OpenAI Trusted Access for Cyber
OpenAI has introduced Trusted Access for Cyber, an identity and trust-based framework designed to provide security professionals with prioritized access to the cyber-capable GPT-5.3-Codex model. This initiative aims to accelerate the discovery and remediation of software vulnerabilities while mitigating the risk of misuse by malicious actors.
GPT-5.3-Codex and Cyber Defense Capabilities
GPT-5.3-Codex is OpenAI's most cyber-capable frontier reasoning model to date. Unlike previous models that were limited to auto-completing code snippets, GPT-5.3-Codex can work autonomously for extended periods—hours or days—to accomplish complex cybersecurity tasks. These capabilities allow organizations to strengthen their security posture, reduce response times, and improve overall resilience against severe and targeted attacks.
The Trusted Access for Cyber Framework
OpenAI is piloting a trust-based access model to reduce the friction caused by standard safety mitigations. Because requests like "find vulnerabilities in my code" can be used for either defensive patching or malicious exploitation, standard restrictions often hinder good-faith security work.
To address this, OpenAI provides three tiers of access for cybersecurity professionals:
- Identity Verification: Individual users can verify their identity at
chatgpt.com/cyberto access models for high-risk cybersecurity work. - Enterprise Access: Organizations can request trusted access for their entire team through an OpenAI representative.
- Invite-Only Program: Security researchers requiring more permissive or highly capable models for legitimate defensive work can apply for an invite-only program.
Users with trusted access must continue to adhere to OpenAI's Usage Policies and Terms of Use. This framework is intended to prevent prohibited behaviors such as malware creation, data exfiltration, and unauthorized testing.
Safety Mitigations and Monitoring
OpenAI employs a combination of safety training and automated monitoring to manage risk. GPT-5.3-Codex is trained to refuse clearly malicious requests, such as those involving the theft of credentials. Additionally, automated classifier-based monitors are used to detect signals of suspicious cyber activity. OpenAI notes that these mitigations may impact developers and security professionals during the policy calibration phase.
Cybersecurity Grant Program
OpenAI is committing $10 million in API credits through the Cybersecurity Grant Program to further scale defensive cyber work. This program targets teams with a proven track record of identifying and remediating vulnerabilities in open-source software and critical infrastructure systems.