




















AI Models impacting Cybersecurity
getty
OpenAI’s launch of GPT-5.4-Cyber this week, released just a week after Anthrophic revealed its most powerful Mythos model, shows that AI companies now see cybersecurity as one of the most important places where frontier AI can have a real impact. Described by Open AI as a flagship model tuned for defensive cybersecurity tasks, GPT-5.4-Cyber is being offered first to vetted security researchers, vendors and organizations, similar to Mythos’ gated release.
The company says the model enables legitimate security work and adds the ability to reverse engineer binary code, not just text-based code, “that enable security professionals to analyze compiled software for malware potential, vulnerabilities and security robustness without needing access to its source code,” according to the company’s announcement.
This deeper analysis ability, baked into Open AI’s latest most powerful GPT model, is important because security teams need to inspect malware, reason through exploit chains and examine compiled code without treating every technical prompt as suspect.
Like Anthropic, OpenAI is trying to make that possible without opening the gates to everyone. As part of the model’s release, the company says it is expanding Trusted Access for Cyber (TAC) program to thousands of verified individual defenders and hundreds of teams protecting important software. Using a layered access system built around identity checks, verification and different permission levels, OpenAI hopes to get ahead of potential security problems by giving security experts a head start.
Unlike Anthropic, OpenAI takes a more open approach to who can access its latest model. According to the blog post, “Because this model is more permissive, we are starting with a limited, iterative deployment to vetted security vendors organizations, and researchers. Access to permissive and cyber-capable models may come with limitations, especially around no-visibility uses like Zero-Data Retention (ZDR).”
Qualified researchers and developers who meet specific criteria can join TAC, and existing TAC members looking to gain access to the latest GPT‑5.4‑Cyber model can “further authenticate themselves as legitimate cyber defenders can express interest in additional tiers of access, including requesting access to GPT‑5.4‑Cyber.” The company says it is expanding TAC in preparation for more capable models expected in the coming months. That implies that GPT-5.4-Cyber is just one of many increasingly powerful and capable models to be released.
In a follow-up post published April 16, the company said leading firms and enterprises including BNY, CrowdStrike, Cisco, Citi, NVIDIA oracle, Zscaler, iVerify and SpecterOps are joining Trusted Access for Cyber, alongside $10 million in API grants for the broader defense ecosystem.
OpenAI’s more open access stance, while still gated, is one of the differences between OpenAI’s approach and Anthropic’s Project Glasswing approach, which is more restricted in terms of its access to Claude Mythos Preview. On its Project Glasswing pages, Anthropic describes Claude Mythos Preview as a general-purpose frontier model with unusually strong cybersecurity capability, strong enough that the company chose not to release it broadly. Anthropic says Mythos has already identified thousands of zero-day vulnerabilities across critical infrastructure and that more than 40 organizations that build or maintain important software infrastructure are getting access to help scan and secure systems. Access to that model is heavily restricted and limited to a narrow set of vetted members who have access as part of defense-focused cybersecurity needs.
Anthropic takes the stance that a powerful model’s capability is strong enough to demand a very tight circle. OpenAI, on the other hand, aims to widen the pool of defenders who can use advanced tools while still keeping tighter controls on the most permissive systems. OpenAI takes a middle path between full public release that was previously typical of its latest models, and Anthropic’s approach of having a very small, closed partner list. The two companies are moving toward the same destination, even if their approaches differ. Both are abandoning the old idea that the strongest models should be distributed to everyone upon release.
That shift in who gets access to the most powerful models could end up being one of the more important business stories in AI this year. The frontier labs are no longer only competing on benchmark scores, coding fluency or chatbot ability. They are competing on who can provide controlled access to powerful models that give some advantages that need qualification and vetting to access.
The market is drifting toward tiered access to AI, where the strongest capabilities are not offered on equal terms to all buyers. Basic models may remain broad. Cyber-permissive models and future systems with stronger offensive or dual-use potential are likely to sit behind higher-friction access programs. That starts to make frontier AI look less like standard software licensing and more like controlled infrastructure.
This has the potential to reshape the dynamics of the hypercompetitive AI market. Model quality will still matter, but so will governance and controls around the model. The winners may be the companies that can verify users, monitor usage, satisfy regulators and show customers that powerful tools are reaching defenders before misuse scales. In that world, trust and control becomes a source of product advantage, a new moat in an environment where competitive moats continue to shrink. The previous approach of broad, access-for-all AI models might turn into new walled gardens where the most capable models are only available to a narrower audience who can also pay the most premium prices.
Cybersecurity is turning into one of the most important enterprise use cases for frontier AI, but also one of the biggest potential danger zones for AI’s broad adoption. A model that can help reverse engineer a binary, find a flaw faster, trace how it might be exploited and suggest a fix can save time where time matters, but also put that power in the hands of those looking to do harm or cause mischief.
The reaction from the finance industry tells you this story reaches far beyond Silicon Valley. Financial institutions run large, old, interconnected systems. Many still depend on legacy software that is hard to replace and expensive to secure. A model that can identify weak points faster than past tools changes the risk equation. It can help defenders, but it can just as easily expose how much technical debt still sits under the world’s payment systems and banking infrastructure. The risk of a vibe-coding hacker being able to take down a bank or steal funds is a scary proposition.
Reuters reported that the European Central Bank planned to ask banks about the risks tied to Anthropic’s Mythos. Reuters also reported on April 16 that German banks are examining those risks with authorities, cybersecurity experts and banking supervisors. On the same day, Reuters reported that the Bank of England is running analyses and simulations to test AI-related threats to the financial system. That is a very different reaction to an AI model release than the usual flashy demo.
The same pattern is likely to play out in healthcare, telecom, energy and cloud infrastructure. These sectors are full of brittle code, old dependencies and understaffed security teams. That makes them natural candidates for AI-assisted defense. It also makes them vulnerable if advanced cyber capability spreads faster than defensive readiness.
OpenAI’s GPT-5.4-Cyber and Anthropic’s Mythos point in the same direction. Frontier AI is moving into work that can have a significant impact on national resilience, financial stability and critical infrastructure. Once that happens, newer, ever-more powerful and capable models become more than just feature releases, but also introduce policy and risk questions.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。