Skip to main content
Back to Blog
AI
Security
Enterprise AI
Governance
Strategy
Vendor Management
Leadership

The Best Security AI Now Requires a Permission Slip.

Jason Oglesby

By Jason Oglesby · August 11, 2026

Ask OpenAI's standard model a hard cybersecurity question and it answers about 1.5 percent of the time.

Ask the version they just released to vetted defenders and it answers 95 percent of the time.

Same company. Same underlying technology. The difference is whether somebody approved you.

OpenAI shipped GPT-5.6-Cyber this week as part of an expanded Daybreak program. It arrived days after the company paused work on Astra, a model that hit the critical cyber threshold in its own preparedness framework. The message is not subtle. OpenAI is deciding, case by case, who gets to use the sharp version.

Two Tiers, One List

Daybreak now runs in two lanes. Blue gives approved organizations access to the standard frontier model without system-level cyber guardrails. Red gives a smaller group GPT-5.6-Cyber for exploit validation, penetration testing, and red team work.

The organizations named as having access are Accenture, IBM, CrowdStrike, Cisco, and Palo Alto Networks.

Read that list again and notice what it is. Those are five of the largest security vendors and integrators on the planet. They are not the companies most likely to be breached. They are the companies most likely to sell you the thing that stops the breach.

Capability Is Being Allocated Now, Not Sold

For thirty years, enterprise technology worked on a simple rule. If you could afford it, you could buy it. Budget was the gate.

That rule just broke for one category.

You cannot purchase GPT-5.6-Cyber. You qualify for it, or you do not. The gate is a vetting process at a private company, and the criteria are not published in any detail you could plan against.

I want to be fair about why. A model that answers 95 percent of advanced offensive security questions is genuinely dangerous in the wrong hands, and OpenAI just watched a more capable model trip its own critical threshold. Gating it is the responsible call. I would make the same call.

But responsible and comfortable are different things. If your company is a regional bank, a hospital system, or a manufacturer with 400 employees, you are not getting on that list. Your access to the best defensive AI now runs through whoever you buy security from.

Your Security Stack Just Became an AI Access Decision

This changes a procurement conversation you are probably not having yet.

When you renew with a managed security provider next quarter, the interesting question is no longer just detection rates and response times. It is what tier of model access they hold, what they actually do with it, and whether that capability shows up in your environment or just in their marketing.

Most vendors will not volunteer this. Ask directly. Do you have Daybreak access, or the equivalent from another lab. Which tier. What workflows run on it. What changed in my coverage because of it.

A vendor who cannot answer that in specifics is selling you last year's product with this year's vocabulary.

The Asymmetry Did Not Go Away

Here is the part nobody in a press release will say plainly.

Attackers do not apply for access. They are not waiting on a vetting queue at a US company. They use whatever is available, including models with no guardrails at all, and they were never going to fill out a form.

So the gating protects against a real risk, and it also means the defenders who follow rules operate at a permission-based disadvantage against people who do not. That is not an argument against the gate. It is an argument for being clear-eyed about what the gate does and does not accomplish.

What it accomplishes is real, though. The Daybreak security plugin has scanned more than 30 million commits across 30,000 codebases since March. Fixing vulnerabilities at that scale is worth more than any single defender's model access.

What I'd Do This Week

Ask your security vendors what model access they hold. Use the vendor names. If they hedge, that is your answer.

Stop budgeting AI security capability as a license. It is a relationship now. Which means vendor selection carries more weight than it did eighteen months ago and switching costs more than the contract says.

Get your own house in order first. The attacks that worked in every recent incident were weak passwords, exposed endpoints, and injection. No model tier fixes a debug page you left open.

Push your industry group. Regional banks, hospital systems, and utilities have collective weight that no single mid-market company has. Access programs respond to organized demand.

The Part That Matters

We spent two years arguing about who would be able to afford AI.

The real question turned out to be who would be allowed to use it.

If you are not on the list, what you still control is the vendor you choose and the basics you finish.

Finish them.