OpenAI launches GPT-5.4-Cyber for approved security teams, expanding the Trusted Access program.

OpenAI launches GPT-5.4-Cyber for approved security teams, expanding the Trusted Access program.

      In summary, OpenAI is launching GPT-5.4-Cyber, a model specialized in defensive cybersecurity with reduced refusal limits and capabilities for binary reverse engineering, while also expanding its Trusted Access for Cyber program to thousands of accredited defenders. This decision follows Anthropic's move to limit its more advanced Mythos model to merely 11 organizations, creating a philosophical divide: OpenAI favors widespread verified access, while Anthropic chooses a more restricted deployment strategy.

      OpenAI will provide its most advanced cybersecurity model to thousands of vetted defenders, introducing GPT-5.4-Cyber and broadening its Trusted Access for Cyber program in direct response to Anthropic’s announcement of Project Glasswing last week.

      GPT-5.4-Cyber is a specialized version of GPT-5.4 tailored for defensive security applications. Its key feature is a lower refusal threshold: while standard models typically block sensitive inquiries related to vulnerability research, exploit assessments, or malware behavior, this variant is designed to respond to such queries if the user is validated as a legitimate security expert. Additionally, the model includes binary reverse engineering capabilities, allowing analysts to investigate compiled software for vulnerabilities without needing access to the source code.

      Scaling up Trusted Access for Cyber

      The model operates within OpenAI’s Trusted Access for Cyber (TAC) initiative, first introduced in February alongside a $10 million cybersecurity grant fund. TAC serves as a framework that regulates access to more advanced models based on verification stages. Users can authenticate at chatgpt.com/cyber, while enterprises can request team-wide access via an OpenAI representative. Security researchers requiring the most extensive capabilities can apply for an exclusive tier.

      The April update transitions the program from a limited pilot to what OpenAI characterizes as “thousands of verified individual defenders and hundreds of teams responsible for defending critical software.” The company is introducing new tiers, allowing higher verification levels to unlock more powerful features. Users approved for the highest tier will gain access to GPT-5.4-Cyber, but there is a caveat: top-tier users may need to forgo Zero-Data Retention, meaning OpenAI will maintain oversight of how the model is utilized.

      This approach marks a philosophical shift: instead of relying predominantly on model-level restrictions to curb misuse, OpenAI is adopting an access-control model that verifies the identity of the user before determining the model's responses. The company aligns this shift with three principles: democratized access through objective verification criteria, iterative deployment that updates safety mechanisms as risks develop, and ecosystem resilience supported by grants and open-source efforts.

      Understanding the Anthropic context

      OpenAI's timing is significant when viewed in relation to Anthropic's Project Glasswing, announced on April 7. Anthropic disclosed that its Claude Mythos Preview model autonomously identified thousands of zero-day vulnerabilities across major operating systems and web browsers, including a 27-year-old bug in OpenBSD and a 17-year-old remote code execution flaw in FreeBSD, which Mythos uncovered, exploited, and documented without human input.

      In response, Anthropic has severely restricted access to Mythos Preview, making it available exclusively to 11 organizations, such as Apple, Google, Microsoft, AWS, Cisco, CrowdStrike, and JPMorgan Chase, through a $100 million defensive initiative. The model will not be made publicly available, and Anthropic has indicated it may remain that way due to the risk of misuse stemming from its exploit-generation abilities.

      In contrast, OpenAI is opting for broader access. While GPT-5.4-Cyber is less proficient than Mythos in sheer vulnerability discovery, it is being made accessible to a much wider audience. The underlying rationale is that limiting powerful security tools to a few technology giants leaves the majority of organizations—including those tasked with protecting critical infrastructure, hospitals, municipal governments, and small security firms—without access to equally effective defensive technology.

      Capabilities of GPT-5.4-Cyber

      In addition to its reduced refusal boundaries, the model is designed for workflows that standard ChatGPT handles inadequately or outright denies. The standout feature is binary reverse engineering: security analysts can input compiled executables into the model to receive analyses regarding potential malware behavior, embedded vulnerabilities, and structural flaws. Such analyses typically necessitate specialized tools like IDA Pro or Ghidra, along with substantial manual expertise.

      The model can also engage with dual-use inquiries, such as questions about attack techniques, exploit chains, and classes of vulnerabilities—topics that standard models often flag as risky. OpenAI states that earlier versions sometimes declined to address legitimate defensive inquiries, creating barriers for security professionals needing the model to analyze adversarial techniques for their defense strategies.

      Codex Security, OpenAI’s automated code-scanning tool, enhances the model's capabilities. Since its launch, Codex Security has facilitated over 3,000 critical and high-severity vulnerability fixes across the open-source landscape, covering more than 1,000 open-source projects through a free scanning initiative.

      The dual-use dilemma

Other articles

Nissan has unveiled the Juke EV, and I sincerely hope this daring design remains. Nissan has unveiled the Juke EV, and I sincerely hope this daring design remains. Nissan has unveiled the third-generation Juke as an all-electric crossover for Europe, and its striking new design is undoubtedly the most captivating aspect of the vehicle. OpenAI has launched GPT-5.4-Cyber for approved security teams, expanding its Trusted Access program. OpenAI has launched GPT-5.4-Cyber for approved security teams, expanding its Trusted Access program. OpenAI has introduced GPT-5.4-Cyber, featuring binary reverse engineering for validated defenders, expanding access to thousands as it competes with Anthropic's limited Mythos model. More than a hundred Chrome extensions have been found causing significant issues. See if you're using any of them. More than a hundred Chrome extensions have been found causing significant issues. See if you're using any of them. A recent report associates 108 Chrome extensions with identity theft, session hijacking, and misuse of browsers, suggesting that if you haven't reviewed your Chrome extensions recently, it's time to examine your seemingly harmless add-ons more closely. Rumors about Nvidia suggest a new memory strategy for the anticipated RTX 5060 Ti graphics card. Rumors about Nvidia suggest a new memory strategy for the anticipated RTX 5060 Ti graphics card. A new rumor indicates that Nvidia might incorporate 3GB GDDR7 modules in the speculated RTX 5060 Ti, increasing the VRAM to 9GB, but this could lead to a reduction in memory bandwidth. A US judge has determined that the fraud defendant's conversations with Claude, an AI, do not have privilege. A US judge has determined that the fraud defendant's conversations with Claude, an AI, do not have privilege. A US court determined that conversations with AI chatbots are not protected by legal privilege. The case centered around Claude. Clients should consider public AI chats as potentially discoverable in legal proceedings. Spotify introduces physical book sales in the US and UK through a collaboration with Bookshop.org. Spotify introduces physical book sales in the US and UK through a collaboration with Bookshop.org. Spotify has introduced the option for users to purchase physical books via Bookshop.org links within the app, in addition to offering Page Match in over 30 languages, as well as new Audiobook Charts and Recaps.

OpenAI launches GPT-5.4-Cyber for approved security teams, expanding the Trusted Access program.

OpenAI introduces GPT-5.4-Cyber, featuring binary reverse engineering for validated defenders, expanding access to thousands while competing with Anthropic's limited Mythos model.