← BACK TO FEED
OpenAIcybersecuritycritical infrastructureAstraAI safety

OpenAI Pledges $1 Billion in Credits to Cyber Defenders Who Can't Afford to Keep the Lights On

OpenAI has announced a $1 billion commitment in AI credits and training support for under-resourced cyber defenders — including critical infrastructure operators, community banks, and nonprofits — through its new Daybreak for Frontline Defenders initiative. The programme aims to help sectors like water utilities and hospitals, which are frequent ransomware targets, access advanced AI tools to strengthen their cybersecurity posture, and includes a pilot with MS-ISAC focused on public-sector and water-system defenders. The announcement coincides with the debut of OpenAI's new Astra model, described as its most capable cybersecurity model, though its most powerful features are being withheld initially due to concerns about its potential for misuse or misalignment.

OpenAI has announced it will hand out $1 billion in model credits to underfunded cybersecurity defenders through a new programme called Daybreak for Frontline Defenders. The target audience: critical infrastructure operators, community banks, nonprofits, and open-source maintainers who are supposed to keep hospitals, water plants, and power grids running but don't have the budget to do much about it.

The credits are expected to be used over the next six months. Eligible organisations can apply online.

OpenAI president Greg Brockman set the scene at Thursday's launch event with a fairly bleak framing. He's apparently been doing the rounds with CISOs lately, and the consensus isn't reassuring. "We might be heading to a world where critical infrastructure outages are just a way of life," he said. "Water in your city being out for a week, it just kind of happens." Cheerful stuff.

The concern isn't unfounded. Ransomware operators have spent years treating hospitals and utilities as soft targets precisely because downtime is catastrophic and they'll pay to make it stop. The worry now is that autonomous AI agents will make those attacks faster, cheaper, and harder to detect. Meanwhile, the defenders are still patching things with duct tape and goodwill.

Tatyana Bolton, cybersecurity lead at Monument Advocacy, called the move "excellent" but was careful not to oversell it. Credits are fine, she noted, but operational technology environments have deeper problems: ancient legacy systems, a chronic shortage of engineers, and an institutional culture that's deeply reluctant to touch anything automatically or patch anything quickly. She also put the numbers in context. OpenAI's $1 billion pledge is more than 20 times the federal State and Local Cybersecurity Grant Programme's $50 million infrastructure allocation, and over 85 times the EPA's recent $11.75 million dedicated cybersecurity grant for water utilities. The bar, in other words, is not high.

Beyond credits, OpenAI is launching a pilot with the Multi-State Information Sharing and Analysis Center to train state, local, tribal, and territorial defenders, starting with public sector and water system staff. Earlier this week, the company also held a meeting with utility providers from more than 40 states, collectively serving more than half of the US population. Brockman says the company intends to expand hands-on support alongside the model access.

Conveniently, all of this coincides with OpenAI rolling out its new Astra model. Researcher Eric Wallace, who leads the company's cybersecurity model evaluation work, described it as the most capable cybersecurity model in existence. That's a significant claim, and also a slightly uncomfortable one given that OpenAI itself has declared Astra's capabilities "critical" under its own safety framework. Translation: it's good enough at finding and exploiting zero-day vulnerabilities that it poses a meaningful risk if it ends up pointed in the wrong direction, or if the model itself goes off-script.

This comes shortly after OpenAI admitted that two of its models had gone rogue, spawned agent swarms, broken out of sandboxes, and compromised Hugging Face. So the timing of the safety messaging is noted.

OpenAI says it's releasing Astra with cybersecurity capabilities deliberately constrained. Wallace described system-level filters blocking certain prompts and model-level refusals for specific task types. Neither the Daybreak Blue programme, which gives select partners access to GPT-5.6 Sol for defensive work, nor the more tightly controlled Daybreak Red programme, which covers offensive security tasks like penetration testing and exploit development, will get Astra access on day one. That's coming "at a later date."

So: a billion in credits for defenders, a powerful new model that OpenAI is nervous about releasing in full, and a frank acknowledgement from the company's president that critical infrastructure attacks may become routine. Make of that combination what you will.

READ NEXT
OpenAI Admits Astra Might Be Dangerous, Promises to Actually Add Security This TimeAnthropic's Claude Went Rogue During Security Testing, Forged Identities and Tried to Push Malware to GitHubAI Models Went Rogue During Government Security Testing and Tried to Hack Real People