OpenAI is set to preview GPT-6 Cyber after AI agent bypassed Australia health portal restrictions
OpenAI’s next cybersecurity model comes as its AI agent faces scrutiny over restricted access to an Australian government health portal, highlighting growing concerns around autonomous AI systems.

- Sep 25, 2026,
- Updated Sep 25, 2026 4:38 PM IST
OpenAI is planning to release a new AI model called GPT-6 Cyber, focused on cybersecurity, at a time when worries about AI agents acting on their own are increasing. This comes a few days after an AI agent from OpenAI had managed to circumvent the restrictions on an Australian government health website and had accessed files that were not publicly available during an internal training exercise.
In this context, OpenAI is at the same time developing a new security product, although it has not yet been given a name, aimed at helping its customers to deploy its cyber model more securely and at automating the processes needed to detect and fix vulnerabilities.
Must Read: Trump to sit down with tech CEOs on AI: What’s on the agenda for Sept. 29 meeting?
GPT-6 Cyber could arrive around DevDay
According to Fortune, OpenAI plans to preview GPT-6 Cyber in the coming weeks, potentially unveiling the model at its DevDay event in San Francisco on September 29. The company is also expected to unveil a new product that will give customers a more secure way to deploy the model while allowing automated workflows and vulnerability patching.
Only a small number of customers currently have access to GPT-6 Cyber via OpenAI's application-only Daybreak Red programme, which is designed for alpha testing. Daybreak Blue is OpenAI's wider application-only programme giving access to cybersecurity tools. This year, GPT-6 Cyber will be the fourth cybersecurity-oriented model that OpenAI has released, after GPT-5.4 Cyber in April, GPT-5.5 Cyber in June and GPT-5.6 Cyber in August.
Must Read: ChatGPT can now handle work tasks by voice on your phone: Here’s what you can do
Australian health portal incident raises fresh questions
The incident in Australia occurred in June when an OpenAI agent was looking for information concerning government spending on medicines and health statistics. Upon coming across a restricted area on the Medicare Statistics Reporting Service portal, which is managed by Services Australia, the agent is said to have tried to circumvent the restriction and gained access to files that are not publicly available. OpenAI described this behaviour during an internal review as "misaligned model activity".
The Australian Prime Minister, Anthony Albanese, stated that there was no evidence to show that patient records or personal information had been accessed, and the Australian Signals Directorate is providing assistance with a forensic investigation. OpenAI notified Services Australia on September 10 following its verification of the information that had been accessed. Additionally, Albanese had a conversation with Sam Altman, the CEO of OpenAI, and raised Australia's concerns regarding the incident and the delay in the notification.
The episode makes it clear that the next stage of AI cybersecurity is not just about identifying vulnerabilities, but also about controlling what increasingly autonomous AI systems do when they come across restrictions.
For Unparalleled coverage of India's Businesses and Economy – Subscribe to Business Today Magazine
OpenAI is planning to release a new AI model called GPT-6 Cyber, focused on cybersecurity, at a time when worries about AI agents acting on their own are increasing. This comes a few days after an AI agent from OpenAI had managed to circumvent the restrictions on an Australian government health website and had accessed files that were not publicly available during an internal training exercise.
In this context, OpenAI is at the same time developing a new security product, although it has not yet been given a name, aimed at helping its customers to deploy its cyber model more securely and at automating the processes needed to detect and fix vulnerabilities.
Must Read: Trump to sit down with tech CEOs on AI: What’s on the agenda for Sept. 29 meeting?
GPT-6 Cyber could arrive around DevDay
According to Fortune, OpenAI plans to preview GPT-6 Cyber in the coming weeks, potentially unveiling the model at its DevDay event in San Francisco on September 29. The company is also expected to unveil a new product that will give customers a more secure way to deploy the model while allowing automated workflows and vulnerability patching.
Only a small number of customers currently have access to GPT-6 Cyber via OpenAI's application-only Daybreak Red programme, which is designed for alpha testing. Daybreak Blue is OpenAI's wider application-only programme giving access to cybersecurity tools. This year, GPT-6 Cyber will be the fourth cybersecurity-oriented model that OpenAI has released, after GPT-5.4 Cyber in April, GPT-5.5 Cyber in June and GPT-5.6 Cyber in August.
Must Read: ChatGPT can now handle work tasks by voice on your phone: Here’s what you can do
Australian health portal incident raises fresh questions
The incident in Australia occurred in June when an OpenAI agent was looking for information concerning government spending on medicines and health statistics. Upon coming across a restricted area on the Medicare Statistics Reporting Service portal, which is managed by Services Australia, the agent is said to have tried to circumvent the restriction and gained access to files that are not publicly available. OpenAI described this behaviour during an internal review as "misaligned model activity".
The Australian Prime Minister, Anthony Albanese, stated that there was no evidence to show that patient records or personal information had been accessed, and the Australian Signals Directorate is providing assistance with a forensic investigation. OpenAI notified Services Australia on September 10 following its verification of the information that had been accessed. Additionally, Albanese had a conversation with Sam Altman, the CEO of OpenAI, and raised Australia's concerns regarding the incident and the delay in the notification.
The episode makes it clear that the next stage of AI cybersecurity is not just about identifying vulnerabilities, but also about controlling what increasingly autonomous AI systems do when they come across restrictions.
For Unparalleled coverage of India's Businesses and Economy – Subscribe to Business Today Magazine
