OpenAI committed $1 billion in Daybreak model credits, training, and technical support for organizations defending U.S. critical infrastructure and under-resourced public-interest services without enterprise-scale cyber budgets. The initial six-month program covers water and wastewater utilities, electric-grid entities, state and local governments, community and regional banks, nonprofits, and open-source projects, with planned expansion to partner countries.
Daybreak is a gated offering available to verified organizations conducting authorized defensive work, with Blue and Red tiers for routine and specialized cyber-defense activities. OpenAI is piloting the service with MS-ISAC and public-sector and water-sector defenders, while using its Daybreak Defense Network and Defense Factory methodology to identify, validate, and remediate vulnerabilities with tested fixes.

See the actors and campaigns active against you right now.
9 events from the most recent confirmed update back to the earliest known activity.
OpenAI launched Daybreak earlier in 2026 as a gated service for verified public- and private-sector organizations conducting authorized defensive work. The service provides Blue and Red access tiers for routine and specialized cyber-defense tasks.
A letter backed by more than 100 firms called on frontier AI companies to provide responsible model access, funding, training, and hands-on support to under-resourced critical-infrastructure defenders. It also urged governments, organizations, cybersecurity professionals, and AI firms to prioritize defense and test systems against powerful AI-model capabilities.
OpenAI released Astra alongside its $1 billion Daybreak for Frontline Defenders pledge. The article describes Astra as OpenAI's first model to meet its "critical" cybersecurity threshold and as capable of autonomously finding and exploiting vulnerabilities in well-protected environments.
OpenAI committed $1 billion in credits, training, and technical support for organizations protecting U.S. critical infrastructure and under-resourced public-interest sectors. The six-month subsidy initially covers sectors including water, electric utilities, state and local government, regional banks, nonprofits, and open-source projects.
OpenAI published the architecture for Defense Factory, an agent-first operation designed to identify and validate vulnerabilities and prepare tested fixes for human review.
Partners in the Daybreak Defense Network announced more than 35 products and partner-operated services integrating OpenAI cyber models into enterprise-defense workflows.
OpenAI began a public-sector and water-focused Daybreak pilot with the Multi-State Information Sharing and Analysis Center. Initial participants receive Daybreak access, guided training, and hands-on support for validating, prioritizing, and remediating findings.
OpenAI held its second utility-focused gathering, attended by participants from 40 U.S. states and the District of Columbia. The represented utilities provide essential services to more than half of the U.S. population.
Following attacks on U.S. water systems, OpenAI offered affected states and utilities up to $1 million in no-cost API credits, Daybreak access, and technical assistance. Recipients used the assistance to review code and configurations, validate findings, develop patches, and confirm fixes while systems remained operational.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
6 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcetechtarget.com
Open sourcesecurityweek.com
Open sourcebbc.co.uk
Open sourcehelpnetsecurity.com
Open sourceopenai.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.