
On May 11, the same day Google's Threat Intelligence Group disclosed the first confirmed case of attackers using AI to build a zero-day exploit — a 2FA bypass that a prominent cybercrime group had planned to deploy in a mass exploitation campaign — OpenAI launched Daybreak, a new agentic cybersecurity platform that embeds its GPT-5.5 models and Codex Security engine directly into the software development lifecycle. The coincidence in timing was not coordinated, but it was clarifying: the era of AI-assisted attacks has arrived, and OpenAI is betting that AI-assisted defense, built into every pull request and deployment, is the only credible response.
"The game's already begun and we expect the capability trajectory is pretty sharp," John Hultquist, chief analyst at Google's Threat Intelligence Group, told CyberScoop after the disclosure. His team was describing attacker capabilities. OpenAI's Daybreak is the defender's answer — the company's most direct move into enterprise security to date, arriving four weeks after Anthropic unveiled Project Glasswing and its Claude Mythos Preview model. In six weeks, the two largest AI labs in the world both shipped AI cybersecurity platforms. For the hundreds of millions of people whose personal and financial data sits inside software that enterprise development teams build and maintain, those two facts together define the current stakes.