Ukraine becomes a named Daybreak deployment
OpenAI announced on 23 September that it will offer the Government of Ukraine access to its Daybreak cyber-defence programme, working with Ukraine’s Ministry of Digital Transformation. OpenAI says Ukrainian teams will receive tools to identify software vulnerabilities and develop and test fixes more quickly for civilian infrastructure. The announcement was made on the sidelines of the UN General Assembly by Ukraine’s consul general in San Francisco, Dmytro Kushneruk, and OpenAI head of national security policy Sasha Baker.
The stated scope is civilian cyber defence. OpenAI points to persistent attacks on Ukrainian hospitals, energy systems and telecommunications and cites nearly 6,000 incidents handled by CERT-UA in 2025. The company’s announcement does not describe offensive cyber operations or a military deployment, so the evidence here supports only the authorised defensive use OpenAI has specified.
Daybreak is built around authorised vulnerability work
OpenAI describes Daybreak as controlled access to advanced cyber models for authorised security work, including reviewing older software, investigating suspicious activity, validating vulnerabilities and testing fixes. Its broader Defense Factory reference architecture places cyber agents inside isolated, reproducible environments with policy enforcement, credential controls, audit mechanisms and human review around consequential changes.
That reference architecture helps explain how OpenAI expects defensive agents to be used, but it is not a published diagram of the Ukrainian deployment. The company has not specified which Daybreak models, model versions, supporting agents or infrastructure Ukrainian teams will receive, nor whether every control in the reference architecture will be used in the same way.
OpenAI points to earlier European deployments
OpenAI says it has already provided cyber-model access to defenders in France, Germany, Poland and other European countries. It says ENISA used the models to identify vulnerabilities in software used across EU institutions and that those flaws were fixed. OpenAI also says CERT Polska used its models to help discover six vulnerabilities in third-party router software and that the vendor released fixes.
Those examples are useful context for the programme’s intended workflow, but the reviewed sources are OpenAI’s own account rather than an independent performance audit. The Ukraine announcement is more specific about the institutional partner and civilian-infrastructure purpose, while leaving operational results for the new deployment to be demonstrated after access is active.
Access timing and operational results remain open
OpenAI’s wording is prospective: it says it “will offer” access and “will provide” Ukrainian teams with tools. The announcement does not give an activation date, identify the Ukrainian teams that will use Daybreak, state whether access is free or paid, specify a duration, or publish terms for data handling, logging and retention. Those details should not be inferred from other Daybreak deployments.
OpenAI’s announcement establishes the commitment and planned collaboration with Ukraine’s Ministry of Digital Transformation. It does not yet confirm completed rollout, independent Ukrainian operational results, reduced incident rates or the effectiveness of Daybreak against attacks on civilian infrastructure. Those are the material evidence points to watch as the programme moves from announcement to use.