OpenAI limits GPT-5.5-Cyber to vetted security teams

On May 7, OpenAI introduced a new GPT-5.5 variant called GPT-5.5-Cyber.

This was not the usual broad preview. Access is limited to vetted cybersecurity teams, and from June 1 the highest tier must use phishing-resistant hardware authentication.

The timing is notable: it came less than a month after Anthropic locked Claude Mythos behind a tightly restricted enterprise program.

What changes from the standard model

OpenAI says the initial preview is not meant to make GPT-5.5 dramatically more capable at cyber operations. The point is that it is trained to be more permissive on legitimate security work.

In practice, that means it may assist with red-team automation, proof-of-concept exploit work, attack simulation in real environments, stress testing, and validation of already identified high-risk vulnerabilities.

The line is still explicit. Requests tied to credential theft, deployable malware, or tools designed to cause real-world harm remain outside the allowed scope. OpenAI is effectively saying: use it to rehearse being attacked, not to attack others.

Three tiers, almost like export control

GPT-5.5-Cyber is the top tier in OpenAI's Trusted Access for Cyber program. The public tier is standard GPT-5.5 with default safeguards. A middle tier loosens some controls for registered security workflows. The highest tier, GPT-5.5-Cyber, is for approved red teams and penetration-testing groups.

Each tier requires identity checks and use-case documentation. Accounts are tied to real identities, calls are logged, and access can be revoked. From June 1, the top tier must use phishing-resistant authentication such as FIDO2 or physical security keys.

The logic resembles export control: the more sensitive the capability, the heavier the oversight.

Reading it against Claude Mythos

The UK AI Security Institute evaluated GPT-5.5 and Mythos Preview on the same 32-step simulated enterprise attack chain. GPT-5.5 completed it twice in ten attempts; Mythos Preview completed it three times in ten.

Both systems are still around the 30% mark, but neither looks suitable for unrestricted public release. One extra detail matters: GPT-5.5 independently solved a reverse-engineering task in 10 minutes.

Anthropic's answer was to close Mythos Preview almost completely, limiting it to 12 alliance partners and 40 selected companies. Its own safety report said Mythos found a 27-year-old OpenBSD bug and 271 Firefox vulnerabilities.

OpenAI is taking a different route: the door is open wider, but the lock is stronger. Mythos is a closed research loop; GPT-5.5-Cyber is aimed at a broader set of defenders, with account controls as the backstop.

The business logic behind the policy

Keeping Mythos closed suggests Anthropic wants to capture value by using the model internally to find vulnerabilities and then selling remediation work to enterprises. OpenAI, by contrast, is positioning the model as SaaS for the security industry.

The first GPT-5.5-Cyber users are likely to be major security vendors. Their penetration-testing demand is large, their willingness to pay is high, and every call can feed OpenAI's next generation of cyber models.

That makes the release both a move against Anthropic in the defender market and a way to gather training data. The June 1 hardware-key requirement also speaks to regulators: with CAISI's pre-review protocol still fresh, OpenAI appears to be setting its own rules before harder regulation arrives.

Sources: OpenAI Opens GPT-5.5-Cyber to Vetted Security Researchers (WinBuzzer); CocoLoop, OpenAI tunes GPT-5.5-Cyber for more permissive security workflows (Help Net Security); OpenAI rolls out new GPT-5.5-Cyber to vetted cybersecurity teams (CNBC)