



















ILLUSTRATION - 22 October 2025, Mecklenburg-Western Pomerania, Schwerin: Several AI applications can be seen on a smartphone screen, including ChatGPT and Claude. Photo: Philip Dulian/dpa (Photo by Philip Dulian/picture alliance via Getty Images)
dpa/picture alliance via Getty Images
OpenAI this week announced GPT 5.4-Cyber, a fine-tuned version of GPT-5.4 optimized for cyber capabilities. The world’s largest AI startup also said it would be scaling up its Trusted Access for Cyber program to thousands of verified defenders and teams responsible for defending critical software.
The TAC will be expanded to introduce access to GPT-5.4-Cyber for users willing to authenticate themselves as cybersecurity defenders, according to OpenAI’s announcement blog post. The company plans to use identity verification and KYC controls to govern who can access the new model.
“This is a version of GPT-5.4 which lowers the refusal boundary for legitimate cybersecurity work and enables new capabilities for advanced defensive workflows, including binary reverse engineering capabilities that enable security professionals to analyze compiled software for malware potential, vulnerabilities and security robustness without needing access to its source code,” the announcement blog post said.
The announcement comes just a week after Anthropic unveiled Claude Mythos Preview and Project Glasswing, an initiative that provided select organizations with access to the startup’s powerful new model to identify potential vulnerabilities in critical infrastructure.
Unlike Mythos Preview, GPT-5.4-Cyber launched with very little information about its capabilities. While Anthropic detailed Mythos’s ability to conduct autonomous attacks and discover thousands of vulnerabilities, OpenAI hasn’t said much about what its new model can do beyond it being more cyber-permissive than GPT-5.4.
There are significant questions as to whether this model offers new defensive capabilities for organizations or if it’s a PR pitch in response to Mythos.
“My initial impression with OpenAI’s announcement is that it is a bit reactive to the Mythos media event last week,” Thomas Randall, a senior business analyst for Info-Tech Research Group, told me in a video call. For Randall, it’s still early, but there appears to be more defensive promise on the Anthropic side, whereas the 5.4-Cyber and TAC announcement seem to be focused on defining how more powerful models will be accessed.
While OpenAI didn’t immediately comment on the release, a representative for the company shared with me a follow-up post via email, noting that it has provided access to GPT-5.4-Cyber to the U.S. Center for AI Standards and Innovation and the U.K. AI Security Institute, so they can conduct evaluations on the model’s cyber capabilities and safeguards.
The company also shared some of the companies that have signed up to its trusted access program, including Bank of America, BlackRock, BNY, Citi, Cisco, CrowdStrike, Goldman Sachs, iVerify, JPMorgan Chase, Morgan Stanley, Nvidia, Oracle, SpecterOps and Zscaler.
“I think the takeaway might be that cybersecurity might become a new differentiator between these frontier models," Randall said before the release of the second blog post, “But at the moment, there’s more evidence that Anthropic’s is a bit more grounded.”
Randall also notes that OpenAI’s decision to open up its TAC program to a wider range of individuals and organizations than Project Glasswing also comes across as an indicator of this being a PR-driven model release.
For now, neither GPT-5.4-Cyber nor Claude Mythos are available for general release, but it is likely that similar models will emerge in the near future. After all, not only are Anthropic and OpenAI facing tremendous pressure to deliver new releases to justify their valuations, but there is also the prospect of other vendors developing equivalent capabilities.
Both of these limited releases indicate frontier AI models will play a bigger role in offensive and defensive operations going forward. For instance, whereas Anthropic stressed the potential offensive capabilities of Mythos in discovering vulnerabilities, OpenAI has opted to present GPT-5.4-Cyber as a defensive tool for organizations.
“GPT-5.4-Cyber reflects how quickly AI-driven vulnerability discovery is maturing. What’s notable is not just that these models can find issues, but they’re doing it more consistently and with less human effort,” Melissa Bischoping, senior director of security and product design research at security automation provider Tanium, told me via email.
“The biggest implication is speed and scale. The cat-and-mouse game we’ve played in security for years is just operating on an amplified scale now,” Bischoping said. “As models get better at identifying vulnerabilities, the window between discovery and exploitation continues to shrink. That puts pressure on organizations to move toward continuous validation and real-time response. Open-weight models hitting the ecosystem will increase that pressure,” Bischoping said.
Beyond introducing new threats, these models have the potential to shift defensive operations as they continue to improve. "This model is just a lot better at security-related tasks. And I say a lot — it’s not really a lot. It looks like, you know, 10 to 15% better. At least, that’s what I’ve seen for Mythos,” Jeff Williams, founder and CTO of Contrast Security, told me in a video interview about GPT-5.4-Cyber.
While Williams didn’t think there would be a substantive difference between the two models, he noted that in the short term, he expects to see a glut of vulnerabilities. That being said, he’s optimistic about the ability of these tools to redefine cybersecurity in the long term.
“These models should be the key to doing security of tomorrow. But that’s not how they’re pitching them right now. And I think that’s kind of the danger, is that people are looking at these as like, ‘Ooh, we’re going to use them to find vulnerabilities and exploit them,’ and just, that’s security of yesterday," Williams said. "I’m optimistic that we can use these models to do something to actually change the industry to make things more secure.”
For Williams, the security of tomorrow is secure by design. He suggests defenders will progress from vulnerability scanning to using AI to remediate vulnerabilities and then, finally, implementing the security architecture and design to prevent these vulnerabilities from entering the code in the first place.
In any case, the fact that both Anthropic and OpenAI are enlisting support from external researchers is a recognition that it’s going to take an industry-wide effort to leverage this technology to its full potential. It’s not just a matter of developing the tools, but also helping defenders to learn how to use them effectively.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。