OpenAI launches GPT-5.4-Cyber for defensive security work

by

OpenAI on Tuesday launched GPT-5.4-Cyber, a cybersecurity-focused version of its GPT-5.4 model, and expanded access through its Trusted Access for Cyber program to thousands of individual defenders and hundreds of security teams.

KEY FACTS

  • New model GPT-5.4-Cyber is tuned for defensive cybersecurity use cases.
  • Access expansion Trusted Access for Cyber is being widened to authenticated defenders and teams securing critical software.
  • Security goal OpenAI says the rollout is meant to broaden legitimate use while strengthening safeguards against jailbreaks and adversarial prompt injections.
  • Prior work Codex Security has helped identify, validate and propose fixes for more than 3,000 critical and high vulnerabilities.

In a company disclosure, the model maker said the program is designed to scale cyber defense while limiting misuse. The disclosure said AI tools can be repurposed by malicious actors, including to search for vulnerabilities before patches are available.

The company said the release is part of a deliberate rollout meant to give defenders a head start and to test safeguards as model capabilities advance. It said the approach includes controls aimed at reducing jailbreak attempts and adversarial prompt injection.

OpenAI also pointed to its Codex Security application security agent, which it said has already contributed to fixing more than 3,000 critical and high-severity vulnerabilities. The company described the broader aim as moving security from periodic audits to continuous feedback during development.

The announcement came days after Anthropic introduced its Mythos model in a controlled deployment for Project Glasswing. Anthropic said that model found thousands of vulnerabilities in operating systems, web browsers and other software.

WHY IT MATTERS

The release shows how major AI companies are trying to make advanced models available for defensive security work while limiting abuse. The push could help developers find flaws sooner, but it also underscores concerns that the same tools may be turned against widely used software.