OpenAI Will Give Ukraine AI Cyber Tools to Help Defend Civilian Infrastructure
The planned access would help Ukrainian teams find software flaws and test fixes. OpenAI has not reported results from the Ukraine effort.
Listen to this story
The audio brief
Story brief
3 key pointsOpenAI is extending its Daybreak cyber program to Ukraine’s Ministry of Digital Transformation, giving government defenders AI support to inspect legacy software, investigate suspicious activity, verify vulnerabilities and test repairs. The move comes as CERT-UA handled nearly 6,000 cyber incidents in 2025, amid attacks on hospitals, energy and telecommunications systems. This is an access commitment—not evidence of...
- 01
OpenAI says ENISA used its models to find vulnerabilities in software used across EU institutions; all identified flaws have since been fixed.
- 02
CERT Polska used the models to help find six vulnerabilities in third-party router software; the vendor’s fixes were confirmed to stop observed attacks.
- 03
OpenAI says defenders in France, Germany, Poland and other European countries already have access to its cyber models.
Ukraine’s teams defending civilian infrastructure are set to get AI tools for finding software weaknesses and testing repairs. OpenAI said Wednesday it would give the government access to its Daybreak cyber program, working with Ukraine’s Ministry of Digital Transformation. The offer targets the systems that keep essential services running under attack.
From finding a flaw to checking a fix
Daybreak is OpenAI’s program for giving cyber defenders advanced AI for authorized security work. The company says its tools can review older software, investigate suspicious activity, validate vulnerabilities and test fixes. For the Ukraine effort, the stated goal is to help local teams identify weaknesses and develop and test repairs more quickly.
Those steps answer different questions. Reviewing code or suspicious activity can surface a possible problem; validating a vulnerability checks whether the weakness is real. A proposed repair then needs testing of its own. OpenAI says Daybreak can help defenders with each part of that work, not just produce a list of potential flaws.
The announcement was made on the sidelines of the UN General Assembly by Dmytro Kushneruk, Ukraine’s consul general in San Francisco, and Sasha Baker, OpenAI’s head of national security policy. It describes access OpenAI will provide, rather than a completed deployment or a measured improvement in Ukraine’s defenses.
Why civilian systems are the focus
OpenAI points to persistent Russian cyberattacks alongside physical attacks on Ukraine’s infrastructure. It cites incidents affecting hospital systems, energy and telecommunications—services whose disruption reaches beyond an organization’s IT department. Ukraine’s national cyber incident response team, CERT-UA, handled nearly 6,000 cyber incidents in 2025, according to OpenAI.
OpenAI cites this figure to describe the pressure on Ukraine’s cyber defenders; it is not a count of vulnerabilities Daybreak has found.
The incident count helps explain the scale of the work, but it is not a measure of what AI assistance can resolve. Daybreak’s proposed contribution is narrower: helping defenders examine software and suspected threats, then work toward tested fixes. Whether that shortens response times for Ukrainian teams remains an outcome to establish, not one demonstrated by the announcement.
Evidence from elsewhere in Europe
Ukraine is not OpenAI’s first European cyber-defense user. The company says it has already given defenders in France, Germany, Poland and other European countries access to its cyber models. It also offers two examples in which model-assisted searches led to fixes. Those examples show what the tools have helped other defenders find; they do not predict results in Ukraine.
According to OpenAI, the EU cyber agency ENISA used its models to identify vulnerabilities in software used across EU institutions, and all the identified flaws have since been fixed. In Poland, the national cyber agency CERT Polska used the models to help find six vulnerabilities in third-party router software. The vendor released fixes that CERT Polska confirmed prevent the attacks it had observed.
The Polish example makes the intended chain tangible: a defender finds a weakness with AI assistance, a software vendor repairs it, and the defender checks the result against attacks it has seen. OpenAI’s Ukraine announcement sets out the first part of that ambition—putting the tools in defenders’ hands. Its value for civilian services will depend on the fixes teams can develop and validate.
Sources
- openai.comOpenAI extends cyber access to Ukraine for civilian defense
Reader comments
Newest comments first. Replies stay oldest first.