- OpenAI Daybreak brings AI cybersecurity into code review, threat modelling, and patching.
- Tanium said Daybreak pressures Malaysia’s monthly patching cycles.
OpenAI has announced Daybreak, a cybersecurity initiative that uses AI models and coding agents to support software defence for enterprise software development.
The company launched Daybreak on May 11th, according to details cited from OpenAI’s announcement. The platform combines OpenAI GPT-5.5 models with Codex Security, an agentic coding system built to work inside software repositories.
OpenAI said the system is intended to help security and development teams identify and assess software flaws earlier in the development cycle and support remediation before deployment. Daybreak is built around the “change left” approach, which places security checks earlier in the software development process.
OpenAI said the platform can support secure code review, threat modelling, and patch validation, dependency analysis, detection, remediation guidance, and vulnerability prioritisation.
How Codex Security fits into Daybreak
Daybreak’s workflow begins by creating an editable threat model from a software repository. It can then identify vulnerabilities, validate exploitability in an isolated environment, and generate and test patches with scoped access to the codebase, OpenAI says.
Codex Security is positioned as an agentic layer in Daybreak. According to OpenAI, the system can interact with software repositories and generate patches, testing fixes in isolated environments and producing remediation reports.
OpenAI describes the setup as an “agentic harness” that connects reasoning models with automated execution.
Daybreak has three access levels. The standard GPT-5.5 model is intended for general software development tasks. GPT-5.5 with Trusted Access for Cyber is designed for verified cybersecurity work, including malware analysis and vulnerability detection. The most restricted tier, GPT-5.5-Cyber, supports specialised work like authorised penetration testing and red teaming, with additional verification and security controls.
OpenAI said Daybreak builds on its earlier GPT-5.4-Cyber and has contributed to fixes for more than 3,000 vulnerabilities.
Enterprise and government partners join the programme
According to OpenAI, its Trusted Access for Cyber programme includes hundreds of organisations and thousands of individual defenders and is working with firms like Akamai, Cisco, Cloudflare, CrowdStrike, and Fortinet, NVIDIA, Oracle, Palo Alto Networks, Sophos, and Zscaler.
Government participants include the US Center for AI Standards and Innovation and the UK AI Security Institute.
OpenAI’s announcement describes Daybreak mainly in relation to repository-level assessment and patching. It does not describe full integration with pull requests or CI/CD pipelines. It also does not describe runtime telemetry or production incident response.
OpenAI has not disclosed pricing details for large codebases or detailed false-positive benchmarks.
Daybreak vs. Project Glasswing
The announcement from OpenAI follows Anthropic’s Project Glasswing, the cybersecurity initiative powered by Claude Mythos. Anthropic reportedly restricted access to Mythos because of concerns around the model’s potential offensive cyber abilities.
Project Glasswing is described as a controlled programme built around a restricted model, while Daybreak is presented as a workflow platform that combines multiple GPT-5.5 variants, Codex agents, verification systems, and enterprise partnerships.

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events, click here for more information.
Tech Wire Asia is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
