Trending: On-device modelsSearch
iHeartGeek
iTECH

OpenAI hands Ukraine its Daybreak cyber toolkit

OpenAI is giving Ukraine's government access to its Daybreak programme so that CERT-UA can defend hospitals, energy and telecoms after nearly 6,000 incidents in 2025.

OpenAI's announcement card for the Ukraine cyber-access post: the words OpenAI extends cyber access to Ukraine for civilian defense in white type over a blue and yellow gradient.

OpenAI will give the Government of Ukraine access to Daybreak, its programme for handing security teams advanced AI, so that Ukrainian defenders can find and fix software vulnerabilities faster. The company announced the move on 23 September 2026, working with Ukraine's Ministry of Digital Transformation, and put two names to it: Dmytro Kushneruk, Ukraine's Consul General in San Francisco, and Sasha Baker, who leads national security policy at OpenAI. The statement was made on the sidelines of the UN General Assembly.

What Ukraine's defenders get

Daybreak gives authorised defenders access to OpenAI's models for security work: reviewing older software, investigating suspicious activity, validating vulnerabilities and testing fixes. The pressure it is meant to relieve is spelled out in the announcement. Ukraine's national cyber incident response team, CERT-UA, handled nearly 6,000 incidents in 2025, with hospital systems, the energy sector and telecommunications among the targets, alongside physical attacks on the same infrastructure.

A track record, and a warning about timing

OpenAI is presenting the grant as an extension of work already done in Europe. It has provided cyber-model access to defenders in France, Germany, Poland and elsewhere, and says the EU's cyber agency ENISA used the models to identify vulnerabilities in software used across EU institutions, all of which have since been fixed.

In Poland, the national agency CERT Polska used OpenAI's models to help discover six vulnerabilities in third-party router software. The vendor released fixes and CERT Polska confirms they prevent the attacks it had observed, which is the kind of detail worth noting: the vendor is publishing outcomes, not just access. Baker framed the urgency bluntly, saying Ukraine is already on the front line and its defenders need support now, and that the aim is to put more capable tools in their hands to find and fix vulnerabilities and protect the critical networks people depend on.

George Osborne, the former UK chancellor who now heads OpenAI for Countries, said Ukraine has shown under the most extreme pressure that cyber defence is a central part of national security, and that protecting civilian infrastructure means defending it against both physical and digital attacks.

Our opinion

Grants of AI capability to governments are easy to announce and hard to judge, so the part of this that actually matters is the Polish router finding. Six vulnerabilities discovered by a national agency, patched by a vendor and confirmed fixed is a measurable result, and it is a better argument for the programme than any pledge about defending democracy. The uncomfortable half is the symmetry: the same class of models can be pointed at finding flaws or at exploiting them, and Britain, France and Germany already have access while much of the world does not, which turns a security tool into a diplomatic lever. Ukraine is a reasonable place to test that bargain, because its defenders are under sustained attack and have no shortage of targets to protect. The question readers should keep asking is not whether OpenAI's models can find bugs, but whether a capability handed over by a company for as long as it chooses can be relied on as national infrastructure.