostly stayed out of reach for the organizations that need them. Rather than selling that capability directly to every company, OpenAI is routing it through security providers that already have the customer relationships and system knowledge to use it effectively.

Who it affects

The immediate beneficiaries are the sixteen named partners: security and services firms Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group and SpecterOps, and technology firms Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet and Cloudflare. Their customers gain indirect access to OpenAI's cyber models through the products, managed services and engagements those partners already run, without needing to build or operate their own AI security programs.

How to use it

Access is granted through Daybreak Access, offered in two tiers. Daybreak Blue supports a broad range of defensive security workflows. Daybreak Red is designed for more specialized, closely governed work, including red teaming and penetration testing. Organizations that want these capabilities are told to contact their existing cybersecurity provider or speak with OpenAI's sales team; the underlying models are never transferred directly to the customer, only used by the partner on the customer's behalf. Companies interested in becoming a partner can apply at openai.com/daybreak/partners.

How solid is it

This is a first-party announcement from OpenAI's own blog, not an independently verified report. It names real, established partners and describes concrete program mechanics (the Blue/Red tiers, the safeguards), but it carries no date for the expansion, no customer or usage numbers, and no technical detail on the models themselves, so the scale and pace of the rollout cannot be checked from this piece alone.

Risks and caveats

OpenAI names no pricing or licensing terms for Daybreak Access, no version or benchmark information for the 'frontier cyber models' involved, and no figure for how many organizations are already using the program versus how many partners are newly added. The safeguards described for controlled access, identity verification, defined testing scopes, logging, monitoring and human oversight, are described only in general terms with no detail on how they are enforced or audited.