OpenAI Extends Daybreak AI System to Ukraine for Civilian Infrastructure Protection

NewsDesk
4 Min Read
OpenAI's Daybreak AI protects Ukrainian infrastructure | AI-Generated Image

OpenAI is providing its Daybreak AI cyber defence system at no cost to Ukrainian authorities to shield hospitals, power plants and other civilian sites from digital assaults, according to a report published by BBC News. The initiative grants access to the company’s advanced GPT 5.6 Sol model, which functions as a rival to offerings from competitors such as Anthropic. CERT-UA, Ukraine’s national cyber incident response team, recorded almost 6,000 attacks throughout 2025, a figure that underscores the scale of the threat environment.

George Osborne, who heads OpenAI for Countries after serving as UK chancellor, stated that protecting civilian infrastructure means defending it against both physical and digital attacks so people can continue to live, work and access essential services. The Daybreak platform enables rapid detection of vulnerabilities in digital systems while supporting the development of corresponding fixes, OpenAI’s documentation on the Defense Factory initiative established in July 2026 indicated. This deployment aligns with OpenAI’s Trusted Access for Cyber framework, which the company introduced in February 2026 to extend frontier models to verified defenders.

Rafe Pilling, senior director of threat intelligence at cybersecurity firm Sophos, said Russian offensive cyber operations had been a key component of the Kremlin’s aggression against Ukraine since 2014. Any initiative that strengthens Ukraine’s already highly capable but heavily burdened cyber defence efforts is a welcome development and could provide a valuable force multiplier, Pilling added in comments to BBC News. Sophos assessments have tracked consistent Russian-linked activity targeting Ukrainian networks over more than a decade.

OpenAI has separately moved against Russian-speaking actors who attempted to leverage its models for offensive purposes, including the creation of malware loaders, credential stealers and command-and-control infrastructure, according to the company’s October 2025 safety report. A June 2025 OpenAI case study on Operation ScopeCreep detailed the banning of accounts tied to a Russian-language threat actor that used the models to refine Windows malware and evasion techniques. These enforcement actions illustrate the company’s dual focus on restricting malicious applications while expanding defensive capabilities to trusted partners.

WithSecure researchers identified a Russian-linked advanced persistent threat known as GREYVIBE that has incorporated commercial AI platforms, including OpenAI’s ChatGPT, into attacks on Ukrainian military, government and civilian entities since August 2025. The group employed the tools to generate obfuscation routines, loader scripts and post-compromise commands, WithSecure’s May 2026 analysis found. Such activity has accelerated the shift toward AI-augmented operations on both sides of the cyber conflict.

OpenAI’s partnership with Ukraine forms part of a wider expansion of its Daybreak Cyber Partner Program, which now includes collaborations with firms such as CrowdStrike, Palo Alto Networks and Sophos to integrate frontier models into existing security workflows, an August 2026 OpenAI announcement stated. The program distinguishes between Daybreak Blue for general defensive tasks and the more restricted Daybreak Red for specialised red teaming. Ukrainian teams will operate under the vetted access protocols the company established to mitigate misuse risks while accelerating vulnerability remediation.

Share This Article
Continental Bulletin NewsDesk is the desk responsible for Continental Bulletin's daily news coverage, monitoring and reporting developments across the Gulf from official sources, including national news agencies and government communications. Its focus is accurate, timely and factual coverage of the region.