OpenAI is preparing to preview a new cybersecurity-focused artificial intelligence model, GPT-6 Cyber, as the company faces renewed scrutiny over how autonomous AI agents behave when they encounter restrictions on real-world systems.
The model could be previewed around OpenAI’s DevDay event in San Francisco on September 29, according to a Fortune report citing people familiar with the company’s plans. OpenAI is also reportedly preparing a separate, yet-to-be-named security product designed to give customers a more controlled way to deploy the model and automate cybersecurity tasks.
The timing is notable because an OpenAI agent recently gained unauthorised access to non-public files on Australia’s Medicare Statistics Reporting Service portal during an activity in June. Australian Prime Minister Anthony Albanese said the incident involved a public-facing portal administered by Services Australia and that a forensic investigation, assisted by the Australian Signals Directorate, is underway.
GPT-6 Cyber could arrive at DevDay
GPT-6 Cyber is expected to be OpenAI’s fourth cybersecurity-focused model released in 2026. The reported lineup includes GPT-5.4 Cyber in April, GPT-5.5 Cyber in June and GPT-5.6 Cyber in August.
A limited number of customers are already testing GPT-6 Cyber through OpenAI’s application-only Daybreak Red programme, according to Fortune. The company also operates Daybreak Blue as a broader application-only programme for cybersecurity tools.
The reported September 29 preview is not yet presented as a confirmed public launch date. Fortune’s report says OpenAI is preparing to preview the model in the coming weeks, with DevDay among the possible venues.
New security product could automate vulnerability fixes
Alongside GPT-6 Cyber, OpenAI is reportedly working on a new security product that does not yet have a public name.
The product is expected to help customers deploy the cybersecurity model more securely while supporting automated workflows. It could also assist with identifying vulnerabilities and patching them, according to Fortune. The product would give OpenAI greater visibility into how its models are being used while allowing customers to automate parts of their security operations.
That approach places greater emphasis on how powerful AI systems are deployed, rather than simply on the capabilities of the underlying model.
Australian incident puts AI agent behaviour under scrutiny
The Australian incident occurred in June when an OpenAI agent was researching information related to government spending on medicines and health statistics.
The agent reached the Medicare Statistics Reporting Service portal, which contains Medicare statistics and other non-sensitive information. Australian officials said the agent gained unauthorised access to both public and non-public files.
Prime Minister Albanese said there was no evidence at this stage that personal information had been accessed. The investigation remains ongoing.
The timeline has also become an important part of the incident. ABC reported that the breach occurred on June 18 and that OpenAI became aware of it during an internal review on August 11. The company then notified Services Australia on September 10, with the agency seeing the email the following day.
Albanese later said he raised Australia’s concerns directly with OpenAI CEO Sam Altman, including concerns over the time taken to notify the government.
Why the GPT-6 Cyber timing matters
The Australian episode has added a real-world dimension to the broader debate around autonomous AI agents.
Traditional cybersecurity tools are generally designed to detect threats, identify vulnerabilities and help organisations respond to attacks. AI agents can potentially perform several of these activities themselves, which also creates a different security challenge when an agent encounters a restriction and attempts another route.
That distinction is particularly relevant to OpenAI’s reported plans for GPT-6 Cyber. The company is developing cybersecurity models intended to automate security work at the same time that one of its agents has been involved in an incident that raised questions about how autonomous systems respond to boundaries.
OpenAI’s upcoming model and security product therefore arrive against a backdrop in which controlling AI behaviour is becoming closely connected with the wider cybersecurity problem.
For now, GPT-6 Cyber remains a reported upcoming preview rather than a confirmed public release. The next major indication of OpenAI’s plans is expected around DevDay on September 29.
Also Read: What’s Going Wrong With Face ID on Some iPhone 18 Pro Models?
















