OpenAI has begun rolling out GPT-5.5-Cyber, a frontier model focused on cybersecurity, and it is going first to a curated set of defenders rather than the general public. Sam Altman announced the phased release on X late last week, saying the model would reach trusted partners within days through the company's Trusted Access for Cyber program.

According to OpenAI's announcement, eligibility is limited to government entities, operators of critical infrastructure, established security vendors, major cloud platforms, and financial institutions. The company said it would work with the wider ecosystem and government agencies to define longer-term access policies.

The AISI verdict

The UK's AI Security Institute, which received early access for evaluation, returned a striking assessment. In its published evaluation, AISI rated GPT-5.5 as one of the strongest models it has tested on cyber tasks. On expert-level evaluations the model achieved an average pass rate of 71.4 percent, ahead of Anthropic's Mythos Preview at 68.6 percent and OpenAI's own GPT-5.4 at 52.4 percent. AISI also reported that GPT-5.5-Cyber is only the second system to solve one of its multi-step cyber-attack simulations end to end.

Access controls instead of capability cuts

The release is OpenAI's most direct entry into a sensitive corner of the field. Frontier cyber capability is dual-use by definition: a model that can find a vulnerability quickly can also help an adversary exploit it quickly. OpenAI is leaning on access controls rather than a watered-down model to manage that risk. As Nextgov reports, the rollout is gated through Trusted Access for Cyber partnerships rather than the standard developer API.

The contrast with Anthropic is sharp. Anthropic's analogous model, Mythos, has so far been confined to roughly fifty organisations under a tightly controlled program, Dataconomy notes. OpenAI's broader-but-vetted approach reads as a different bet: that putting a stronger model into the hands of more defenders, faster, is the safer path on the whole.

Whether that bet pays off depends on the discipline of the partners admitted to the programme and the controls around it. The first real test comes in the next few weeks, as security teams begin running GPT-5.5-Cyber against live workloads.

Sources

  1. i. openai.com
  2. ii. www.aisi.gov.uk
  3. iii. www.nextgov.com
  4. iv. dataconomy.com

Commentarii · 0

Add · a · Comment