What was announced, and what it actually covers

On September 23, 2026, OpenAI announced that it will offer the Government of Ukraine access to its Daybreak program, an arrangement that gives cyber defenders access to advanced AI models for authorized security work. The announcement was made on the sidelines of the UN General Assembly by Dmytro Kushneruk, the Consul General of Ukraine in San Francisco, and Sasha Baker, Head of National Security Policy at OpenAI.

The operational core of the deal is narrow and concrete. Working with Ukraine's Ministry of Digital Transformation, OpenAI says it will provide Ukrainian teams with tools to identify software vulnerabilities and to develop and test fixes more quickly. Daybreak's described scope runs from reviewing older software and investigating suspicious activity to validating vulnerabilities and testing fixes. That is defensive work: finding flaws before attackers do, and patching them.

This article examines what the arrangement includes, what it does not establish, and the questions of accountability that follow when a private AI company equips a wartime government's civilian defenders.

Why Ukraine: a defender under persistent attack

The strategic context is the reason this access matters. Ukraine's national cyber incident response team, CERT-UA, handled nearly 6,000 cyber incidents in 2025, according to the OpenAI announcement, which links to the Ukrainian government's own reporting. Those incidents include attacks on hospital systems, the energy sector and telecommunications. Readers should note a sourcing caveat: the nearly 6,000 figure appears in OpenAI's announcement and is attributed there to CERT-UA, but the underlying Ukrainian government page was not independently retrievable through our research tools for this article, so we rely on OpenAI's citation of it.

The pattern is not incidental. Russian military action against Ukraine has included physical attacks on infrastructure alongside persistent cyber operations, so civilian institutions that keep hospitals running and power flowing defend themselves on two fronts at once. In that environment, the marginal value of a tool that accelerates vulnerability discovery and patching is not hypothetical, though its measured effect in Ukraine's specific environment is not yet demonstrated.

Precedents in Europe, read with care

Ukraine is not the first beneficiary of this program. OpenAI states it has already provided access to its cyber models to defenders in Europe, including France, Germany, Poland and others.

Two prior deployments are cited with specific outcomes, and each deserves careful reading. The EU's cyber agency, ENISA, has used the models to identify vulnerabilities in software used across EU institutions, all of which have since been fixed. In Poland, the national cyber agency CERT Polska used OpenAI models to help discover six vulnerabilities in third-party router software; the vendor has released fixes, which CERT Polska confirms prevent the attacks it observed.

These are meaningful data points, but they are vendor-relayed and vendor-confirmed outcomes. CERT Polska's confirmation of the router fixes is the stronger of the two, because an independent national agency verified that the patches prevent attacks it observed. The ENISA case, as described, is an OpenAI summary of a partner's work. Neither establishes how the models will perform at the scale, pace and network diversity of Ukraine's wartime environment. Treat both as evidence of feasibility, not proof of effectiveness in Ukraine.

What the company says

Sasha Baker, OpenAI's Head of National Security Policy, framed the program this way in the announcement:

We want to put more capable tools in their hands to help them find and fix vulnerabilities and protect the critical networks people depend on.

Sasha Baker, Head of National Security Policy at OpenAI, statement of September 23, 2026, OpenAI announcement, https://openai.com/index/openai-extends-cyber-access-to-ukraine-for-civilian-defense/

George Osborne, Head of OpenAI for Countries, added:

Ukraine has shown under the most extreme pressure that cyber defense is a central part of national security.

George Osborne, Head of OpenAI for Countries, statement of September 23, 2026, OpenAI announcement, https://openai.com/index/openai-extends-cyber-access-to-ukraine-for-civilian-defense/

Both quotations are word-for-word from the verified primary source. Note what they claim and what they do not. Baker's statement is a commitment of intent and capability. Osborne's is a characterization of Ukraine's situation that is broadly consistent with the documented incident record. Neither is an empirical claim about measured outcomes of the program itself.

The accountability questions

Access to defensive AI is expanding to a wartime government, and that raises accountability questions that the announcement does not fully resolve.

First, who is accountable for use? The arrangement runs through Ukraine's Ministry of Digital Transformation, a civilian body, and Daybreak's stated scope is authorized defensive security work. The civilian framing matters: this is presented as protecting hospitals, power grids and telecoms, not supporting offensive cyber operations. Still, the boundary between defensive and offensive work can blur in practice, and the announcement describes scope but not the verification, audit or monitoring mechanisms that would let outside observers confirm how access is used. Independent confirmation of responsible use would strengthen the case for this model.

Second, who is accountable for failure? If AI-assisted tooling misses a vulnerability that is later exploited, or produces a flawed fix that creates new risk, the responsibility falls on Ukrainian defenders and their institutions. A vendor providing tools does not own that outcome. Readers should expect Ukrainian agencies, not OpenAI, to account for operational results.

Third, what does dependence mean? A wartime government relying on a single US company's frontier models for part of its defensive capacity creates a relationship of reliance that outlasts any announcement. That is not necessarily an argument against the arrangement, but it is a fact of it, and Ukrainian institutions have strong incentives to build their own capability on top of whatever access they receive.

Analysis: a defensible access model that still needs evidence

The case for this kind of access rests on a simple asymmetry: defenders have to cover every vulnerability, attackers need only find one. Any tool that reliably accelerates finding and fixing flaws shifts a little of that burden back toward the defenders. Prior European deployments suggest the models can find real vulnerabilities that vendors then fix, which is exactly the loop civilian defense needs.

My view is that this is a legitimate public-interest use of frontier AI and a reasonable test case for how such access should be structured. The strongest argument for it is the incident record: nearly 6,000 handled incidents in one year, against targets including hospital systems and the energy sector, is the environment the tools are meant for. The strongest reason for caution is evidentiary: the program's effectiveness in Ukraine is a prediction, not an observed result, and the European precedents are vendor-relayed. Honest analysis holds both at once.

What would change the picture in either direction is concrete follow-up: published counts of vulnerabilities found and patched through the program, independent confirmation from Ukrainian agencies, and clarity on the usage controls in place. If OpenAI and the Ministry of Digital Transformation report those numbers, this arrangement can be judged on evidence rather than intent. Until then, the right posture is support for the access and reserve on the claims.