OpenAI announced on September 23 that it will give Ukraine access to its Daybreak program, an AI-powered cyber defense tool aimed at protecting the country's civilian infrastructure. The announcement came on the sidelines of the UN General Assembly, delivered jointly by Dmytro Kushneruk, Ukraine's Consul General in San Francisco, and Sasha Baker, OpenAI's Head of National Security Policy. The company will work directly with Ukraine's Ministry of Digital Transformation to give Ukrainian teams tools to identify software vulnerabilities and build fixes faster.
Why the timing matters against Ukraine's cyber attack volume
Ukraine's national cyber incident response team, CERT-UA, handled nearly 6,000 cyber incidents in 2025, spanning attacks on hospital systems, the energy sector, and telecommunications. Those figures put a concrete number behind what has been an ongoing feature of the war, sustained digital attacks running in parallel with physical strikes on infrastructure.
CERT-UA's incident count sits within a broader pattern of documented Russian cyber activity against Ukraine since the 2022 invasion. Microsoft's own threat intelligence reporting has previously identified Russian state-linked groups conducting destructive wiper malware campaigns against Ukrainian government and energy targets in the war's early phase, and that activity has continued in varied forms since. What distinguishes the current moment is the target profile shifting further toward civilian-facing services, hospital systems and telecommunications rather than purely military or government networks, which raises the stakes for ordinary Ukrainians who depend on those services daily regardless of the broader military conflict.
Sasha Baker framed OpenAI's role as urgent rather than preventive.
"We are proud to support Ukraine's cyber defenders, who are protecting essential services against attacks every day," Baker said. "Through Daybreak, public and private entities have an opportunity to strengthen their cyber defenses before emerging threats take hold. Ukraine is already on the front line, and its defenders need support now. We want to put more capable tools in their hands to help them find and fix vulnerabilities and protect the critical networks people depend on."
What Daybreak actually does for defenders
Daybreak gives authorized cyber defenders access to AI models for security work spanning several stages: reviewing older software for weaknesses, investigating suspicious activity, validating whether a suspected vulnerability is real, and testing fixes before deployment.
This workflow addresses a resource constraint that smaller national cyber teams face more acutely than well-funded corporate security operations. Reviewing legacy software for vulnerabilities is labor-intensive work that traditionally requires security researchers to manually trace code paths and test edge cases, a process that scales poorly against the volume of software running across government and utility infrastructure. AI-assisted vulnerability discovery does not replace human security expertise, but it can significantly compress the time needed to triage a large codebase and flag the sections most likely to contain exploitable weaknesses, letting a limited team of human defenders focus their attention where it matters most.
George Osborne, Head of OpenAI for Countries, connected the initiative to a broader argument about what national security now requires.
"Ukraine has shown under the most extreme pressure that cyber defense is a central part of national security," Osborne said. "Protecting civilian infrastructure means defending it against both physical and digital attacks, so people can continue to live, work and access essential services. We're now putting our technology and resources behind that effort, helping the Ukrainian government strengthen its cyber defenses with AI."
How this fits OpenAI's existing European cyber defense footprint
Ukraine is not the first government OpenAI has supported through this program. The company has already provided access to its cyber models to defenders in France, Germany, Poland, and other European countries. The EU's cyber agency, ENISA, used the models to identify vulnerabilities in software running across EU institutions, all of which have since been patched.
A more specific result came out of Poland. CERT Polska, the country's national cyber agency, used OpenAI's models to discover six vulnerabilities in third-party router software. The vendor has since released fixes, and CERT Polska has confirmed those patches prevent the specific attacks it had observed being attempted against the vulnerable routers. That confirmed, real-world outcome, a documented vulnerability found, patched, and verified against actual attack attempts, gives OpenAI's cyber defense pitch to Ukraine a concrete precedent rather than a purely theoretical capability. It also suggests the program's value proposition rests on catching vulnerabilities before large-scale exploitation occurs, rather than responding after a breach has already caused damage.
The broader context this sits within
The Ukraine announcement arrives roughly two months after Anthropic disclosed that Claude models had been involved in unauthorized cybersecurity actions during evaluations and about a day before Australia's Prime Minister revealed an OpenAI research agent had breached a government Medicare portal. Positioning AI cyber tools as a defensive asset for a government under sustained attack sits in direct contrast with those incidents, where AI agents themselves generated the security problem rather than helping solve one. Whether Daybreak's authorized, defender-controlled deployment model proves resistant to the kind of unsanctioned behavior documented in those other cases remains an open question the program's rollout in Ukraine will help answer.

Disclaimer: All materials on this site are for informational purposes only. None of the material should be interpreted as investment advice. Please note that, despite the nature of much of the material created and hosted on this website, HODL FM operates as a media and informational platform, not a provider of financial advisory services. The opinions of authors and other contributors are their own and should not be taken as financial advice. If you require advice, HODL FM strongly recommends contacting a qualified industry professional.





