Markets World Tech USA · World
Euro Stoxx 50
6,393.27
+10.68   +0.17%
Live
FTSE 100
10,812.76
-18.76   -0.17%
Live
DAX
26,144.65
+141.33   +0.54%
Live
EUR/USD
1.1602
-0.00   -0.25%
Pre-market
CAC 40
8,271.72
-14.68   -0.18%
Live

Crypto

OpenAI puts $1 billion behind cyber defense after unveiling AI that can find zero-days

· CoinDesk

OpenAI puts $1 billion behind cyber defense after unveiling AI that can find zero-days
OpenAI Pledges $1 Billion to Arm Critical Infrastructure Against AI-Powered Cyberattacks

OpenAI is committing $1 billion in subsidized access to its artificial intelligence models, training and technical support for organizations that keep essential services running, a direct response to fears that AI-enabled attacks will soon overwhelm under-resourced cyber defenders at water utilities, power grids and local governments.

The initiative, called Daybreak for Frontline Defenders, was unveiled Thursday by OpenAI President Greg Brockman during a summit at the company's headquarters attended by roughly 300 security leaders. The company expects participating organizations to draw on the credits over the next six months.

"I've spent a lot of time over the past couple weeks talking to CISOs, and I think that we're at a place where the median response is that we might be heading to a world where critical infrastructure outages are just a way of life," Brockman said during the event. "Water in your city being out for a week, it just kind of happens, and that's quite scary. We have to act, and that's one of the reasons we're really putting our money where our mouth is."

The program targets the defenders charged with securing services people rely on daily but who lack the budgets or staffing to deploy advanced models and agentic technology. Water systems, electrical utilities and hospitals have become attractive targets for ransomware operators seeking to halt operations and extract payments, as well as government-backed operatives aiming to disrupt critical services.

OpenAI is structuring the effort around two pillars. The first, Daybreak for America, focuses on US-based organizations including water and sewer operators, electricity providers, state and local governments, regional banks and nonprofits. The second, called the Daybreak Defense Network, involves more than 35 technology and cybersecurity partners embedding OpenAI's cyber models into their products and services. The company said it plans to expand the program to partner countries in the coming weeks.

As part of Daybreak for America, OpenAI is launching a pilot with the Multi-State Information Sharing and Analysis Center (MS-ISAC), the central information-sharing body for state, local, tribal and territorial governments. The pilot will pair Daybreak access with guided training and hands-on assistance for an initial group of public-sector and water-system defenders, helping them validate findings, coordinate remediation and develop repeatable approaches.

OpenAI said it has previously provided up to $1 million in free API credits, Daybreak access and technical support to states and operators hit by attacks on US water systems. Those resources were used for code and configuration review, patch development and verification.

The company also published the design philosophy for a continuing mechanism called Defense Factory this week, which aims to support defenders through the full cycle from vulnerability discovery and validation to preparing fix patches.

Astra reaches 'critical' capability threshold

The announcement coincided with the release of Astra, which OpenAI described as its most capable model to date and the first to reach the "Critical" threshold under its Preparedness Framework for cybersecurity. That classification means the system can detect unknown vulnerabilities and develop operational exploits on hardened systems without human guidance at every step.

Astra achieved a perfect 100% score on the public ExploitBench benchmark. In an internal test built from 20 recent high-severity V8 vulnerabilities, designed to rule out training contamination, the model posted much higher code-execution rates than GPT-5.6 Sol while consuming fewer tokens. The assessment uncovered two actual zero-day vulnerabilities that Astra incorporated into an exploit chain; those will be reported to their maintainers.

"Astra's exploit-finding can help defenders find and patch weaknesses," OpenAI said.

Eric Wallace, who leads OpenAI's work on training and evaluating cybersecurity capabilities, called Astra the "world's most capable model for cybersecurity" during Thursday's event. He said the company is enforcing restricted cybersecurity capabilities through system-level mitigations that block certain prompts and model-level refusals that prevent specific tasks.

Participants in Daybreak Blue and Daybreak Red will not have access to Astra on day one. Daybreak Blue is a restricted tier for select partners authorized to use GPT-5.6 Sol for defensive workflows such as secure code review, malware analysis and patch validation. Daybreak Red requires additional approval layers and uses GPT-5.6 Cyber for authorized offensive security actions including proof-of-concept exploit development, penetration testing and red teaming. Wallace said OpenAI is working to make Astra available to both programs "at a later date."

The rollout comes after a turbulent period for OpenAI's safety record. Earlier this summer, an OpenAI agent broke out of its test environment and accessed Hugging Face's systems. OpenAI said Astra itself was not involved in that breach, but some training was paused for two weeks while the company strengthened infrastructure, isolation and monitoring. Reinforcement learning resumed on August 28.

Chief Scientist Jakub Pachocki acknowledged that Astra uses a method called opaque recurrence, which hides chain-of-thought monitoring — the process researchers use to review why a model made a particular decision. "As model capabilities are increasing, monitorability is getting more challenging," he said, noting that more capable systems can solve harder problems using few language tokens, or none.

Tatyana Bolton, cybersecurity lead at public affairs firm Monument Advocacy, called the commitment "excellent" and said AI in operational technology is inevitable, so operators must prepare now. "Initiatives like this help OT personnel get familiar with AI tools, learn how to operationalize them safely, and develop proactive defense strategies before threats escalate," she said.

But she cautioned that software credits alone will not solve underlying challenges. "OT environments suffer from legacy technology limitations, a shortage of engineering resources, and severe risk-aversion toward automated changes or rapid patching," Bolton said.

She put the scale of the pledge in context: OpenAI's single commitment is more than 20 times larger than a $50 million federal State and Local Cybersecurity Grant Program infrastructure allocation, and over 85 times larger than the Environmental Protection Agency's most recent $11.75 million dedicated cybersecurity grant pool for midsize and large water utilities.

The urgency stems from a sobering assessment shared by many national security experts: disruptions will likely become more severe as attackers increasingly use autonomous agents and AI tools to carry out intrusions. OpenAI said the program will allow lesser-resourced utilities to review legacy code, analyze suspicious activity, identify and validate vulnerabilities, prioritize the most serious risks, and develop and test security patches.

Yet the company acknowledged that expanding services and training does not solve all the security problems that have plagued critical infrastructure for decades. Many entities also need more workers who understand the nuances of protecting the physical systems they are trying to defend from digital threats.

This week, OpenAI held a meeting with utility companies from more than 40 states that collectively serve more than half of the US population. The company said its broader Daybreak program, which launched in the first half of 2026, already counts 2,000 certified organizations and workspaces among its users, including security firms, defense-related organizations and law enforcement agencies.

Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.