AGI Soon As Possible · Deep reads on AI & tech
Article

OpenAI takes on cyber defense with Daybreak: GPT-5.5-Cyber hits 85.6% on CyberGym

2026-07-02 · 3 min read

AI is now able to find and fix software vulnerabilities faster than people can. On June 22, 2026, OpenAI announced an expansion of its cybersecurity platform Daybreak. Its dedicated model GPT-5.5-Cyber scored 85.6% on CyberGym, beating GPT-5.5 at 81.8%, alongside a Codex Security plugin, 13 partner companies, trusted access for 7 governments, and Patch the Planet, an open-source support initiative. ASAP summarizes the announcement from the primary source.

GPT-5.5-Cyber scores 85.6% on CyberGym

GPT-5.5-Cyber is a cyber-defense model that scored 85.6% on CyberGym. On the same benchmark it leads GPT-5.5's 81.8% by about 4 points. It is released in a limited way to trusted defenders.

Codex Security fixes vulnerabilities inside the code

Codex Security is a plugin that finds, validates, and fixes vulnerabilities inside Codex. It patches vulnerabilities in existing systems quickly and automatically stops new ones before they reach production. In a 3-month preview it scanned more than 30K codebases and 30M commits and fixed more than 500K findings.

13 partner companies and 7 governments

OpenAI gathered 13 security companies into the Daybreak Cyber Partner Program. Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Akamai, IBM, Accenture, and Check Point are among the participants. It also formed Trusted Access for Cyber partnerships with seven entities: Australia, Canada, France, Germany, Japan, the Republic of Korea, and EU (ENISA).

Patch the Planet protects open source

Patch the Planet is an initiative that moves vulnerabilities in widely used open-source projects from finding to fix. OpenAI founded it with the security firm Trail of Bits, with HackerOne and others collaborating. It uses AI to support exposed open-source maintainers.

Why 4 points is a big deal: defense's break-even line

On paper, the gap between 85.6% and 81.8% looks small. But in security, the remaining few percent tend to cluster on the hardest vulnerabilities. The easy ones are already caught by automated tooling, and it is that last stretch that most often turns into an actual breach. A dedicated model edging out a general-purpose one, even narrowly, suggests defense was optimized as its own objective. In other words, the headline here is not the score itself but the pivot to "defense-purpose."

What Korean practitioners should watch

Korea appearing on the Trusted Access for Cyber list as its own entry (separate from EU) is a signal for domestic security teams. From a regulatory and procurement angle, a government trusted-access roster tends to become a justification for adoption. Yet because GPT-5.5-Cyber is "released in a limited way to trusted defenders," what most practitioners can actually get their hands on soon is Codex Security. How to handle vendor lock-in and the concern of sending code outside the org becomes the real gate to local adoption.

Open questions and limits

The CyberGym score is a result in a benchmark setting and does not fully represent the varied stacks of real production. Codex Security's "500K findings fixed" likewise says nothing in the disclosed figures about severity distribution or false-positive rates. Since attackers use the same kind of AI, how long auto-patching can hold a defensive edge remains an open question. The announcement shows a direction, but verification is left to each organization's own measurement.

Source: ASAP summary of OpenAI's Daybreak expansion (June 22, 2026; GPT-5.5-Cyber at 85.6% on CyberGym vs GPT-5.5 at 81.8%, Codex Security 3-month preview scanning 30K-plus codebases and 30M-plus commits and fixing 500K-plus findings, 13 partner companies, Trusted Access for Cyber across 7 governments, Patch the Planet).

ASAP — AGI Soon As Possible

AI & tech,
read in depth

Beyond the headlines — into the context and the structure

AGI Soon As Possible · asapai.co.kr

← All posts