Check Point Software Technologies has announced it is integrating OpenAI’s Daybreak frontier AI models across its security platform, extending a partnership aimed at helping defenders detect, validate, and remediate cyber risk faster.
The move builds on Check Point’s existing collaboration with OpenAI through the Daybreak Defense Network, first expanded three months ago, and follows the company’s recent decision to join more than 100 technology and security firms in backing OpenAI’s call for a collective, global surge in cyber defense.
In a blog post announcing the expansion, Check Point Chief Technology Officer Jonathan Zanger said the work does not stop with previous milestones, arguing that security needs to keep adapting as new threats and attacker capabilities emerge, alongside evolving technology stacks and growing enterprise use of AI.
Zanger said the aim is to put OpenAI’s frontier cyber reasoning to work across the security lifecycle, combining it with Check Point’s own security intelligence, context, and enforcement capabilities so customers can move from large volumes of raw security data to validated risk, actionable decisions, and faster protection.
Four Areas of Integration
According to Check Point, the Daybreak models are being rolled into four parts of its platform:
- Agentic Exposure Validation: Within Check Point’s Exposure Management product, the models are being piloted inside a multi-agent pipeline that separates genuinely exploitable risk from theoretical findings, combining AI reasoning with Check Point’s security context to validate attack paths and prioritise remediation.
- Agentic Security Management: As part of Check Point’s autonomous, intent-driven approach to network security management, the models will help investigate potential attack paths, understand vulnerabilities and risky exposures, and identify appropriate fixes, reducing manual policy management.
- Autonomous Workspace Platform: Within Harmony, Check Point’s investigation pipeline correlates email, endpoint, mobile, and browser telemetry; the models are being applied to investigate malware behaviour, attacker techniques, and credential-abuse chains, aiming to deliver clearer verdicts and remediation guidance while easing the load on security teams.
- Vulnerability research: The models are being used to accelerate analysis of vulnerable code and patches, identify realistic exploitation paths and reach verified results faster, without relying on publicly available exploit code, which Check Point says should translate into faster protection against newly disclosed vulnerabilities.
Check Point said it is taking a phased approach to the rollout: some capabilities are already in production, others are in development and being tested with design partners, with more to follow as the underlying technology matures. The company said every deployment follows the same discipline: governing what the model can see, constraining what it can act on, and testing and verifying its output before allowing it to take on more work within approved security workflows.
A Two-Way Relationship
Zanger framed the OpenAI partnership as operating in two directions: Check Point uses frontier AI to strengthen how it defends customers, while also helping those customers adopt and use OpenAI’s technologies securely. He said both sides of that relationship are becoming more important as AI moves beyond answering questions towards writing code and operating autonomous enterprise agents.
“Our goal is to give organizations the confidence to embrace what AI makes possible while staying protected against evolving risks,” Zanger said, adding that the partnership is intended to put frontier AI to work for defenders while helping customers deploy it safely themselves.
The announcement is the latest sign of security vendors racing to embed frontier AI reasoning models directly into detection, validation and remediation workflows, as both defenders and attackers increasingly turn to AI to gain an edge.

