IBM has partnered with OpenAI to bring frontier AI capabilities into enterprise security workflows. The collaboration targets rapidly evolving cyber threats and aims to help businesses identify risks faster.
IBM has joined the OpenAI Daybreak Cyber Partner Program. Through the initiative, the companies will integrate protective AI capabilities into business operations. As a result, enterprises can use advanced models to examine security risks within controlled environments.
New security service targets vulnerabilities
As part of the partnership, IBM has launched a new application security service. The service uses OpenAI’s cyber capabilities to identify and validate software vulnerabilities. Moreover, AI-driven analysis can assess application code and prioritize areas with potential flaws or exploitable paths.
The service runs through IBM Consulting Advantage, IBM’s AI platform for consulting delivery. Meanwhile, its security harness connects client environments with OpenAI models through controlled access. The system uses read-only access to code repositories and bounded execution. Therefore, organizations can conduct large-scale exposure analysis while maintaining governance controls.
Clients can begin with targeted evaluations of important applications. Then, they can expand toward continuous monitoring as their code and threat environment change. This approach allows security teams to reassess vulnerabilities over time.
Project Lightwell strengthens the strategy
The partnership also builds on Project Lightwell, which focuses on securing open-source software. IBM and Red Hat have committed $5 billion to the initiative. Furthermore, Project Lightwell will combine engineers with AI tools for code review, validation and remediation.
“Attackers are already using AI to probe, exploit, and scale threats at machine speed. Defenders need the same advantage, with the security and control enterprises require,” said Mark Hughes, Global Managing Partner, Cybersecurity Services, IBM Consulting.
Meanwhile, OpenAI CISO Dane Stuckey said the partnership will use frontier models to accelerate defensive security workflows. The companies also plan further integrations through the Daybreak Cyber Partner Program.








