Partnerships
OpenAI Offers Ukraine Daybreak Access for Civilian Cyber Defense

OpenAI announced on September 23, 2026 that it will offer the Government of Ukraine access to its Daybreak program to support the cyber defense of civilian infrastructure. Working with the Ministry of Digital Transformation, OpenAI will provide Ukrainian teams with access to tools that identify software vulnerabilities and develop and test fixes more quickly.
Announced at the UN General Assembly
The announcement was made on the sidelines of the UN General Assembly by Dmytro Kushneruk, the Consul General of Ukraine in San Francisco, and Sasha Baker, Head of National Security Policy at OpenAI.
OpenAI describes Daybreak as giving cyber defenders access to advanced AI for authorized security work, from reviewing older software and investigating suspicious activity to validating vulnerabilities and testing fixes.
“Ukraine is already on the front line, and its defenders need support now,” Baker said. “We want to put more capable tools in their hands to help them find and fix vulnerabilities and protect the critical networks people depend on.”
According to the announcement, Ukrainian defenders face persistent cyber attacks from Russia alongside physical attacks on the country’s infrastructure, including attacks on hospital systems, the energy sector, and telecommunications.
“Ukraine has shown under the most extreme pressure that cyber defense is a central part of national security,” said George Osborne, Head of OpenAI for Countries. “Protecting civilian infrastructure means defending it against both physical and digital attacks, so people can continue to live, work and access essential services. We’re now putting our technology and resources behind that effort, helping the Ukrainian government strengthen its cyber defenses with AI.”
Ukraine’s Recorded Cyber Incident Load
CERT-UA, Ukraine’s national cyber incident response team operating under the State Service of Special Communications and Information Protection, handled 5,927 cyber incidents in 2025, a 37.4% increase over the 4,315 incidents handled in 2024, according to a Ukrainian government record published on January 12, 2026. The record attributes the rise to more intense attacks as well as to defenders’ improved detection capabilities and greater public cyber awareness.
According to the record, local authorities drew the largest number of attacks in 2025, at 2,115 incidents, and their share of the total rose from 31.8% to 35.7%. Government organizations followed with 1,170 incidents, while the security and defense sector recorded 1,039, its share nearly unchanged at 17.5% versus 18.1% a year earlier. The energy sector saw 279 incidents, and the record notes growing attacker interest in the IT sector, at 75 incidents, and medicine, at 95.
The most common incident methods were malware distribution, with 2,058 cases, and phishing, with 1,727 cases, double the 843 recorded in 2024. Malware infection accounted for 988 cases and account compromise for 425, the record states. It says professional groups including UAC-0050, UAC-0150, and UAC-0010 continued to scale operations using both automated mass mailings and targeted attacks. CERT-UA expects Russia to keep applying combined methods to obtain strategically important information — including the plans of Ukraine’s Defense Forces, defense-industrial enterprise data, and communities’ logistical and financial resources — and expects malicious software used for covert data collection, together with phishing, to remain the aggressor’s most widespread tools.
Prior Model Access for European Defenders
OpenAI states it has already provided access to its cyber models to defenders in Europe, including France, Germany, and Poland. According to the company, ENISA, the EU’s cyber agency, has used the models to identify vulnerabilities in software used across EU institutions, all of which have since been fixed. In Poland, the national cyber agency CERT Polska used OpenAI models to help discover six vulnerabilities in third-party router software; the vendor has released fixes, which OpenAI reports CERT Polska confirms prevent the attacks it observed.
The Daybreak Program and Its $1 Billion Commitment
OpenAI launched Daybreak earlier in 2026, enabling verified public and private sector defenders to use advanced AI for authorized cyber defense. Daybreak Blue supports common defensive work with the company’s mainline models, while Daybreak Red gives approved organizations access to specialized cyber models for more sensitive and technically demanding work. OpenAI states that thousands of defenders across 2,000 approved organizations and workspaces already use Daybreak, including cybersecurity companies, defense organizations, and law enforcement organizations.
On September 3, 2026, OpenAI introduced Daybreak for Frontline Defenders, committing $1 billion in subsidized Daybreak access, training, technical support, and partnerships, targeted to be consumed over six months and starting in the United States. Under a Daybreak for America effort, OpenAI said it will prioritize operators of essential services, including water and wastewater systems, electric grid operators, state and local governments, community and regional banks, nonprofits, and open-source maintainers, and it stated its intent to expand the model to partner countries in the weeks following that announcement. The September 3 announcement also included a public sector and water-focused pilot with the Multi-State Information Sharing and Analysis Center (MS-ISAC) to train and support state, local, tribal, and territorial cyber defenders, and OpenAI said partners across the Daybreak Defense Network were announcing more than 35 partner products and partner-operated services.
The Daybreak program page describes a governed cyber defense stack combining frontier models, the Codex harness, and Codex Security, organized around an agentic defense loop of inventory, discovery, dynamic validation, ownership assignment, and verified remediation. Under that model, people review consequential changes and independently verify deployed fixes. Verified defenders gain entry through Daybreak Access, which pairs more capable defensive tools with stronger verification, scope controls, and oversight, and listed use cases span secure software development, defensive operations, and authorized security testing.
The Daybreak page restates the $1 billion subsidized-access commitment over six months and notes that state and local governments, critical-infrastructure operators, community banks, nonprofits, and open-source maintainers can register interest in support to find, prioritize, and fix security vulnerabilities.












