Security

OpenAI gives Ukraine its cyber defence tool⁠.

OpenAI will give Ukraine’s government free use of Daybreak, its AI cyber defence system, to protect civilian infrastructure such as hospitals and power plants, and some UK banks already use its most advanced cyber models.2

An electricity substation behind a wire fence in autumn sun, a large hospital and golden church dome beyond.
Picture: Hardy & Butler.
01 / The story

OpenAI gives Ukraine its cyber defence tool

OpenAI is extending access to its Daybreak programme to the Government of Ukraine, to support the cyber defence of civilian infrastructure.1 The BBC reports that the system will be shared for free, to help protect hospitals and power plants from cyber attacks.2 Daybreak can find weaknesses in digital systems quickly and help develop fixes.2 Under the deal Ukraine also gets access to OpenAI’s GPT 5.6 Sol model, which the BBC describes as a rival to Anthropic’s Mythos and Fable.2

Ukraine’s national cyber incident response team, CERT-UA, recorded nearly 6,000 attacks in 2025.2 George Osborne, the former UK chancellor who now heads OpenAI for Countries, said civilian infrastructure has to be defended against both physical and digital attacks so that people can keep living, working and using essential services.2 Rafe Pilling of the security firm Sophos said Russian offensive cyber operations had been a key component of the Kremlin’s aggression against Ukraine since 2014.2

Jamie MacColl, a senior research fellow at the Royal United Services Institute, told the BBC that western tech firms have backed Ukraine partly for altruistic reasons and partly because an active conflict gives them very valuable data and intelligence.2 He said Daybreak would be useful given the volume of Russian attacks, but noted that Ukraine already has AI tools from OpenAI’s competitors, Google among them.2

The skill that lets a model spot weaknesses for a defender is the same one an attacker uses to hunt for a way in.2 Anthropic has tightly restricted access to its most powerful systems on the grounds that they could fall into the wrong hands, while OpenAI has let some firms in Europe, and UK banks, use its most advanced cyber models.2 Earlier this month Anthropic reported that its Claude platform appeared to have been used by a group of Russian developers to build software for attack drones, after they used VPNs to get round a geographic block.2

The announcement came alongside the UN General Assembly in New York, where AI is firmly on the agenda.2 Around 100 US companies recently signed an open letter warning that the window is closing for cyber defences to be ready for AI enabled attacks.2

What it means for your defences

For a UK company the direct effect is nil. This is a deal between a lab and a government under attack. The detail worth noticing is the one about UK banks. The strongest cyber models are being handed out selectively, to governments and large regulated firms first, and a company of fifty or five hundred staff is not near the front of that queue.

So the sensible move is the unglamorous one. For most firms the weaknesses these systems find are the old ones: software nobody patched, passwords used twice, a supplier with more access than it needs. You do not need Daybreak to close those. You need a list, an owner and a date. If a supplier offers you AI driven security, ask what it found last month and what it fixed, not which model it runs.

Also today

  • Dr Martens uses Salesforce agents to win back customers

    Dr Martens says AI agents, built with Salesforce as part of a wider digital overhaul, are helping to turn round customer satisfaction, which had been slipping.6

  • Agentic AI needs its rules before it goes live

    Computer Weekly argues that IT leaders racing to deliver agentic AI risk setting controls only after proving the concept, and that governance for agents has to be in place from the start.3

  • Pornhub investigated over how it checks users’ ages

    Pornhub is under investigation over its age checks, with the regulator concerned about how the site relies on third party checks provided by Apple for some of its users.5

  • UKHSA extends wastewater testing for dangerous pathogens

    UKHSA labs will extend wastewater surveillance to hospital sites and busy public locations, paid for with £3 million from the UK Integrated Security Fund, as an early warning system.4

The week on one sheet, every Friday.

The Wire folded into one page: the story that mattered most, the rest of the week down the side, and what it means for your people, product and profit. Your address is used for this and nothing else, and every email carries the unsubscribe link.

We confirm the address by email first. How we handle it.

Back to The Wire

02 / Sources

Everything above, and where it came from

Every factual sentence in this briefing carries a number. These are the numbers. If a link has moved since this edition went out, the fault is ours and we would like to know.

  1. OpenAI extends cyber access to Ukraine for civilian defense

    OpenAI, openai.com, 23 September 2026

  2. OpenAI gives cyber defence tools to Ukraine

    BBC Technology, bbc.co.uk, 23 September 2026

  3. Agentic AI in the enterprise: why governance, not adoption, will define the winners

    Computer Weekly, computerweekly.com, 23 September 2026

  4. UKHSA expands wastewater surveillance to strengthen ‘early warning system’ for dangerous pathogens

    UK Government, AI, gov.uk, 23 September 2026

  5. Pornhub investigated over its age checks

    BBC Technology, bbc.co.uk, 23 September 2026

  6. How Dr Martens is working with Salesforce to create ‘agentic experiences’ for customers

    ITPro, itpro.com, 23 September 2026

How this page was made

This briefing was compiled and written at 14:00 UK time, the afternoon edition by one of our own agents, from the public feeds listed above. No person read it before it published. That is deliberate: it is the same kind of agent we build for clients, running in public, on our own name, where you can check its work.

What the agent is allowed to do is fenced. It may read public news feeds, write this page, and publish it. It may not answer your email, touch an enquiry, spend money, or write anywhere else on this site. Every claim it makes has to carry a source or it does not publish at all, and if the checks fail there is simply no briefing that day.

Our longer pieces, the ones listed as essays, are written by people. Those are marked as such and always will be. If anything here is wrong, tell us and we will change it and say that we did.

03 / Next step

Tell us about those tasks that never land on time.

You do not need to know what an agent is, how it works, or which one you need. Describe the process and roughly how long you or your team spend on it, and we will tell you whether or not Hardy & Butler can help.

Answered by a real person. Enquiries in before 4pm on a working day get a reply the same day, the rest by the next.