
OpenAI's GPT-5.5-Cyber: A controlled rollout of a more capable, permissioned security model for defenders
Published by AINave Editorial • Reviewed by Ramit
OpenAI has released a more permissive version of its cybersecurity AI model, GPT-5.5-Cyber, designed for advanced, authorized security work. The model is only available to vetted cybersecurity companies and researchers under a trust-based access framework. For AI builders and security teams, this rollout signals a trend toward high-capability, access-controlled cyber AI tools that accelerate defense work, but only within trusted programs and governance frameworks.
What happened
OpenAI is updating its GPT-5.5-Cyber model to be both "more permissive and more capable for advanced, authorized cybersecurity work", according to a blog post. Access remains limited to vetted cybersecurity companies and researchers under the Trusted Access for Cyber (TAC) program, which aims to scale access while strengthening safeguards against misuse.
The company is also expanding its cybersecurity partnerships with governments and critical infrastructure operators, including agencies in the U.S., Australia, Canada, France, Germany, Japan, South Korea, and EU institutions such as ENISA. This is part of OpenAI's broader Daybreak security initiative, which includes new tools and programs to speed up software patching.
Why AI builders should care
For teams building security products or managing vulnerability workflows, GPT-5.5-Cyber illustrates a path for deploying specialized AI models under governance and access controls. The model is designed to help defenders move from vulnerability discovery to patching at machine speed, addressing what OpenAI calls a shift in the cybersecurity bottleneck: "the bottleneck is now patching vulnerabilities".
This matters for AI builders because it shows how frontier models can be adapted for narrow, high-stakes domains without broad public release. The Daybreak Cyber Partner Program lets security vendors integrate GPT-5.5 with Trusted Access for Cyber into their products, creating opportunities for third-party tooling that wraps these capabilities.
Practical implications
The updated Codex Security plugin is a key practical component. It enables developers to run scans, assess severity, collect validation evidence, map potential attack paths, and generate patches tailored to a specific codebase for human review. The plugin can also ingest findings from scanners, advisories, bug bounties, or ticketing systems, then automate patch creation at scale and export results into existing vulnerability-management workflows.
OpenAI also launched Patch the Planet, a collaboration with HackerOne and open-source maintainers. More than 30 open-source projects have signed on, including cURL, Go, Python, Sigstore, and pyca/cryptography. The initiative aims to move findings to fixes with governance and human oversight.
OpenAI reports that GPT-5.5-Cyber outperformed GPT-5.5 on benchmarks including CyberGym, ExploitGym, and SEC-bench Pro. These claims come from OpenAI's own announcements and should be treated as vendor-reported results.
Caveats
There is no broad public rollout of GPT-5.5-Cyber. Access is restricted to vetted defenders under the Trusted Access for Cyber program, and the program's details may evolve as partnerships and governance frameworks expand. Performance and capability claims are primarily from OpenAI announcements and media coverage, not independent third-party audits. The model's effectiveness in real-world environments will depend on integration quality, human oversight, and the specific threat landscape.
FAQs
Sources
- OpenAI rolls out more capable version of cyber model
- OpenAI Says AI Broke Cybersecurity — Now It Wants AI To Fix It
- Trusted access for the next era of cyber defense - OpenAI
- Introducing Trusted Access for Cyber - OpenAI
- OpenAI rolls out new GPT-5.5-Cyber to vetted cybersecurity teams - CNBC
- OpenAI Releases GPT‑5.5‑Cyber With Full Automation for Vulnerability ...
- OpenAI rolls out its latest competitor to Anthropic Mythos - here's what it can do
- OpenAI makes its rival to Anthropic's Mythos more widely available to cyber defenders
- Anthropic still won’t hand over its ‘Mythos’ cyber model — even as OpenAI agrees to give the EU a locked-down version of GPT-5.5
- OpenAI’s GPT-5.5-Cyber: What the limited release means for cybersecurity
- OpenAI Opens Cyber Model to EU While Anthropic Keeps Mythos Restricted
- Scaling Trusted Access for Cyber with GPT-5.5 and ... - OpenAI
- OpenAI Is Rolling Out GPT-5.5-Cyber to Critical Defenders ...
- OpenAI rolls out advanced AI cyber model to challenge Anthropic’s Mythos
- OpenAI rolls out its latest competitor to Anthropic Mythos - here's what it can do
- OpenAI to roll out GPT-5.5 Cyber to select users: What it is and who gets access



















