OpenAI Launches Dedicated Cybersecurity Model
OpenAI has launched GPT-5.6-Cyber, an AI model specifically designed for cybersecurity defense professionals. The model achieves a 98.5% response rate to security-related questions that are normally restricted in standard AI systems, and OpenAI has announced the discovery of two previously unknown vulnerabilities in Google Chrome. Identity verification is required for access.

OpenAI has begun offering GPT-5.6-Cyber, a specialized AI model designed for cybersecurity defense professionals. The model achieves a 98.5% response rate to security-related questions that are normally restricted for safety reasons in standard AI systems. Additionally, OpenAI has announced the discovery of two previously unknown vulnerabilities in Google's Chrome browser.
In the cybersecurity field, there has long existed a structural "asymmetry" between attackers and defenders. While attackers only need to find one breach point to succeed, defenders must seal every gap—an inherent imbalance. According to OpenAI, the time window available for defenders to act within this structure is shrinking further. As attack methods enhanced by AI become more sophisticated, the window for defenders to discover and patch vulnerabilities continues to narrow.
GPT-5.6-Cyber was developed with this situation in mind, designed to help defenders discover vulnerabilities before attackers do. Conventional AI models have broadly restricted answers to security-sensitive questions to prevent misuse. This model relaxes those restrictions specifically for defensive purposes, enabling security experts to use it in actual investigation and analysis work.
Use of the model requires identity verification. This measure is positioned as a safeguard against misuse of the model's high response capabilities. Given that the model handles highly sensitive security information, implementing a system to limit and manage users is considered essential.
In terms of concrete results, the discovery of two previously unknown Chrome vulnerabilities is presented as a tangible achievement. The discovery of "zero-day vulnerabilities"—vulnerabilities that have not yet been publicly disclosed or patched—holds particular value in the security field. If AI can autonomously identify such vulnerabilities, it has the potential to function as a tool that complements issues human experts might overlook.
The trend of applying AI to cybersecurity extends beyond OpenAI, with growing industry-wide interest in this area. However, the risk that models with equivalent capabilities could be repurposed by attackers remains structurally inseparable. The requirement for identity verification can be viewed as OpenAI's current countermeasure to this duality.
Key points for future attention include how this model will be integrated into real-world corporate and organizational security infrastructure, and how discovered vulnerabilities will be addressed. If AI-driven vulnerability discovery becomes a routine part of everyday security operations, it could bring about significant shifts in the dynamics between defenders and attackers.
This article is an original work independently written and edited by the AI issue editorial team based on factual reporting. © AI issue. Unauthorized reproduction, redistribution, or use for AI training is prohibited.