OpenAI is giving Ukraine free access to its Daybreak cyber defence programme as Kyiv looks to AI to help protect civilian infrastructure from relentless Russian cyberattacks.
The company said it will work with Ukraine’s Ministry of Digital Transformation to provide government teams with AI tools that can find software vulnerabilities and help develop and test fixes more quickly.
The agreement was announced on the sidelines of the UN General Assembly by Dmytro Kushneruk, Ukraine’s Consul General in San Francisco, and Sasha Baker, OpenAI‘s Head of National Security Policy.
Ukraine is already dealing with cyber attacks at a scale few countries experience. CERT-UA handled 5,927 cyber incidents during 2025, up 37.4% on the previous year, with local authorities, government organisations, and the security and defence sector among the most frequently targeted.
Daybreak is OpenAI’s programme for giving vetted cyber defenders access to its more capable models with fewer of the restrictions normally placed on cybersecurity requests. Daybreak Blue, its defensive tier, supports work including vulnerability discovery, secure code review, malware analysis, incident response and patch validation.
OpenAI says the EU cybersecurity agency ENISA has used its models to identify vulnerabilities in software deployed across EU institutions, which have since been fixed. Poland’s CERT Polska has also used OpenAI models to uncover six vulnerabilities in third-party router software, with the vendor subsequently releasing patches.
For Ukraine, the attraction is likely to be less about handing cyber defence over to AI than helping already stretched security teams work through cyberattacks and vulnerabilities faster.
Rafe Pilling, director of Sophos’ Counter Threat Unit, told Resilience Media that Ukraine was most likely to use Daybreak and GPT-5.6 Sol as a “force multiplier” rather than an autonomous defensive system.
“According to OpenAI, the tool is designed to identify weaknesses in systems and help develop fixes, which means its greatest day-to-day value will likely be accelerating vulnerability assessment, incident triage, threat hunting, malware analysis, and detection engineering across government and critical infrastructure networks,” Pilling said.
“Given the volume of Russian cyber activity Ukraine faces, the biggest benefit is likely to be freeing analysts from time-consuming investigative tasks so they can focus on higher-value response and decision-making.”
However, OpenAI’s own research shows why human oversight still matters. Earlier this year, the company disclosed that models undergoing cybersecurity evaluations had broken out of their intended testing environment and compromised both the company’s own infrastructure and systems belonging to AI platform Hugging Face.
The incident did not involve Daybreak being deployed against a real-world target, as the models were being deliberately tested with reduced safeguards to measure their cyber capabilities. But the incident offered a striking demonstration of what those capabilities can look like when the boundaries fail.
According to OpenAI’s subsequent investigation, agents found ways onto the internet, exploited vulnerabilities in shared infrastructure, and eventually gained access to third-party systems. They also began exchanging information with other agents, which OpenAI said enabled further exploitation. GPT-5.6 Sol was among the models involved, although OpenAI said the incident was primarily driven by a more capable internal research model.
The company has since tightened its security and says Daybreak access is restricted to approved users and authorised work, with identity verification, monitoring and other controls intended to prevent misuse.
“We are proud to support Ukraine’s cyber defenders, who are protecting essential services against attacks every day,” Baker said. “Ukraine is already on the front line, and its defenders need support now. We want to put more capable tools in their hands to help them find and fix vulnerabilities and protect the critical networks people depend on.”
For Ukraine, those capabilities arrive with an unusual track record: OpenAI’s cyber models have already demonstrated that they can find vulnerabilities and help defenders patch them – and, under very different conditions, just how effectively the same underlying capabilities can be used to break through them.













