AI Safety

OpenAI Gates GPT-5.5-Cyber After Mocking Mythos Limits

OpenAI is gating GPT-5.5-Cyber behind its Trusted Access program for vetted defenders, nine days after Altman called Anthropic's Mythos limits 'fear-based marketing'.

OpenAI Gates GPT-5.5-Cyber After Mocking Mythos Limits — article cover
On this page6 SECTIONS
  1. What GPT-5.5-Cyber Does
  2. How Trusted Access for Cyber Works
  3. The “Fear-Based Marketing” Rebuke, Nine Days Earlier
  4. Why Both Labs Landed in the Same Place
  5. What It Means for Security Teams
  6. Sources

On Thursday, April 30, 2026, Sam Altman announced on X that GPT-5.5-Cyber would roll out over the next few days — but only “to critical cyber defenders.” The model can perform penetration testing, vulnerability identification and exploitation, and malware reverse engineering. Those same capabilities are exactly why it cannot ship openly.

The drama sits in the timeline. On April 21, Altman publicly slammed Anthropic for “gatekeeping” its cybersecurity model Mythos, calling the approach “fear-based marketing.” Nine days later, OpenAI made a nearly identical decision for its own Cyber line. On the question of whether cyber-capable models should be gated, the frontier labs just reached consensus — by action, not argument.

What GPT-5.5-Cyber Does

Per OpenAI’s description, the Cyber line is a toolbox built for defense: helping companies find security holes and test their own defenses. GPT-5.4-Cyber already exists; GPT-5.5-Cyber is the next iteration. Its capability list — penetration testing, vulnerability exploitation, malware reverse engineering — is double-edged by construction: defenders use it to harden systems, attackers to find the way in. The reason for restricted access is not rhetoric; it is the nature of the capability itself.

How Trusted Access for Cyber Works

Access runs through the Trusted Access for Cyber (TAC) program. Applicants fill out a form on OpenAI’s site, submitting credentials and intended use; the application asks not just who you are but what you plan to do with the model. Those who pass review get the latest model with reduced “friction” from safeguards — meaning verified defenders receive a less restricted, more usable version. Teams with legitimate defensive use cases can also apply for “dedicated more cyber-permissive models” through the same channel.

An OpenAI spokesperson told TechCrunch that TAC has scaled “to thousands of verified defenders and hundreds of teams responsible for protecting critical software,” and that the company is working with the U.S. government to broaden access over time.

The “Fear-Based Marketing” Rebuke, Nine Days Earlier

The timeline is the ironic core of this story. Starting April 9, commentators argued Anthropic’s safety rhetoric around Mythos was overblown; on April 21, Altman branded it “fear-based marketing.” Yet in the same window, an unauthorized group reportedly gained access to Mythos anyway — evidence that once a gap exists, a fence will not stop a determined seeker.

OpenAI’s pivot nine days later amounts to conceding the rival’s premise: for a cyber model whose offensive capability crosses a certain threshold, the risks of open release outweigh the benefits. The difference is execution — Anthropic chose suspension and selection; OpenAI chose tiered verification, with reduced safeguard friction as the reward for passing review.

Why Both Labs Landed in the Same Place

The dual-use nature of cyber models means “can find vulnerabilities for customers” and “can find vulnerabilities for attackers” share the same weights. For a lab, fully open release hands an attack toolkit to everyone; refusing to release cedes the defense market. Tiered access is the only compromise that serves both ends: replace the paywall with an identity wall, and bring KYC into the model release process.

Notably, on the same day OpenAI also announced advanced account security for ChatGPT, including a Yubico hardware-key partnership. Read together, “security” is being extended from model capability to the account and access layer — packaged as one product message.

What It Means for Security Teams

Three observations. First, if your team runs penetration tests or red-team exercises, applying to TAC is now worthwhile — the verified tier has fewer guardrails and higher practical value; prepare credentials and concrete use cases for the application, since vagueness about intended use is the likeliest reason for rejection. Second, “thousands of defenders” is a tiny fraction of the global security workforce, and the pace of the government-backed expansion will determine when this class of model goes from privilege to standard equipment — watch whether the eligibility pool widens beyond critical-infrastructure and enterprise security teams. Third, Altman’s reversal is a reminder that public criticism of safety restrictions tends to get repriced the moment one’s own model hits the same capability threshold. When evaluating any gated model, judge the mechanism — who reviews, what gets logged, how access is revoked — not the launch-week rhetoric.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

FOUND_THIS_USEFUL?

Support more practical AI articles, tutorials, and build notes.

BUY_ME_A_COFFEE
SHAREXEMAIL