OpenAI Launches GPT-5.6-Cyber, Raising Dual-Use AI Cybersecurity Risks

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

OpenAI has launched GPT-5.6-Cyber, an advanced AI model capable of finding and exploiting software vulnerabilities, as part of its expanded Daybreak cybersecurity program. While designed to help defenders, the model's dual-use nature and reduced refusals for high-risk tasks raise concerns about potential misuse and future AI-powered cyberattacks.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly describes an AI system (GPT-5.6-Cyber) with advanced capabilities to find and exploit software vulnerabilities, which is a clear AI system involvement. The use is primarily for security research and defense, with safeguards and controlled access tiers, indicating responsible use. No actual harm or incident is reported; vulnerabilities found have been responsibly disclosed and fixed, so no realized harm occurred. However, the AI's capability to develop exploit chains and find zero-day vulnerabilities presents a credible risk of future misuse leading to cyberattacks or breaches, fitting the definition of an AI Hazard. The event is not Complementary Information because it is not merely an update or response to a past incident but a new development with potential risk. It is not Beneficial Use because the AI's capabilities include dual-use potential that could cause harm, not solely beneficial countermeasures. Therefore, the classification is AI Hazard.[AI generated]
AI principles
SafetyRobustness & digital security

Industries
Digital security

Affected stakeholders
BusinessGovernment

Harm types
Economic/PropertyReputationalPublic interest

Business function:
ICT management and information security

AI system task:
Event/anomaly detection


Articles about this incident or hazard