GPT-5.4-Cyber: OpenAI Launches New AI Cybersecurity Model After Anthropic’s Mythos

Quick Reads
- OpenAI has launched a new AI model called GPT-5.4-Cyber, designed specifically for defensive cybersecurity work.
- The release comes one week after Anthropic unveiled its own advanced model, Claude Mythos Preview, to a restricted group of about 40 organisations.
- GPT-5.4-Cyber is a fine-tuned version of GPT-5.4 with fewer restrictions on sensitive security tasks, available only to vetted users.
- Access runs through OpenAI’s Trusted Access for Cyber programme, which launched in February and is now being scaled to thousands of verified security professionals.
- The two companies are taking noticeably different approaches: Anthropic is more restrictive; OpenAI is betting on wider, identity-verified access.
GPT-5.4-Cyber Is OpenAI’s Answer to the AI Cybersecurity Race
OpenAI launched a new AI model on Tuesday built specifically for cybersecurity defence. The model, GPT-5.4-Cyber, was announced alongside the next phase of the company’s broader cybersecurity strategy. The announcement arrived just one week after rival Anthropic introduced Claude Mythos Preview a powerful AI model restricted to a small group of partners over fears it could be weaponised by hackers. The two releases together signal that AI companies are now openly competing on cybersecurity as a frontier battleground.
What GPT-5.4-Cyber Actually Does
GPT-5.4-Cyber is not a general-purpose AI model. It is a version of GPT-5.4 with a lowered refusal boundary for legitimate cybersecurity work. It enables new capabilities for advanced defensive workflows, including binary reverse engineering the ability to analyse compiled software for malware and security weaknesses without needing access to source code.
Standard AI models often block sensitive technical questions. GPT-5.4-Cyber lifts many of those restrictions for verified users. This means security professionals can ask it things that a regular AI assistant would typically refuse to help with.
OpenAI’s Codex Security product, which launched in private beta six months ago, has already contributed to fixes for more than 3,000 critical and high-severity vulnerabilities across the ecosystem since its broader launch. GPT-5.4-Cyber builds on that foundation.
How OpenAI Is Controlling Who Gets Access
OpenAI is not opening GPT-5.4-Cyber to everyone. The company is adding new tiers to its Trusted Access for Cyber programme, with higher levels of identity verification unlocking more powerful capabilities. Users approved for the highest tier gain access to GPT-5.4-Cyber, which has fewer restrictions on sensitive tasks like vulnerability research and analysis.
OpenAI plans to expand access to thousands of individuals and hundreds of security teams through the programme, provided they complete verification checks.The programme launched in February, alongside a $10 million cybersecurity grant programme confirmed in OpenAI’s official blog post.
This is a notable difference from how Anthropic handled Mythos. OpenAI’s approach differs from Anthropic’s more restrictive rollout, where only about 40 organisations are getting access to Mythos Preview. OpenAI’s Fouad Matin put it plainly: “No one should be in the business of picking winners and losers when it comes to cybersecurity.”
The Anthropic Context and Why This Rivalry Matters
To understand why OpenAI moved when it did, you need to understand what Anthropic announced a week earlier. Anthropic released a preview of its frontier model, Mythos, for use by a select group of partner organisations as part of a new security initiative called Project Glasswing. The company claims that Mythos identified thousands of zero-day vulnerabilities previously unknown security flaws many of them critical and some one to two decades old. TechCrunch
The partners involved in Project Glasswing include some of the most powerful companies in technology. They include Amazon, Apple, Broadcom, Cisco, CrowdStrike, the Linux Foundation, Microsoft, and Palo Alto Networks. Anthropic committed up to $100 million in usage credits for Mythos Preview across these efforts, as well as $4 million in direct donations to open-source security organisations
OpenAI appeared to be seeking to differentiate its message by striking a less catastrophic tone. The company wrote in its blog post: “We believe the class of safeguards in use today sufficiently reduce cyber risk enough to support broad deployment of current models.”That is a direct, if indirect, pushback on Anthropic’s alarming framing.
Security researchers, meanwhile, are divided. Some experts say the concern about these models is overstated and could feed a new wave of anti-hacker sentiment consolidating power even further with tech giants. Others emphasise that vulnerabilities in current security defences are real and could be exploited with new speed and intensity by a broader range of bad actors in the age of agentic AI.





