OpenAI gives Ukraine’s government access to Daybreak cyber tools
Announced on the sidelines of the UN General Assembly, the deal puts OpenAI’s vulnerability-hunting models in the hands of a country whose national CERT handled nearly 6,000 incidents in 2025.

Key takeaways
- OpenAI will give Ukraine’s government Daybreak access to find and fix software vulnerabilities.
- CERT-UA handled nearly 6,000 cyber incidents in 2025, hitting hospitals, energy and telecoms.
- France, Germany and Poland already have access; Poland’s CERT found six router flaws with it.
OpenAI said on Wednesday, September 23, that it will give the Government of Ukraine access to Daybreak, its programme for putting frontier models to work on defensive cybersecurity. The announcement was made on the sidelines of the UN General Assembly in New York by Dmytro Kushneruk, Ukraine’s consul general in San Francisco, and Sasha Baker, OpenAI’s head of national security policy.
Working with Ukraine’s Ministry of Digital Transformation, OpenAI will give Ukrainian teams tools to find software vulnerabilities and to develop and test fixes faster. The company’s framing is direct. “Ukraine is already on the front line, and its defenders need support now,” Baker said.
The scale of the problem it is aimed at
The number that anchors the announcement is 6,000. Ukraine’s national incident response team, CERT-UA, handled nearly that many cyber incidents in 2025, including attacks on hospital systems, the energy sector and telecommunications. George Osborne, who runs OpenAI for Countries, said Ukraine “has shown under the most extreme pressure that cyber defense is a central part of national security”.
What is being handed over is not a bespoke tool. Daybreak launched on June 22 as OpenAI’s umbrella for authorised security work, built around a cyber-tuned model and the Codex Security plugin, with a “Trusted Access for Cyber” scheme that requires institutional verification and human oversight. An August 10 update described two tiers: Daybreak Blue, running GPT-5.6 Sol with defensive safeguards for everyday tasks, and Daybreak Red, running GPT-5.6-Cyber for sensitive exploit and vulnerability work. The Next Web reported that Ukraine’s access includes GPT-5.6 Sol and is free. OpenAI’s own post states neither the cost nor the duration.
Where Ukraine fits in a bigger programme
Ukraine is joining a queue rather than starting one. OpenAI says it has already given cyber-model access to defenders in France, Germany, Poland and others; in Poland, CERT Polska used the models to help find six vulnerabilities in third-party router software. In June the company listed trusted-access arrangements with Australia, Canada, France, Germany, Japan, South Korea and the EU’s cyber agency, ENISA.
On September 3 OpenAI went further with “Daybreak for Frontline Defenders”, a $1 billion commitment of subsidised access, training and support aimed at water and grid operators, local governments, small banks, non-profits and open-source maintainers, meant to be used over about six months, starting in the United States and expanding to partner countries. At that point the company said roughly 2,000 approved organisations and workspaces were using Daybreak. The Ukraine post does not say whether this access is drawn from that pool.
Why a company gives this away
The generous reading is the one OpenAI offers: defenders lack money and attackers do not. The commercial reading is that a government CERT operating under sustained attack is the hardest possible test of whether these models find and fix real vulnerabilities, and good results would be worth more than the compute. Both readings can be true at once.
There is also the question of what “defensive” means when a country is at war. Daybreak’s own materials draw the line at authorised security work with human oversight, and the August update described the Red tier as trained to refuse less often on exploit development for vetted users. The Ukraine post talks only of finding and fixing vulnerabilities in civilian infrastructure. Whether the ministry gets Blue, Red or both is not stated.
What to watch
Results, above all. OpenAI cited a concrete outcome for Poland, six router vulnerabilities, and will presumably want one it can cite for Ukraine. Then whether the arrangement is extended to Ukraine’s energy and telecoms operators themselves rather than only to government teams, which the post does not address. And the six-month clock on the $1 billion pool, which runs to roughly March 2027 and will show how much of it reaches the small operators it was pitched at.
- OpenAI
- Cybersecurity
- Daybreak
- Ukraine
- AI companies
Sources
- OpenAI extends cyber access to Ukraine for civilian defense — OpenAI, Sep 23, 2026
- OpenAI opens its Daybreak cyber defence programme to Ukraine — The Next Web, Sep 23, 2026
- Daybreak: Tools for securing every organization in the world — OpenAI, Jun 22, 2026
- Expanding Daybreak as the Cyber Defense Window Narrows — OpenAI, Aug 10, 2026
- Daybreak for Frontline Defenders: $1B to protect essential services — OpenAI, Sep 3, 2026
Related stories

OpenAI agent broke into an Australian government portal, PM says
Anthony Albanese says an OpenAI research agent got around the blocks on a Medicare statistics portal on June 18, read non-public files and wrote files to the server. OpenAI took until September 10 to say so, by email to a public mailbox.
4 min read

Alibaba plans a 10-trillion-parameter Qwen and 20 GW of data centres
At its Apsara Conference in Hangzhou on Tuesday, Alibaba showed the Zhenwu V900 accelerator, set a 20-gigawatt capacity target for 2032 and said its next Qwen generations will be two to four times the size of the current flagship.
4 min read

Amazon blocks Meta's Muse AI agent from shopping on its store
Amazon says it first asked Meta to take its store out of Muse, without success. The dispute looks set to turn on terms of service rather than hacking law.
4 min read
Comments
No comments yet. Start the conversation.