OpenAI made its Daybreak cybersecurity models available on AWS through Amazon Bedrock on August 11, 2026. Both Daybreak Blue and Daybreak Red are now open to eligible enterprise customers inside their existing AWS environments.
Earlier this year, OpenAI frontier models and Codex became generally available on AWS. That gave enterprises a path to bring advanced AI into production. Daybreak extends that path to security work.
What Daybreak Blue and Red Actually Do
Daybreak Blue gives access to frontier general-purpose models. That includes GPT-5.6 Sol. It ships with safeguards built for authorized defensive security work.
Daybreak Red gives access to purpose-trained cybersecurity models. Those models support authorized vulnerability research, exploit validation, and security testing. Red can accelerate detection engineering and incident response, from initial discovery through a validated fix. It also supports exploit reproduction and mitigation development.
Both tiers run through the Amazon Bedrock console. You can also reach them through the Responses API using the bedrock-mantle endpoint.
Why the AWS Integration Changes the Operational Path
Adopting specialized cybersecurity tools takes more than model performance. Security review, governance, procurement, and access controls all matter too. Running Daybreak through Bedrock puts model access inside existing AWS workflows. Teams already managing those steps inside AWS get a clearer path through familiar processes.
This path is for vetted enterprise customers. SMBs without a formal security program, an active AWS environment, and the controls described below are not the intended audience. Organizations that do not yet qualify should close the attestation gaps before applying.
Enrollment Requirements Are Substantive
Daybreak Access is OpenAI's Trusted Access for Cyber program. Vetted enterprise customers and cybersecurity practitioners must apply. OpenAI reviews and approves each application. Access is not self-serve.
The program carries real obligations. Each item below is an attestation requirement. None of them are post-approval suggestions.
Security certification. Approved customers must maintain an enterprise security program with SOC 2 Type II, ISO 27001, or an equivalent certification. Both are listed as accepted certifications in the attestation requirements.
Identity controls. Required identity controls cover single sign-on (SSO), multi-factor authentication (MFA), least-privileged role management, and role-based access control (RBAC). All four apply to every workspace with TAC access.
API key governance. Customers must enforce vaulted keys, rotation and revocation procedures, per-service principals, least-privilege access, and scoped permissions. Storing keys without a vault or rotation policy does not satisfy the attestation.
Device controls. Employees with access must use enterprise-controlled devices with disk encryption, patch management, endpoint protection, and endpoint management.
Usage logging. Customers must monitor employee use for abuse and retain logs of model usage sufficient to support retrospective review of violative prompts and outputs, where feasible and lawful. Local legal limits may affect what you can retain. If your logging covers infrastructure events but not application-layer AI queries, enabling Daybreak creates a governance gap. Close that gap before you attest.
Incident response. Customers must maintain a documented incident response process for account compromise or misuse. If your security program lacks a written process for that scenario, enrollment requires one first.
AWS agreement. Customers accessing Daybreak through AWS operate under the OpenAI Services Agreement for Amazon Bedrock rather than the standard OpenAI Services Agreement.
Scope of use. TAC-backed model access may not be made available to external customers, downstream users, or other third parties. It is scoped to internal use by the approved organization only.
Data sharing authorization. The enrollment form asks whether you authorize OpenAI to share contact and approval information with AWS to enable your AWS access.
What to Check Before You Apply
Does your organization run active vulnerability research, red team, or defensive security workflows on AWS? If so, Daybreak warrants a direct evaluation. The full list of attestation requirements is in the enrollment form. That list includes additional items such as domain-specific email requirements and a potentially required separate organization ID for TAC users.
Start with the two most disqualifying gaps. First: does your organization hold SOC 2 Type II, ISO 27001, or an equivalent certification today? Second: does your logging capture application-layer AI queries, not just infrastructure events? A no to either defines the remediation work. That work should come before enrollment makes sense.