OpenAI is extending its Daybreak cyber defense program to the Government of Ukraine, giving the country's defenders access to advanced AI models for finding and fixing software vulnerabilities in civilian infrastructure. The announcement came on the sidelines of the UN General Assembly, from Dmytro Kushneruk, Ukraine's Consul General in San Francisco, and Sasha Baker, OpenAI's Head of National Security Policy.

Daybreak is a gated program, not a public API: authorized cyber defenders get model access for reviewing older software, investigating suspicious activity, validating vulnerabilities, and testing fixes. Working with Ukraine's Ministry of Digital Transformation, OpenAI says the aim is to help Ukrainian teams identify flaws and ship patches faster.

The pressure is measurable. CERT-UA, Ukraine's national cyber incident response team, handled nearly 6,000 cyber incidents in 2025, according to a Ukrainian government source cited by OpenAI, with hospital systems, the energy sector, and telecommunications among the targets.

Ukraine is not the first recipient. OpenAI has already provided cyber model access to defenders in France, Germany, and Poland. ENISA, the EU's cyber agency, used the models to identify vulnerabilities in software deployed across EU institutions — all since fixed. In Poland, CERT Polska used the models to find six flaws in router software made by a third-party vendor, which has since shipped patches that CERT Polska says stop the attacks that were observed.

OpenAI frames the arrangement as extending to public and private entities the chance to strengthen defenses before emerging threats take hold. Sasha Baker, the company's head of national security policy, said Ukraine's defenders need support now and that Daybreak puts more capable tools in their hands. George Osborne, who heads OpenAI for Countries, said the company is putting its technology and resources behind Ukraine's effort to strengthen cyber defenses with AI.

Why it matters

This puts a gated defensive AI capability inside an active conflict zone, where civilian infrastructure absorbs cyber attacks alongside physical strikes. ENISA and CERT Polska demonstrate the models can surface real, exploitable flaws in widely deployed software. Ukraine's operational tempo and threat landscape are different — the open question is whether Daybreak shortens patch cycles at scale under wartime conditions.

Our take

Daybreak remains controlled-access, so its value depends on how fast Ukrainian teams fold it into existing vulnerability management workflows — not on how capable the models look on paper. The ENISA and CERT Polska precedents are encouraging, but neither faced the volume or simultaneity of attacks CERT-UA handles daily. That makes Ukraine the first real stress test of the program's limits.

Series: 1. Hugging Face Confirms Breach Affected Internal Datasets and Credentials · 2. OpenAI Ships GPT-5.6-Cyber Through Gated Daybreak Red — Not a Public API Release · 3. OpenAI Details AI Security Strategy After Its Own Models Breached Hugging Face in Eval · 4. OpenAI Pauses Frontier RL Training After Astra Model Shows Critical Cyber Capabilities · 5. OpenAI designates Astra as first model at Critical cybersecurity capability threshold · 6. Google launches Fairwind Program: gated Gemini 3.8 Flash Cyber for defenders via CodeMender · 7. Google DeepMind ships Gemini 3.8 Flash — third Flash in six weeks, with a gated Cyber SKU · 8. OpenAI rolls out GPT-6 Astra — limited orgs first, then Plus/Pro/API; Daybreak cyber unlocks later · 9. NemoClaw CVE lets a malicious page reach host Ollama and poison the agent model · 10. OpenAI says it skipped a dedicated disclosure when agents used public wikis during evals · 11. Trail of Bits: GPT-5.6-Cyber escapes a QEMU/KVM sandbox three times, including with 0-days · 12. Prime Intellect: frontier models bypass “offline” eval sandboxes via inference API remote fetch · 13. OpenAI extends Daybreak cyber access to Ukraine for civilian defense · AI Cyber Defense

Sources