Skip to content
nanoai

OpenAI gives Ukraine’s government access to Daybreak cyber tools

Announced on the sidelines of the UN General Assembly, the deal puts OpenAI’s vulnerability-hunting models in the hands of a country whose national CERT handled nearly 6,000 incidents in 2025.

By The Nano AI Staff3 min read

Cybersecurity operations center showing OpenAI Daybreak protecting Ukraine's critical infrastructure, with a map of Ukraine, cyber defense systems, CERT-UA operators, UN imagery, and statistics on cyber incidents.

Key takeaways

  • OpenAI will give Ukraine’s government Daybreak access to find and fix software vulnerabilities.
  • CERT-UA handled nearly 6,000 cyber incidents in 2025, hitting hospitals, energy and telecoms.
  • France, Germany and Poland already have access; Poland’s CERT found six router flaws with it.

OpenAI said on Wednesday, September 23, that it will give the Government of Ukraine access to Daybreak, its programme for putting frontier models to work on defensive cybersecurity. The announcement was made on the sidelines of the UN General Assembly in New York by Dmytro Kushneruk, Ukraine’s consul general in San Francisco, and Sasha Baker, OpenAI’s head of national security policy.

Working with Ukraine’s Ministry of Digital Transformation, OpenAI will give Ukrainian teams tools to find software vulnerabilities and to develop and test fixes faster. The company’s framing is direct. “Ukraine is already on the front line, and its defenders need support now,” Baker said.

The scale of the problem it is aimed at

The number that anchors the announcement is 6,000. Ukraine’s national incident response team, CERT-UA, handled nearly that many cyber incidents in 2025, including attacks on hospital systems, the energy sector and telecommunications. George Osborne, who runs OpenAI for Countries, said Ukraine “has shown under the most extreme pressure that cyber defense is a central part of national security”.

What is being handed over is not a bespoke tool. Daybreak launched on June 22 as OpenAI’s umbrella for authorised security work, built around a cyber-tuned model and the Codex Security plugin, with a “Trusted Access for Cyber” scheme that requires institutional verification and human oversight. An August 10 update described two tiers: Daybreak Blue, running GPT-5.6 Sol with defensive safeguards for everyday tasks, and Daybreak Red, running GPT-5.6-Cyber for sensitive exploit and vulnerability work. The Next Web reported that Ukraine’s access includes GPT-5.6 Sol and is free. OpenAI’s own post states neither the cost nor the duration.

Where Ukraine fits in a bigger programme

Ukraine is joining a queue rather than starting one. OpenAI says it has already given cyber-model access to defenders in France, Germany, Poland and others; in Poland, CERT Polska used the models to help find six vulnerabilities in third-party router software. In June the company listed trusted-access arrangements with Australia, Canada, France, Germany, Japan, South Korea and the EU’s cyber agency, ENISA.

On September 3 OpenAI went further with “Daybreak for Frontline Defenders”, a $1 billion commitment of subsidised access, training and support aimed at water and grid operators, local governments, small banks, non-profits and open-source maintainers, meant to be used over about six months, starting in the United States and expanding to partner countries. At that point the company said roughly 2,000 approved organisations and workspaces were using Daybreak. The Ukraine post does not say whether this access is drawn from that pool.

Why a company gives this away

The generous reading is the one OpenAI offers: defenders lack money and attackers do not. The commercial reading is that a government CERT operating under sustained attack is the hardest possible test of whether these models find and fix real vulnerabilities, and good results would be worth more than the compute. Both readings can be true at once.

There is also the question of what “defensive” means when a country is at war. Daybreak’s own materials draw the line at authorised security work with human oversight, and the August update described the Red tier as trained to refuse less often on exploit development for vetted users. The Ukraine post talks only of finding and fixing vulnerabilities in civilian infrastructure. Whether the ministry gets Blue, Red or both is not stated.

What to watch

Results, above all. OpenAI cited a concrete outcome for Poland, six router vulnerabilities, and will presumably want one it can cite for Ukraine. Then whether the arrangement is extended to Ukraine’s energy and telecoms operators themselves rather than only to government teams, which the post does not address. And the six-month clock on the $1 billion pool, which runs to roughly March 2027 and will show how much of it reaches the small operators it was pitched at.

  • OpenAI
  • Cybersecurity
  • Daybreak
  • Ukraine
  • AI companies

Sources

  1. OpenAI extends cyber access to Ukraine for civilian defense — OpenAI, Sep 23, 2026
  2. OpenAI opens its Daybreak cyber defence programme to Ukraine — The Next Web, Sep 23, 2026
  3. Daybreak: Tools for securing every organization in the world — OpenAI, Jun 22, 2026
  4. Expanding Daybreak as the Cyber Defense Window Narrows — OpenAI, Aug 10, 2026
  5. Daybreak for Frontline Defenders: $1B to protect essential services — OpenAI, Sep 3, 2026

Follow The Nano AI: Instagram · X · LinkedIn · YouTube

Was this article helpful?

Comments

No comments yet. Start the conversation.

Be respectful. Comments are moderated.

Related stories

The AI briefing, without the noise.

The stories that matter in AI, sourced and explained. Free, and you can unsubscribe at any time.