Companies & Products

AWS puts OpenAI’s Daybreak cyber models on Bedrock in one region

AWS has put two OpenAI cyber defence models on Amazon Bedrock, and it’s letting only vetted customers near them. Daybreak Red and Daybreak Blue went live on 11 August 2026 in a single AWS Region, US East (Ohio), according to the AWS machine learning blog. Getting in needs an approval programme that OpenAI runs first.

Daybreak Red provides access to GPT-5.6 Cyber, which AWS describes as a purpose-trained cybersecurity model. Daybreak Blue provides GPT-5.6 Sol with safeguards calibrated for defensive cybersecurity work. AWS calls Blue the right starting point for most security teams, covering vulnerability discovery, detection engineering and incident response. Red is pointed at vulnerability research, exploit reproduction and mitigation development.

Access levelModel behind itIntended work
Daybreak BlueGPT-5.6 SolVulnerability discovery, detection engineering, incident response
Daybreak RedGPT-5.6 CyberVulnerability research, exploit reproduction, mitigation development
Source: AWS machine learning blog, 11 August 2026.

What separates the two is the refusal threshold, the point at which a model declines a request. AWS says the lower threshold on Red comes matched with stronger identity verification, monitoring and access controls. That matters because a request to reproduce a vulnerability looks identical whether the person asking is defending a network or attacking one.

AWS and OpenAI share a belief that defenders should have the advantage. This partnership brings Daybreak Red and Daybreak Blue from OpenAI to Amazon Bedrock. AWS security teams are using both models today to analyze source code, discover vulnerabilities, and conduct red-team research.

John Sheehan, Vice President, AWS Security

There’s one result on the record. According to OpenAI, quoted in the AWS post, security researchers used GPT-5.6 Cyber through Daybreak Red to identify two previously unknown vulnerabilities in V8, the JavaScript engine used by Chrome. Chained together, that pair could enable memory corruption and a heap sandbox escape. The first was fixed and released as CVE-2026-15903.

The NVD record for that bug describes an out of bounds read and write in V8, affecting Chrome before version 150.0.7871.128. It carries a CVSS score of 8.8 from CISA’s ADP entry, though NIST’s own assessment is still pending. AWS calls it one of only four successful zero-day entries to V8 CTF in 2026, and Google’s v8CTF rules explain why that bar is high. A valid submission pays $10,000 and has to exfiltrate a flag in under five minutes with at least an 80 percent success rate.

Four successful zero-day entries in a year is a thin field, and one of them now has a model’s name on it.

Rundowns AI

The other half of the pitch is custody of your data, because a security workload feeds a model proprietary source code and unpatched vulnerability details. AWS says zero operator access is enforced at the chip, so even its own operators can’t read prompts and completions during inference. Inference data isn’t used for model training, and neither model requires you to opt into sharing data with OpenAI. Classifier-flagged traffic is retained by AWS for up to 30 days and processed programmatically, though customers can request zero data retention through their account team.

Even the gate has two names. AWS says access requires enrollment in Trusted Access for Cyber from OpenAI, while OpenAI’s own post calls the programme Daybreak Access and sends approved users to the Bedrock console or the Responses API. We covered the approval-only launch of that cyber model when OpenAI first put a queue in front of it. The drift is small, but naming is the sort of thing that stalls a procurement review, which is the same boring layer where enterprise AI keeps stalling.

So the opening is narrow: one region, one vetting queue, and no published figure for how many teams have cleared it. Watch whether Ohio gets company, and whether either company says anything about the size of that approved list.

Get the daily rundown

One email each weekday with the AI news that matters, every claim linked to its primary source.

Free, one email each weekday, unsubscribe in one click. We never sell or share your address.

Leave a Reply

Your email address will not be published. Required fields are marked *