OpenAI Will Give Ukraine AI Cyber Tools to Help Defend Civilian Infrastructure

The planned access would help Ukrainian teams find software flaws and test fixes. OpenAI has not reported results from the Ukraine effort.

By 3 min read
OpenAI Will Give Ukraine AI Cyber Tools to Help Defend Civilian Infrastructure
OpenAI Will Give Ukraine AI Cyber Tools to Help Defend Civilian Infrastructure

Listen to this story

The audio brief

About 1:38
0:001:38
Read transcript
OpenAI plans to give Ukraine’s government access to its Daybreak cyber program, so teams defending civilian infrastructure can use AI to inspect software weaknesses and test repairs. The offer is being made through Ukraine’s Ministry of Digital Transformation. OpenAI says Daybreak can help defenders review older software, investigate suspicious activity, check whether a suspected vulnerability is real, and test a fix. Those are separate steps: an AI-flagged weakness still needs validation, and a repair needs to be tested before it can be relied on. The stakes are concrete. OpenAI says Russian cyberattacks have affected hospitals, energy systems and telecommunications in Ukraine. CERT-UA, the country’s national cyber incident response team, handled nearly 6,000 cyber incidents in 2025. That number describes the workload—not vulnerabilities found by Daybreak, or incidents the tools have resolved. There are examples elsewhere in Europe, though they’re not evidence of results in Ukraine. OpenAI says the EU agency ENISA used its models to identify flaws in software used across EU institutions, and all those flaws have since been fixed. In Poland, CERT Polska used the models to help find six vulnerabilities in third-party router software; the vendor’s fixes were confirmed to stop the attacks observed. OpenAI says defenders in several European countries already have access. For Ukraine, the announcement is an access commitment, not a measured deployment. The key question is whether local teams can turn that access into repairs they can verify.

Story brief

3 key points

OpenAI is extending its Daybreak cyber program to Ukraine’s Ministry of Digital Transformation, giving government defenders AI support to inspect legacy software, investigate suspicious activity, verify vulnerabilities and test repairs. The move comes as CERT-UA handled nearly 6,000 cyber incidents in 2025, amid attacks on hospitals, energy and telecommunications systems. This is an access commitment—not evidence of...

  1. 01

    OpenAI says ENISA used its models to find vulnerabilities in software used across EU institutions; all identified flaws have since been fixed.

  2. 02

    CERT Polska used the models to help find six vulnerabilities in third-party router software; the vendor’s fixes were confirmed to stop observed attacks.

  3. 03

    OpenAI says defenders in France, Germany, Poland and other European countries already have access to its cyber models.

Ukraine’s teams defending civilian infrastructure are set to get AI tools for finding software weaknesses and testing repairs. OpenAI said Wednesday it would give the government access to its Daybreak cyber program, working with Ukraine’s Ministry of Digital Transformation. The offer targets the systems that keep essential services running under attack.

From finding a flaw to checking a fix

Daybreak is OpenAI’s program for giving cyber defenders advanced AI for authorized security work. The company says its tools can review older software, investigate suspicious activity, validate vulnerabilities and test fixes. For the Ukraine effort, the stated goal is to help local teams identify weaknesses and develop and test repairs more quickly.

Those steps answer different questions. Reviewing code or suspicious activity can surface a possible problem; validating a vulnerability checks whether the weakness is real. A proposed repair then needs testing of its own. OpenAI says Daybreak can help defenders with each part of that work, not just produce a list of potential flaws.

The announcement was made on the sidelines of the UN General Assembly by Dmytro Kushneruk, Ukraine’s consul general in San Francisco, and Sasha Baker, OpenAI’s head of national security policy. It describes access OpenAI will provide, rather than a completed deployment or a measured improvement in Ukraine’s defenses.

Why civilian systems are the focus

OpenAI points to persistent Russian cyberattacks alongside physical attacks on Ukraine’s infrastructure. It cites incidents affecting hospital systems, energy and telecommunications—services whose disruption reaches beyond an organization’s IT department. Ukraine’s national cyber incident response team, CERT-UA, handled nearly 6,000 cyber incidents in 2025, according to OpenAI.

Pressure on Ukraine’s cyber defenders
Nearly 6,000Cyber incidents handled by CERT-UA in 2025

OpenAI cites this figure to describe the pressure on Ukraine’s cyber defenders; it is not a count of vulnerabilities Daybreak has found.

The incident count helps explain the scale of the work, but it is not a measure of what AI assistance can resolve. Daybreak’s proposed contribution is narrower: helping defenders examine software and suspected threats, then work toward tested fixes. Whether that shortens response times for Ukrainian teams remains an outcome to establish, not one demonstrated by the announcement.

Evidence from elsewhere in Europe

Ukraine is not OpenAI’s first European cyber-defense user. The company says it has already given defenders in France, Germany, Poland and other European countries access to its cyber models. It also offers two examples in which model-assisted searches led to fixes. Those examples show what the tools have helped other defenders find; they do not predict results in Ukraine.

According to OpenAI, the EU cyber agency ENISA used its models to identify vulnerabilities in software used across EU institutions, and all the identified flaws have since been fixed. In Poland, the national cyber agency CERT Polska used the models to help find six vulnerabilities in third-party router software. The vendor released fixes that CERT Polska confirmed prevent the attacks it had observed.

The Polish example makes the intended chain tangible: a defender finds a weakness with AI assistance, a software vendor repairs it, and the defender checks the result against attacks it has seen. OpenAI’s Ukraine announcement sets out the first part of that ambition—putting the tools in defenders’ hands. Its value for civilian services will depend on the fixes teams can develop and validate.

Sources

  1. openai.comOpenAI extends cyber access to Ukraine for civilian defense

Loading discussion...

YOUR READING SPACE

Notifications