# ack3 Is Verified for OpenAI Daybreak Blue

> ack3 is verified under OpenAI's Trusted Access for Cyber and holds Daybreak Blue access. What the program is, and why verified access to OpenAI's cyber models matters.

- Canonical: https://ack3.ai/research/ack3-verified-for-openai-daybreak-blue/
- Published: September 8, 2026
- Authors: Josef Gattermayer
- Category: Announcement
- Topics: announcements, ai, audit, security

ack3 is verified under OpenAI's Trusted Access for Cyber and holds Daybreak Blue access.

## What Daybreak Blue is

[Daybreak](https://openai.com/daybreak/) is OpenAI's cybersecurity program for verified defenders, and Trusted Access for Cyber is the verification behind it. Daybreak Blue, the program's standard tier, gives access to OpenAI's cyber models with the safeguards configured for defensive work: vulnerability discovery and triage, secure [code review](/research/glossary/code-review/), threat modeling, and patch validation. It runs GPT-5.6 Sol, one of the two models that cleared the human baseline in [our private benchmark](/research/benchmarking-frontier-models-on-unpublished-audits/) with 33 verified critical and high findings on five unpublished audits against 32 in the human reports, and it is the route OpenAI has set for wider access to [Astra](https://openai.com/index/path-to-astra/), the first model to reach the Critical cyber threshold of its Preparedness Framework. None of this is generally available: access requires cybersecurity verification of the business.

## Why verified access matters now

a16z's [Chart of the Week](https://www.a16z.news/p/chart-of-the-week-experience-skills) of September 4, 2026 shows exploitation turning parabolic: just under 87% of exploited vulnerabilities are now exploited on the day of disclosure or before, and the median time to exploit is one day. The window for patching after disclosure is gone; the bug has to be found before the attacker finds it. AI is what changed the attacker's side, and not only frontier models: GLM, DeepSeek and Kimi K3 find exploitable bugs and scale in a way human attackers never did. Cybersecurity verification keeps OpenAI's cyber models away from that side. A security review run with them works with a model the attacker does not have.

The consequence for anyone running software worth attacking: review everything whose compromise would hurt, the whole system including integrations and infrastructure, and review it with every change, not once a year.
