PARTNERSHIP

Cloudflare partners with OpenAI Daybreak for AI-powered vulnerability discovery at the edge.

Vulnerability Discovery and Remediation enters early access via Managed Defense. GPT-5.6 Cyber hunts authorized codebases; humans still approve every WAF rule and patch. Inference stays on OpenAI via AI Gateway.

Sep 3, 2026 · 3 min read

On September 3 Cloudflare announced Vulnerability Discovery and Remediation — early access through Cloudflare Managed Defense, delivered via the OpenAI Daybreak Defense Network. The pitch is context-aware vuln management: Cloudflare’s live traffic and WAF signals plus OpenAI Daybreak models, including GPT-5.6 Cyber, running recon, hunting, and validation against customer-authorized codebases. Findings come back with proposed custom WAF rules and code patches. No edge rule and no code fix takes effect without explicit human approval.

Where the model runs matters. Cloudflare’s blog is explicit: the harness runs on Cloudflare, prompts leave Workers through Cloudflare AI Gateway, and inference happens on OpenAI’s servers. No model inference runs at Cloudflare’s edge, and the model cannot apply any patch or rule it proposes. Engagements are invitation-only for select Enterprise / Managed Defense customers, typically starting with one authorized application and read access to Web Assets, relevant WAF controls, and Workers observability where available.

Cloudflare frames urgency with an NVD volume claim in the press release: by September 2026 the National Vulnerability Database had logged 60,475 vulnerabilities, versus 48,185 across all of 2025. Treat that as a company claim pending independent tally. CEO Matthew Prince: “If your security team is manually fighting AI-driven attacks, you’re not just burning them out—you’re losing… Pair that with the power of OpenAI GPT-5.6 Cyber, and you’re not just reacting to attacks anymore, you’re stopping them before they land.” OpenAI’s McCall McIntyre, Head of Global Cyber Partnerships: “Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely.”

The sourced facts: Managed Defense early access, Daybreak / GPT-5.6 Cyber for authorized-code recon and validation, proposed WAF + patches with mandatory human approval, inference via AI Gateway on OpenAI (not at the edge), invitation-only Enterprise path, and the NVD figures as Cloudflare’s claim. One-line context only: Cloudflare’s July 8 research pilot was a different search-indexing deal — not this product lead.

Sources