OpenAI announced on 2026-09-23 that it will give the Government of Ukraine access to its Daybreak program, working with Ukraine's Ministry of Digital Transformation, so Ukrainian teams can find software vulnerabilities and develop and test fixes for civilian infrastructure. OpenAI describes Daybreak as giving defenders access to advanced AI for authorized security work, and says it has provided its cyber models to defenders in France, Germany, Poland and elsewhere in Europe. It reports that ENISA used the models to identify vulnerabilities in software used across EU institutions and that CERT Polska used them to help find six router-software vulnerabilities; these outcomes are OpenAI's account.
It shows OpenAI granting a national government's defenders access to its cyber models under an access program, with defender-side results reported only by OpenAI.
Key facts
As stated in the sources, with where to find them.
- The announcement was made on the sidelines of the UN General Assembly by Dmytro Kushneruk, Consul General of Ukraine in San Francisco, and Sasha Baker, OpenAI's Head of National Security Policy; OpenAI says it will work with the Ministry of Digital Transformation.Opening paragraphs
- OpenAI cites CERT-UA as having handled nearly 6,000 cyber incidents in 2025, including attacks on hospital systems, the energy sector and telecommunications.Third paragraph
- OpenAI says ENISA used its cyber models to identify vulnerabilities in software used across EU institutions, all since fixed.Closing section
- OpenAI says CERT Polska used its models to help discover six vulnerabilities in third-party router software; the vendor released fixes and CERT Polska confirms they prevent the attacks it observed.Closing section
- The post gives no terms of access, vetting criteria, model names, or number of Ukrainian users.Whole post
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Is AI shifting the balance between finding and fixing vulnerabilities?Discovery is ahead. AI finds real vulnerabilities faster than they are fixed, and simple checks overstate how often AI patches work.