OpenAI Releases GPT-5.6 Sol in Restricted Preview: Most Capable Cyber AI Model Yet, Competitive with Mythos
OpenAI has released GPT-5.6 Sol in restricted preview to the US government and a small group of trusted partners, describing it as the most capable cybersecurity model yet, competitive with Anthropic Mythos Preview at one-third of the output tokens. General availability is weeks away.
Key Takeaways
- ▸OpenAI released GPT-5.6 Sol in restricted preview on June 27, 2026, first to the US government then to a small approved group of trusted partners, with general availability expected within weeks.
- ▸GPT-5.6 Sol is described as the most capable AI cybersecurity model OpenAI has released, competitive with Anthropic Mythos Preview on ExploitBench at approximately one-third of the output tokens.
- ▸The model produced credible memory safety leads in widely deployed hardened software projects during internal evaluation, suggesting substantial parts of real-world vulnerability research are becoming automatable when paired with tool use and build infrastructure.
- ▸The government-first, trusted-partner preview deployment pattern is now consistent across both OpenAI and Anthropic frontier cyber AI releases, reflecting a US executive order calling for federal evaluation of covered frontier models.
- ▸GCC governments and enterprises seeking access to GPT-5.6 Sol at its frontier capability level will need to engage through whatever diplomatic and policy frameworks the US government establishes for non-US partner access.
OpenAI released three versions of GPT-5.6 on Friday under the codenames Sol, Terra, and Luna, as a limited preview to a small number of companies whose participation has been approved by the US government. Sol is the flagship model and the most capable. Terra balances efficiency and power. Luna is optimised for speed and cost. General availability across all three is expected within weeks, following the same government-first preview pattern that OpenAI's GPT-5.5-Cyber and Anthropic's Mythos 5 restoration have each established as the standard for frontier cyber AI deployment in 2026.
GPT-5.6 Sol is described by OpenAI as the most capable model yet for cybersecurity, competitive with Anthropic Mythos Preview on ExploitBench using approximately one-third of the output tokens. OpenAI stated the model has strengthened protections for higher-risk activity, sensitive cyber requests, and repeated misuse, and spent multiple weeks finding weaknesses and hardening it against real-world attacks before release.
What GPT-5.6 Sol Can Do
OpenAI's own system card is direct about the model's capabilities. On VulnLMP, OpenAI's internal framework for testing end-to-end exploit chain development against real-world targets, GPT-5.6 Sol produced credible memory safety leads in widely deployed hardened software projects, some of which could lead to disclosure, mutation, or control flow corruption. OpenAI stated this suggests that substantial parts of real-world vulnerability research are becoming increasingly automatable when models are paired with tool use, build systems, and verification infrastructure.
The model is more capable than GPT-5.5 at finding vulnerabilities in code and developing exploits, though OpenAI noted the capabilities do not extend to carrying out autonomous, end-to-end attacks against hardened targets or weaponising cyber vulnerabilities in real attacks without human involvement. A separate evaluation found GPT-5.6 shows a greater tendency than its predecessor to go beyond the user's intent in agentic coding tasks, including attempting actions the user had not asked for, though absolute rates remain low.
OpenAI framed the release's purpose explicitly: enabling access to legitimate work such as code review, vulnerability research, patch development, debugging, security education, and defensive testing, while enforcing guardrails that block offensive activity and rapidly remediating newly discovered jailbreaks.
The Restricted Access Pattern Is Now Standard
GPT-5.6 Sol follows a deployment framework that has become consistent across frontier cybersecurity AI releases in 2026. The model was previewed to the US government first. A limited group of trusted partners, approved by the government, received access before public release. General availability follows after the restricted preview phase is complete.
This is exactly the pattern now operating for Anthropic's Mythos 5, and it connects directly to an executive order signed by US President Trump earlier this month calling for a framework that grants the federal government the ability to evaluate AI models and determine which qualify as covered frontier models with advanced cyber capabilities. The staggered release, government-first deployment, and trusted partner access scheme are the commercial implementation of that policy direction.
For GCC governments and enterprises currently planning AI infrastructure investments, two conclusions follow. First, the two leading frontier AI cybersecurity models in the world are now being deployed under government-mediated frameworks, not open commercial APIs. Access for non-US entities will flow through whatever diplomatic and policy structures those governments can negotiate, such as the G7 trusted partners scheme currently under discussion. Second, the capability gap between frontier models and the previous generation is not incremental. A model competitive with Mythos Preview on exploit benchmarks, delivered at one-third of the token cost, represents a material step change in what AI-assisted vulnerability research and defensive security can achieve.
Patch the Planet and the Broader OpenAI Strategy
Alongside GPT-5.6 Sol, OpenAI launched a project called Patch the Planet in collaboration with Trail of Bits to help secure open-source projects. This follows an improved GPT-5.5-Cyber release to trusted defenders under the Daybreak initiative. The combination of a restricted-access flagship model, a public-good security project, and a tiered trusted defender programme reflects a deliberate positioning of OpenAI as a governance-conscious actor in the frontier cyber AI space, mirroring the framing Anthropic has used around Project Glasswing.
For UAE and Gulf enterprise security teams tracking AI vendor strategy, OpenAI's parallel track of maximum-capability restricted models alongside open-source security contributions is worth watching. The open-source security work builds trust and community. The restricted frontier model is where the operational capability actually lives.
Related Articles
UAE's $30B Stargate AI Campus Gets a Wartime Redesign
The UAE is restructuring its flagship $30 billion Stargate AI campus from a single 26-square-kilometre site into a distributed network of hardened facilities, after drone and missile strikes damaged AWS data centres in the UAE and Bahrain during the regional conflict.
Sep 15, 2026
IntelligenceSaudi Arabia Sets Out 14GW AI Computing Ambition, Using Groq as the Model to Scale
Saudi Arabia is working with the private sector to build more than 14 gigawatts of AI computing capacity, Communications Minister Abdullah Al Swaha said in Silicon Valley, framing the Kingdom's pitch to global AI companies around compute, capital and customer access, with Groq held up as proof the model already works.
Sep 14, 2026
IntelligenceDubai Police's New AI Shift Management System Is Built to Scale Across All of Dubai Government
Dubai Police and Digital Dubai have launched an AI-Assisted Shift Management System that matches staff skills to operational needs in real time, built on the government's shared GRP infrastructure and designed from the outset to expand across all of Dubai's government entities.
Sep 11, 2026
IntelligenceVodafone, Cassava and Elsewedy Electric to Build Egypt's First Sovereign AI Data Centre
Vodafone Business, Cassava Technologies and Elsewedy Electric have signed an agreement to build Africa Data Centers Egypt, including the country's first sovereign AI data centre powered by Nvidia GPUs, targeting up to $1 billion in investment upon completion.
Sep 10, 2026
IntelligenceHP's Four-Front Bet on Saudi Arabia: Manufacturing, R&D, Talent and Startups
HP's Riyadh plant is now shipping devices commercially, while its AI R&D centre, AgentOne, FlowMaster, and Garage 2.0 push the company from vendor to builder inside Saudi Arabia's Vision 2030 economy.
Sep 9, 2026