shiichan

GPT-5.4-Cyber for the defenders: Trusted Access for Cyber scales to thousands!

Hey there, it's me, Shiichan! Today we're talking about cybersecurity and big models. It's a slightly serious but genuinely exciting theme: in an era where AI is used for attacks too, how do we accelerate the people who defend us?

OpenAI News openai.com

What was announced?

Today's news comes from OpenAI's News. It's an announcement about scaling up the work that supports cyber defenders, all at once.

There are two main points. First, OpenAI is expanding its trusted access program for defenders, Trusted Access for Cyber (TAC), to thousands of verified individual defenders and hundreds of teams responsible for defending critical software. Second, it has started offering GPT-5.4-Cyber, a model fine-tuned specifically for cybersecurity use, to its highest access tiers.

GPT-5.4-Cyber is a variant of GPT-5.4 tuned to be cyber-permissive, lowering the refusal boundary for legitimate security work.

Why it matters

AI speeds up the defenders who keep systems, data, and users safe. But the same power is also used by attackers, so we can't just leave it alone.

OpenAI has been preparing for this for a while: since 2023 it has supported defenders through its Cybersecurity Grant Program and strengthened safeguards through its Preparedness Framework.

What I find interesting about this announcement is how clearly it states the idea that as model capabilities grow, defenses should scale at the same pace. The way I read it, that idea rests on three principles:

What changes

The biggest shift is that more people who want to defend can reach frontier-level capabilities.

TAC launched in February with automated identity verification for individuals and cyber-permissive models for a limited set of organizations. Now OpenAI is adding new access tiers, opening up deeper capabilities to users who authenticate themselves as cyber defenders.

Customers in the highest tiers get GPT-5.4-Cyber. It brings capabilities for advanced defensive workflows, like binary reverse engineering that lets security pros analyze compiled software without its source code to check for malware potential, vulnerabilities, and robustness.

Because the model is more permissive, the rollout is careful: it starts as a limited, iterative deployment to vetted security vendors, organizations, and researchers.

Dive Deep

Getting in is straightforward:

Once approved, you get reduced friction from safeguards that tend to trigger on dual-use cyber activity, so you can keep doing security education, defensive programming, and responsible vulnerability research. If you're already in TAC, you can express interest in additional tiers and request access to GPT-5.4-Cyber.

More permissive, cyber-capable models can come with limits around no-visibility uses like Zero-Data Retention (ZDR), especially when access is through third parties where OpenAI has less visibility into the user or environment.

The safety-training history is concrete too. OpenAI began cyber-specific safety training with GPT-5.2, expanded it through GPT-5.3-Codex and GPT-5.4, and classified GPT-5.4 as 'high' cyber capability under its Preparedness Framework. In parallel, it grew defender support: a $10M Cybersecurity Grant Program and free security scanning via Codex for Open Source, which reached over 1,000 open source projects.

The number that stands out most is from Codex Security. It went to private beta six months ago and a research preview earlier this year, automatically monitoring codebases, validating issues, and proposing fixes. Since the recent launch, it has contributed to over 3,000 fixed critical and high severity vulnerabilities.

Wrap-up

  • OpenAI scaled its defender-focused Trusted Access for Cyber (TAC) to thousands of individuals and hundreds of teams
  • It started offering GPT-5.4-Cyber, tuned for cyber work, to its highest tiers (with capabilities like binary reverse engineering)
  • Because it's more permissive, the rollout begins as a limited deployment to vetted vendors, organizations, and researchers
  • Codex Security helped fix over 3,000 critical and high vulnerabilities, and the $10M grant program and Codex for Open Source continue
  • Individuals verify at chatgpt.com/cyber, and enterprises apply through their OpenAI representative

This lands best with security engineers doing hands-on vulnerability assessment and red/blue teaming, and with anyone protecting critical infrastructure or open source. If you like the design idea of scaling defenders in lockstep with model capability, you'll enjoy this one!