SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Check Point expands OpenAI Daybreak use in security

Check Point expands OpenAI Daybreak use in security

Sat, 5th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Check Point has expanded its work with OpenAI by adding Daybreak models to parts of its security platform to help defenders find, validate and remediate risk.

The move brings OpenAI's cyber models into several Check Point products and workflows, including exposure management, network security management, workspace security and vulnerability research. Some functions are already running in production, while others remain in testing with design partners.

Check Point is using the models in what it calls a multi-agent exposure validation pipeline. The goal is to separate exploitable risks from theoretical findings by validating attack paths and helping teams decide which issues to address first.

Another deployment area is Keystone, Check Point's security management offering. There, the models investigate possible attack paths, assess vulnerabilities and exposures, and suggest remediation steps as part of a broader AI-led approach to policy and configuration management.

Within the company's Autonomous Workspace Platform, the technology is being applied to incident investigation. It correlates email, endpoint, mobile and browser telemetry into a smaller set of incidents, while the OpenAI models analyse malware behaviour, attacker techniques and credential-abuse chains.

Check Point is also applying the models to NexPloit, its vulnerability research system. The tool turns vulnerability information into verified attack material that can be used for automated protection development without relying on publicly available exploit code.

Security lifecycle

Jonathan Zanger, Chief Technology Officer at Check Point, said the company sees the partnership as part of a wider shift in cyber defence as attackers adopt more advanced tools.

"As attackers move faster and operate with greater scale and sophistication, defenders need to take advantage of the same advances in AI. That's the core of our collaboration with OpenAI: putting frontier AI to work to help defenders stay ahead," Zanger said.

He said the use of OpenAI models is spreading across the security lifecycle rather than being confined to a single product area. That includes risk discovery, exploitability validation, threat investigation and support for remediation.

"By incorporating OpenAI Daybreak models into the Check Point security platform, we can build, test and continuously strengthen security - while bringing those capabilities directly into the security workflows customers already rely on," Zanger said.

Check Point is taking a phased approach. Some functions are available now, while others are still under development and evaluation before wider release.

According to the company, model use is constrained by controls over what systems the AI can access, what actions it can take and how outputs are tested before entering approved workflows. That reflects broader caution across the security industry about using generative AI in operational settings, where inaccurate results or overreach could create fresh risks.

Dual role

Check Point said its work with OpenAI has two strands: using frontier AI to improve its own security products and helping customers adopt OpenAI technologies securely in their own environments.

It said this has become more important as AI tools move beyond question answering into code generation, autonomous agents and operational decision-making. That trend has increased pressure on security vendors to address both the use of AI in defence and the protection of AI deployments themselves.

Zanger said the company's objective is to turn advances in AI into results customers can rely on without weakening controls.

"What ties them together is the same discipline in every case: govern what the model can see, constrain what it can act on, test and verify what it produces, and only then allow it to take on more of the work within approved security workflows," Zanger said.

He also linked the OpenAI work to a broader industry challenge as organisations deploy AI more widely across business systems while threat actors improve their own methods.

"As AI moves from answering questions to writing code, operating enterprise agents and taking actions, both sides of that relationship become increasingly important. Security must keep pace," Zanger said.