OpenAI scales Trusted Access for Cyber and releases GPT‑5.4‑Cyber for defensive cybersecurity
OpenAI scales Trusted Access for Cyber and releases GPT‑5.4‑Cyber for defensive cybersecurity
Overview
OpenAI is scaling its Trusted Access for Cyber (TAC) program to thousands of individual defenders and hundreds of teams, and is introducing GPT‑5.4‑Cyber, a variant of GPT‑5.4 fine‑tuned for cyber‑permissive defensive tasks.
Trusted Access for Cyber Program Expansion
The TAC program now offers additional tiers of access for users who authenticate as cybersecurity defenders, with the highest tiers providing access to GPT‑5.4‑Cyber. Individuals can verify identity at chatgpt.com/cyber and enterprises can request trusted access through their OpenAI representative. All approved customers receive versions of existing models with reduced friction around safeguards that might trigger on dual‑use cyber activity, supporting security education, defensive programming, and responsible vulnerability research.
GPT‑5.4‑Cyber Model Details
GPT‑5.4‑Cyber is a version of GPT‑5.4 that lowers the refusal boundary for legitimate cybersecurity work and enables new capabilities for advanced defensive workflows, including binary reverse engineering to analyze compiled software for malware potential, vulnerabilities, and security robustness without source code. Because the model is more permissive, OpenAI is starting with a limited, iterative deployment to vetted security vendors, organizations, and researchers, noting that access may come with limitations around no‑visibility uses such as Zero‑Data Retention when accessed through third‑party platforms.
Principles Guiding the Approach
OpenAI’s strategy rests on three principles: democratized access through clear, objective verification criteria; iterative deployment by putting systems into the world carefully and improving them over time; and investing in ecosystem resilience via trusted access pathways, grants, open‑source security contributions, and technologies like Codex Security. These principles aim to make advanced defensive capabilities available to legitimate actors large and small while preventing misuse.
Codex Security Impact
Codex Security, launched in private beta six months ago and released as a research preview earlier this year, automatically monitors codebases, validates issues, and proposes fixes. Since its recent launch, Codex Security has contributed to over 3,000 critical and high fixed vulnerabilities, along with many more lower‑severity fixed findings across the ecosystem. The system’s precision and usefulness have improved as models have advanced.
Looking Ahead
OpenAI believes current safeguards sufficiently reduce cyber risk to support broad deployment of existing models and expects similar safeguards to suffice for upcoming more powerful models. However, models explicitly trained and made more permissive for cybersecurity work will require more restrictive deployments and appropriate controls. Over the long term, OpenAI anticipates the need for more expansive defenses for future models whose capabilities will exceed today’s purpose‑built models.