The Pulse
OpenAI Gives Ukraine Daybreak Access for Civilian Cyber Defense
OpenAI is extending its Daybreak cybersecurity program to Ukraine’s government to help defend civilian infrastructure. The initiative will support vulnerability discovery, software analysis and testing of security fixes amid nearly 6,000 cy

AI.info Team ·
Ukraine handled 5,927 cyber incidents in 2025
Ukraine’s national cyber incident response team handled 5,927 cyber incidents in 2025, a 37.4% increase from the previous year. OpenAI is now giving the Government of Ukraine access to its Daybreak program to help civilian defenders find vulnerabilities and develop security fixes faster.
The company announced the arrangement on September 23, 2026, saying it is working with Ukraine’s Ministry of Digital Transformation. The announcement was made on the sidelines of the United Nations General Assembly by Dmytro Kushneruk, Ukraine’s consul general in San Francisco, and Sasha Baker, OpenAI’s head of national security policy.
Ukraine’s official account of the 2025 figures says local governments recorded the largest number of incidents, followed by government organizations and the security and defense sector. Energy, telecommunications and medical systems also faced attacks. The Ukrainian government’s report identifies malware distribution, phishing, malware infections and account compromises among the most common methods.
Daybreak targets software weaknesses and suspicious activity
OpenAI describes Daybreak as an access program for authorized cyber defense work. Ukrainian teams will be able to use the tools to review older software, investigate suspicious activity, validate vulnerabilities and test fixes before deployment.
The company did not identify the specific Ukrainian agencies or private operators that will receive access. It also did not disclose how many accounts will be approved, which models will be provided or when the first teams will begin using the program.
“Ukraine is already on the front line, and its defenders need support now.”
Sasha Baker, head of national security policy, OpenAI
OpenAI said the purpose is to help protect civilian infrastructure against both digital and physical attacks. The company framed the work as a defensive extension of Daybreak rather than a military deployment.
OpenAI cites European testing of its models
OpenAI said it has already provided cyber-model access to defenders in France, Germany, Poland and other European countries. The company said the European Union Agency for Cybersecurity, known as ENISA, used its models to identify vulnerabilities in software used across EU institutions, and that those issues have since been fixed.
In Poland, OpenAI said the national cyber agency CERT Polska used its models to find six vulnerabilities in third-party router software. According to OpenAI, the vendor released fixes that CERT Polska confirmed would prevent the attacks it had observed.
Those examples are claims from OpenAI’s announcement, not an independent evaluation of the tools’ performance. The company’s post does not provide technical details about the vulnerabilities, the model outputs or the testing methods used by either agency.
A broader push to subsidize cyber defense
The Ukraine initiative follows OpenAI’s September 3 announcement of a $1 billion commitment to subsidized Daybreak access, training, technical support and partnerships for frontline cyber defenders. OpenAI said that program would support essential-service operators, including utilities, state and local governments, community banks, nonprofits and open-source maintainers.
Daybreak has also been expanded into two access tiers. Daybreak Blue provides general-purpose models for work such as vulnerability discovery, incident response and secure code review. Daybreak Red provides access to purpose-trained cybersecurity models for authorized vulnerability research, exploit validation and security testing.
OpenAI says access is controlled through identity verification, account security, monitoring, approved-use restrictions and legal attestations. The company has not published a Ukraine-specific description of those controls or said whether the Ukrainian government will receive Blue access, Red access or both.
The unanswered questions sit with deployment
OpenAI’s announcement establishes the partnership but leaves its operational scope open. It does not say which civilian networks will be assessed, whether Ukrainian teams will use Daybreak directly or through government contractors, how findings will be reviewed before action, or whether the program will cover systems operated by municipalities and utilities.
Those details will determine how much the arrangement changes Ukraine’s defensive capacity. For now, the concrete commitment is access to OpenAI’s cyber tools for Ukrainian government teams, against a threat environment in which CERT-UA recorded 5,927 incidents during 2025.