Quick Facts
- Unit 42’s expanded Frontier AI Exposure Analysis service uses GPT-5.6-Cyber, which completes 95% of exploit-chain, authentication bypass, and privilege escalation tasks in OpenAI’s internal benchmark.
- 36% of exposures the service identifies map to no known CVE, typically because they require multiple gaps to be discovered, chained, and tested together.
- Access to the underlying models stays with approved partners only — customers receive findings and remediation plans, not direct model access.
Palo Alto Networks announced on Aug. 12 that its Unit 42 consulting arm will deploy OpenAI’s frontier cyber models directly inside customer environments. The expanded service, called Unit 42 Frontier AI Exposure Analysis, searches applications and network assets for vulnerabilities, misconfigurations, leaked credentials, and unmanaged attack surfaces.
The models reach Unit 42 through OpenAI’s Daybreak program, which expanded on Aug. 10 with two access tiers. Unit 42 uses the higher tier, Daybreak Red, which runs on GPT-5.6-Cyber — a purpose-trained model built for authorized vulnerability research, exploit validation, and penetration testing.
OpenAI’s internal Advanced Cybersecurity Completion Rate benchmark shows GPT-5.6-Cyber completing 95.0% of requests across exploit-chain development, authentication bypass, and privilege escalation scenarios. That compares to 1.5% for safeguarded GPT-5.6 Sol and 2.0% for Daybreak Blue access. Its predecessor, GPT-5.5-Cyber, completed only 57.3% of comparable requests.
The jump addresses a persistent complaint from security researchers: that general-purpose AI models refuse too many requests during legitimate offensive security work.
How the Service Works
Unit 42 runs adversary simulation against findings to confirm whether an exposure is actually exploitable and how far an attacker could travel once inside a network. A multi-model harness assigns each task to whichever model handles it best. Human reviewers stay in the loop throughout.
Consultants direct the models and validate results using Palo Alto Networks telemetry and Unit 42 threat intelligence. The team then produces a remediation plan ranked by which fixes break the most attack paths.
GPT-5.6-Cyber has already found five vulnerabilities in a major mobile operating system, including a privilege-escalation chain from untrusted apps. It also uncovered three critical remote code execution issues in a widely used database and more than 400 privilege-escalation flaws in a popular OS kernel.
Partner Program Structure
Sixteen companies have access through the Daybreak program. Nine are security and services firms: Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps. Seven are technology partners: Palo Alto Networks’ Unit 42, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare.
The program is structured so model access stays with the approved partner. Customers receive findings and remediation guidance, not direct access to the underlying models.
Safety Controls
Under OpenAI’s Preparedness Framework, GPT-5.6-Cyber is classified as “High” in cybersecurity capability. It has not reached the “Critical” threshold, and it remains a human-in-the-loop tool. OpenAI is separately evaluating whether its upcoming Astra model requires stronger controls based on preliminary testing showing autonomous capability at sophisticated cyber tasks.
New safeguards accompany the release. Starting Sept. 1, 2026, hardware security keys will be mandatory for all Daybreak accounts. Access requires identity verification, legal attestations, and approved-use restrictions. Each project can be scoped with defined testing boundaries, logging, and monitoring.
What It Means for Security Teams
Since Unit 42 introduced an earlier version of the service in May, the team has briefed more than 1,000 security teams worldwide and brought hundreds of customers onto its Frontier AI Defense service.
“Securing the modern enterprise requires pairing frontier AI with deep cyber expertise and scalable managed services,” said Simone Gammeri, Chief Partnerships Officer at Palo Alto Networks. “We are expanding our joint reach to give more enterprises access to accelerated threat detection, automated response, and true operational resilience.”
The 36% figure — exposures with no matching CVE — is the number security leaders should watch. It signals that traditional vulnerability databases miss a material share of real attack surface, particularly where multiple smaller gaps combine into a viable intrusion path.
Read more: Palo Alto Networks to run OpenAI cyber models inside customer networks
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
