AI & Models
OpenAI restricts access to new cybersecurity model
OpenAI will begin rolling out its GPT-5.5-Cyber tool to verified defenders in the next few days, despite previously criticizing competitor Anthropic for similar access restrictions.
On Thursday, OpenAI CEO Sam Altman announced on the social media platform X that the company will begin rolling out its GPT-5.5-Cyber model to critical cyber defenders in the next few days. To obtain access to the tool, applicants must submit information through OpenAI’s website detailing their professional credentials and planned use cases. The tool is designed as a defensive toolkit to help companies find security holes and test their digital defenses.
This controlled release strategy closely mirrors the approach of competitor Anthropic, which previously restricted access to its own cybersecurity tool, Mythos. When Anthropic limited Mythos to select users, Altman publicly criticized the decision, characterizing the tactic as “fear-based marketing.” Some critics also agreed, arguing that Anthropic’s safety rhetoric was overblown. However, the limits proved imperfect, as an unauthorized group reportedly managed to gain access to Mythos despite the restrictions.
OpenAI is managing its own distribution through a verification program called Trusted Access for Cyber (TAC). According to an OpenAI spokesperson, the TAC program has already scaled to thousands of verified defenders and hundreds of teams responsible for protecting critical software. This tiered permissions program allows defenders to bypass standard safeguards to perform necessary security work. The spokesperson explained that “Critical defenders with legitimate defensive use cases can apply to access dedicated more cyber-permissive models like GPT-5.4-Cyber, and the forthcoming GPT-5.5-Cyber, through the program.”
The GPT-5.5-Cyber model is capable of executing highly sensitive operations. The application process implies that the model can perform tasks such as penetration testing—which refers to simulated cyberattacks to identify and exploit vulnerabilities—as well as malware reverse engineering, the process of analyzing malicious software to understand its functionality and origin. Because of concerns that the toolkit could be misused by “bad guys,” OpenAI is keeping the model gated. The company is currently consulting with the U.S. government to explore how to make the Cyber tools more widely available while ensuring they only reach users with verified defensive credentials.
Why it matters
This development highlights the ongoing tension between AI safety and accessibility, as OpenAI adopts the same gatekeeping practices it once publicly disparaged in competitors.