On April 14, OpenAI announced it is expanding access to GPT-5.4-Cyber, opening it to "thousands of individuals and hundreds of security teams."
The timing is notable — just one week earlier, Anthropic announced Project Glasswing, strictly limiting access to its Claude Mythos (its strongest cybersecurity model) to about 40 top-tier companies.
Two companies, the same problem, and diametrically opposite answers.
What GPT-5.4-Cyber can do
GPT-5.4-Cyber is a cybersecurity-specific version of GPT-5.4, fine-tuned for security scenarios. According to OpenAI, its main capabilities include:
- Binary reverse engineering: Analyze compiled software to identify malicious code, vulnerabilities, and security weaknesses without needing source code.
- Vulnerability research and analysis: Assist security researchers in vulnerability discovery, lowering the barrier to entry.
- Advanced defense workflows: Task chains designed around real-world security team operations.
The restrictions are real. You must pass multi-layered KYC (Know Your Customer) and identity verification to gain access. OpenAI has tiered permissions, with higher-level access requiring stricter institutional background checks.
Anthropic's approach on the other side
Last week, Anthropic announced Project Glasswing with a completely different philosophy.
Claude Mythos is reportedly capable of uncovering 27-year-old vulnerabilities in the cybersecurity domain. Anthropic's internal assessment deemed it "too dangerous" for broad commercial release.
Glasswing's approach: select about 40 top tech companies and grant them restricted access under strict monitoring. If you're not on the list, you're essentially out of luck.
The fundamental divide between two philosophies
These two approaches reflect very different value judgments.
OpenAI's logic, in its own words:
We do not believe it is appropriate or feasible for us to centrally decide who is entitled to defend themselves.
In other words: defenders need tools on par with attackers. If powerful tools are only given to a few elite institutions, thousands of enterprise security teams worldwide lack equivalent capabilities, making the overall security posture worse.
Their solution: broad access + strong verification. As long as you pass identity checks and prove you are a legitimate defender, the tool is available.
Anthropic's logic is the opposite: Mythos-level models are too powerful. Once widely distributed, the benefits to attackers could outweigh those to defenders. Better to limit coverage than risk the tools falling into the wrong hands.
Both companies acknowledge these tools can be used in either direction. The disagreement is over who should be the gatekeeper and how wide the door should open.
Why this divide matters
Consider a real-world scenario: a mid-sized enterprise security team with a limited budget facing a complex supply chain attack. They need powerful vulnerability analysis tools but may never make Anthropic's list of 40.
OpenAI's approach gives such teams a chance to use the tools. Anthropic's approach asks: what if the person who passes KYC is actually an attacker?
This is not a minor technical detail. It represents a fundamental question that AI security tools must answer as they mature.
OpenAI and Anthropic are betting on different probability distributions: the former believes there are more defenders and the verification system is sufficient; the latter believes the risk is too great and prefers less coverage.
By the numbers
Looking at the number of beneficiaries, the gap between the two sides is stark:
| Approach | Coverage | Verification method | Model |
|---|---|---|---|
| OpenAI Trusted Access | Thousands of individuals and teams | Tiered KYC verification | GPT-5.4-Cyber |
| Anthropic Glasswing | About 40 companies | Invitation + monitoring | Claude Mythos |
In the short term, OpenAI's approach will likely win more goodwill from security practitioners — after all, the teams ranked outside the top 40 far outnumber those inside it.
The next test
OpenAI says GPT-5.4-Cyber will continue to iterate, with features adjusted based on real-world usage data.
The real test after this expansion: can the KYC system prevent abuse? If cases emerge where someone passes verification and uses the tool for attacks, the "broad access" strategy will face significant pressure.
Anthropic may be watching and waiting.
Which path is right? The final verdict may have to come from real security incidents.
Sources: OpenAI expands Trusted Access for Cyber to thousands for cybersecurity (CyberScoop); OpenAI rolls out tiered access to advanced AI cyber models (Axios); CocoLoop; Trusted access for the next era of cyber defense (OpenAI Blog)