
Last month, OpenAI introduced GPT-5.4-Cyber, a variant of the GPT-5.4 model fine-tuned for defensive cybersecurity use cases. While OpenAI's primary competitor, Anthropic, restricted its latest and greatest Mythos model to a select few companies, OpenAI took the opposite approach by broadening access to its security-focused model for thousands of developers.
Today, OpenAI announced GPT-5.5-Cyber, a new model built on top of the recently released GPT-5.5, designed for specialized cybersecurity work. The model is now available in a limited preview for defenders responsible for securing critical infrastructure. It is important to note that GPT-5.5 already supports cybersecurity teams through Trusted Access for Cyber (TAC), which gives verified developers more useful access to cyber capabilities while maintaining safeguards against misuse.
we're starting rollout of GPT-5.5-Cyber, a frontier cybersecurity model, to critical cyber defenders in the next few days.
— Sam Altman (@sama) April 30, 2026
we will work with the entire ecosystem and the government to figure out trusted access for cyber; we want to rapidly help secure companies/infrastructure.
OpenAI says GPT-5.5 and GPT-5.5-Cyber are meant for different parts of the cyber defense ecosystem. For most organizations and developers, OpenAI recommends GPT-5.5 with TAC for defensive security work. It can be used for secure code review, vulnerability triage, malware analysis, binary reverse engineering, detection engineering, and patch validation.
The new GPT-5.5-Cyber is targeted at more specialized and higher-risk workflows where even trusted developers may still encounter refusals from the GPT-5.5 model. This model will be helpful for authorized red teaming, penetration testing, and controlled exploitability validation by offering more permissive behavior.
Starting June 1, 2026, individual developers using OpenAI’s most capable and permissive cyber models through Trusted Access for Cyber must enable Advanced Account Security. Organizations can attest that they use phishing-resistant authentication through their single sign-on workflow.
OpenAI says it is also working with security vendors across discovery, development, detection, response, and network enforcement. It will help researchers disclose vulnerabilities with proof-of-concepts and patch guidance, prevent vulnerable code from reaching production, detect exploitation in the wild, and deploy mitigations while fixes are being rolled out.
0 Comments
Load the comments and join the conversation!
Read the comments, ask the editors questions, show respect and join the conversation.