OpenAI grants Ukraine Daybreak access for civilian cyber defense

OpenAI will provide the Government of Ukraine with access to its Daybreak program to support the cyber defense of civilian infrastructure. The company is working with Ukraine’s Ministry of Digital Transformation so Ukrainian teams can identify software vulnerabilities and develop and test fixes more quickly.
The announcement was made on the sidelines of the UN General Assembly by Dmytro Kushneruk, Ukraine’s Consul General in San Francisco, and Sasha Baker, OpenAI’s Head of National Security Policy. Daybreak is intended for authorized security work, giving defenders advanced AI capabilities for vulnerability review, investigation and remediation testing.
Pressure on essential services
Ukraine continues to face persistent cyber attacks from Russia alongside physical attacks on infrastructure. CERT-UA, the country’s national cyber incident response team, handled nearly 6,000 cyber incidents in 2025. The reported incidents included attacks affecting hospital systems, the energy sector and telecommunications.
Those sectors provide services that people depend on every day. OpenAI said the Daybreak access is designed to help Ukrainian defenders review older software, investigate suspicious activity, validate vulnerabilities and test fixes before threats can disrupt critical networks.
Daybreak’s role in authorized security work
OpenAI describes Daybreak as a program for cyber defenders conducting authorized work. Its tools are intended to accelerate tasks that can otherwise delay remediation, including examining software for weaknesses and verifying whether a proposed fix addresses a vulnerability.
The Ukraine initiative follows OpenAI’s provision of cyber-model access to defenders in France, Germany, Poland and other European countries. In a separate government-access effort, OpenAI technology for public-sector institutions shows OpenAI extending its technology to public-sector institutions, while the Ukraine program is focused on civilian infrastructure defense.
Examples from European deployments
ENISA, the European Union Agency for Cybersecurity, has used OpenAI’s models to identify vulnerabilities in software used across EU institutions. OpenAI said all of those vulnerabilities have since been fixed.
In Poland, CERT Polska used OpenAI models to help discover six vulnerabilities in third-party router software. The vendor released fixes, and CERT Polska confirmed that the updates prevent the attacks it observed. These cases illustrate the operational sequence Daybreak is intended to support: find a weakness, validate it, test a fix and put the remediation into use.
Business implication
For organizations responsible for hospitals, energy, telecommunications or other essential services, the practical implication is to establish authorized vulnerability-review and patch-testing processes before an incident occurs, so security teams can assess and deploy fixes with greater speed when critical systems are targeted.

