Defensive AI · News & analysis
More capable cyber AI still needs a scoped job
OpenAI’s August Daybreak expansion raises practical questions about authorized scope, security evaluation and evidence quality for defensive AI workflows.
OpenAI expanded Daybreak on August 10 with Blue and Red access tiers for approved defenders, alongside GPT-5.6-Cyber. The announcement describes different access conditions and evaluations of cybersecurity workflows, including vulnerability research and report preparation.
The provider’s results vary by task and evaluation setting. They should not be reduced to a claim that one model is best for every security job, or that access to a more capable model grants permission to test a third party’s systems.
Define the deliverable before selecting the model
Our suggested starting point is a bounded defensive task with an observable result. Examples include reviewing an internal change for a known class of bug, explaining a finding in your own repository or checking whether a proposed fix addresses a reproduced issue. The model choice should follow the task and its data requirements.
Write down what success looks like. A review might need a precise file reference, a clear explanation of impact and a test the team can run. A plausible narrative alone is not enough. Equally, a tool that rejects a task may be unsuitable for that workflow without being generally poor at security work.
Evaluate evidence quality as well as completion
Run a small evaluation on work your team understands. Include issues with known answers, ordinary safe changes and examples that should be escalated rather than acted on. Look at missed problems and false positives, not only whether the agent produced a response.
Keep the environment and input version fixed when comparing systems. Record which tools were available and how much human assistance the run received. This makes the result useful for a purchasing or deployment decision, instead of turning a one-off demonstration into an unsupported productivity claim.
- Set written authorization boundaries and permitted targets.
- Use isolated test data and task-specific credentials.
- Ask reviewers to assess reproducibility, impact and proposed remediation.
- Retain rejected findings so false positives can be reviewed.
Keep a human owner for the outcome
An approved defensive model can help produce a report or investigate a hypothesis. The organization still needs somebody accountable for deciding what to test, which changes to deploy and how to communicate with a software maintainer.
For most small teams, the first useful deployment will be narrow and repeatable. Pick a workflow with a clear owner and compare the resulting evidence with your existing process. Expand access when the team can show that the workflow works reliably, not simply because the underlying model can attempt more complicated tasks.
Put your security work in motion.
Book a meeting