OpenAI’s New Cybersecurity Push: GPT-5.6 Sol Can Find Software Vulnerabilities, Access Restricted to Trusted Defenders
- byPranay Jain
- 12 Aug, 2026
Artificial intelligence is becoming an increasingly important tool in cybersecurity. OpenAI has now expanded its efforts in this area with GPT-5.6 Sol, a model designed to handle demanding cybersecurity and vulnerability-research tasks.
Rather than making its most advanced cyber capabilities freely available for every user, OpenAI says enhanced access is being provided through its Trusted Access for Cyber program to verified individuals and organizations working on authorized defensive tasks.
What can GPT-5.6 Sol do?
GPT-5.6 Sol is OpenAI's strongest cybersecurity model to date, according to the company. It is designed to assist security teams with tasks such as secure code review, vulnerability research, threat modelling, malware analysis, detection engineering and patch validation.
OpenAI says the model has made significant gains on cybersecurity benchmarks. On ExploitBench, GPT-5.6 Sol scored 73.5%, compared with 47.9% for GPT-5.5 at a comparable output-token budget.
AI can help discover previously unknown vulnerabilities
One of the most important applications of these models is vulnerability discovery.
OpenAI says its cybersecurity work has already helped identify vulnerabilities in widely used software, including Google's V8 JavaScript engine. The company's Daybreak initiative says OpenAI researchers found and reported five exploitable vulnerabilities in V8, including vulnerabilities that were identified and fixed shortly after being introduced.
Finding vulnerabilities before criminals can exploit them could give security teams valuable time to develop and deploy patches.
Why isn't everyone getting access?
Cybersecurity AI is a dual-use technology. The same capabilities that can help a security researcher find and fix a vulnerability could potentially be misused to attack systems.
Because of this, OpenAI has created a Trusted Access for Cyber framework. Verified defenders can receive access to enhanced cyber capabilities for legitimate work, while safeguards continue to restrict activities such as credential theft, malware deployment and unauthorized exploitation.
OpenAI says it is also using identity verification, monitoring, access controls and other safeguards around its most capable cybersecurity models.
AI is becoming more capable at cybersecurity
The rapid improvement of AI in cybersecurity is significant. OpenAI's latest evaluations show that GPT-5.6 Sol is better at identifying and fixing vulnerabilities than at reliably carrying out complete attacks against hardened targets. The company says the model does not cross its current Cyber Critical threshold.
At the same time, OpenAI has acknowledged that advanced models can discover novel attack paths. In a July 2026 security incident involving an internal evaluation with Hugging Face, OpenAI reported that models including GPT-5.6 Sol identified and chained vulnerabilities in a testing environment. The incident reinforced the need for stronger containment, monitoring and access controls.
What does this mean for cybersecurity?
The development points toward a future where AI can work alongside security researchers to scan large codebases, identify suspicious weaknesses, investigate threats and help developers create fixes much faster.
However, the technology also highlights the importance of strong safeguards. As AI becomes better at finding vulnerabilities, companies will need to ensure that these capabilities are directed toward authorized defensive work.
For now, OpenAI's approach is clear: give verified cybersecurity professionals greater access to powerful AI tools while keeping tighter controls around capabilities that could be misused.






