OpenAI is making a deliberate play in the cybersecurity AI race. The company has released GPT-5.4-Cyber, a more permissive version of its flagship model built specifically for defensive security work. The launch is widely seen as a direct response to Anthropic’s Mythos rollout, which remains capped at a whitelist of just 40 organisations.
A Tale of Two Strategies
OpenAI’s new model takes a fundamentally different approach to access. While Mythos restricts use to a small circle of trusted partners, GPT-5.4-Cyber will be available to anyone who passes ID verification through OpenAI’s Trusted Access for Cyber initiative. The company is betting that arming thousands of defenders beats restricting access to a handful of giants.
The technical capabilities are notable. GPT-5.4-Cyber can reverse-engineer compiled software to identify malware or security flaws. That means analysts can inspect programs without needing the original source code, dramatically widening the scope of what defenders can examine under pressure.
OpenAI researcher Fouad Matin put it plainly: “No one should be in the business of picking winners and losers” on who gets to defend their systems.
Government Attention Is Growing
The stakes are high enough that Washington is already paying attention. Treasury Secretary Bessent summoned Wall Street leaders to an emergency Mythos briefing last week, with concerns mounting over its potential hacking capabilities. The move signals that advanced AI models are no longer just a technology debate, but a national security conversation.
What This Means for the Cybersecurity Landscape
It is still unclear how GPT-5.4-Cyber will perform against Mythos on benchmark scores. What is already clear is that the next generation of AI upgrades will carry serious implications for how defenders and attackers operate. The two leading labs are now taking sharply different views on who should hold the keys to powerful defensive AI.
For security teams, the divergence offers a genuine choice. OpenAI is pushing for scale and broad access. Anthropic is prioritising tight control and trusted partnerships. The outcome of that philosophical split could reshape cybersecurity practice for years.
One thing is certain: the race to build AI that can outthink cyber threats is no longer a backroom research effort. It is a public, well-funded competition between two of the most influential AI companies in the world. The organisations that adapt fastest to this new reality will be the ones that survive it.


