OpenAI Cybersecurity Grant Program
OpenAI has established the Cybersecurity Grant Program to accelerate the development of AI-powered defensive capabilities and shift the power dynamics of cybersecurity in favor of defenders. This initiative provides funding and technical support to ensure that cutting-edge AI benefits security professionals first and most.
Program Objectives and Goals
The Cybersecurity Grant Program is designed to move beyond the traditional axiom that attackers have a natural advantage because they only need to be right once. OpenAI aims to leverage the coordination of defenders to create a safer collective environment through three primary goals:
- Empowering Defenders: Ensuring that the most advanced AI capabilities are prioritized for defensive use.
- Measuring Capabilities: Developing standardized methods to quantify the effectiveness of AI models in cybersecurity tasks.
- Elevating Discourse: Fostering rigorous, nuanced discussions regarding the challenges and opportunities at the intersection of AI and security.
Funding and Application Criteria
OpenAI initially launched the program as a $1M initiative, granting funds in increments of $10,000 USD. Support is provided via API credits, direct funding, or equivalents.
Key application requirements include:
- Focus on Defense: Only practical applications of AI in defensive cybersecurity (tools, methods, and processes) are considered. Offensive-security projects are explicitly excluded from funding.
- Public Benefit: Priority is given to projects with a clear plan to be licensed or distributed for maximal public benefit and sharing.
- Rolling Evaluation: Applications are evaluated and accepted on a rolling basis.
Targeted Technical Use Cases
OpenAI has identified several high-priority areas where AI can enhance defensive security, including:
- Vulnerability Management: Automatically patching vulnerabilities, optimizing patch management processes for better prioritization and deployment, and helping developers port code to memory-safe languages.
- Threat Detection and Response: Automating incident triage, detecting social engineering tactics, and assisting reverse engineers in creating malware signatures and behavior-based detections.
- Secure Development: Identifying security issues in source code, assisting developers in creating "secure by design and secure by default" software, and aiding in the creation of robust threat models.
- Infrastructure and Intelligence: Developing confidential compute on GPUs, creating honeypots and deception technology, and producing tailored threat intelligence for specific organizations.
- Forensics and Compliance: Assisting with network or device forensics and analyzing security controls against compliance regimes.
Program Evolution and GPT-5.3-Codex
As of February 5, 2026, the program evolved to focus on the large-scale deployment of models to accelerate cyber defense. In conjunction with the release of GPT-5.3-Codex, OpenAI introduced Trusted Access for Cyber and committed an additional $10M in API credits to support these efforts.