EVIDENCE RECORD
August 10, 2026
OpenAI
primary source
Daybreak separates capability from access
OpenAI’s cyber-defense program shows why powerful systems need an access architecture, not only a safety paragraph.
What changed
OpenAI expanded Daybreak around governed access to advanced cyber capability, with separate defensive and red-team programs.
What the source supports
- Daybreak Blue focuses access on vetted defensive work while Daybreak Red supports controlled red-team research.
- The program references GPT-5.6-Cyber as a capability intended for qualified cyber-defense use.
- Access, monitoring, and safeguards are presented as part of delivery rather than policy placed outside the product.
Architecture consequence
High-capability systems need explicit admission, role boundaries, task scoping, monitoring, escalation, and revocation. The reusable lesson is to design access as a state machine whose evidence can be reviewed.
Creator translation
Even lower-risk creator agents benefit from capability tiers. Separate read, draft, transform, publish, and spend permissions so speed never erases authorship or approval.
Open the creator specimenUseful next move
Contribute before asking.
Release a capability-access matrix that teams can adapt for creator agents, including evidence requirements and the exact action that needs human approval.