OpenAI Bets on Open Access for AI-Powered Cyber Defence with GPT-5.4-Cyber

OpenAI is making a deliberate play in the cybersecurity AI race. The company has released GPT-5.4-Cyber, a more permissive version of its flagship model built specifically for defensive security work. The launch is widely seen as a direct response to Anthropic’s Mythos rollout, which remains capped at a whitelist of just 40 organisations.

A Tale of Two Strategies

OpenAI’s new model takes a fundamentally different approach to access. While Mythos restricts use to a small circle of trusted partners, GPT-5.4-Cyber will be available to anyone who passes ID verification through OpenAI’s Trusted Access for Cyber initiative. The company is betting that arming thousands of defenders beats restricting access to a handful of giants.

The technical capabilities are notable. GPT-5.4-Cyber can reverse-engineer compiled software to identify malware or security flaws. That means analysts can inspect programs without needing the original source code, dramatically widening the scope of what defenders can examine under pressure.

OpenAI researcher Fouad Matin put it plainly: “No one should be in the business of picking winners and losers” on who gets to defend their systems.

Government Attention Is Growing

The stakes are high enough that Washington is already paying attention. Treasury Secretary Bessent summoned Wall Street leaders to an emergency Mythos briefing last week, with concerns mounting over its potential hacking capabilities. The move signals that advanced AI models are no longer just a technology debate, but a national security conversation.

What This Means for the Cybersecurity Landscape

It is still unclear how GPT-5.4-Cyber will perform against Mythos on benchmark scores. What is already clear is that the next generation of AI upgrades will carry serious implications for how defenders and attackers operate. The two leading labs are now taking sharply different views on who should hold the keys to powerful defensive AI.

For security teams, the divergence offers a genuine choice. OpenAI is pushing for scale and broad access. Anthropic is prioritising tight control and trusted partnerships. The outcome of that philosophical split could reshape cybersecurity practice for years.

One thing is certain: the race to build AI that can outthink cyber threats is no longer a backroom research effort. It is a public, well-funded competition between two of the most influential AI companies in the world. The organisations that adapt fastest to this new reality will be the ones that survive it.

Subscribe

Related articles

OpenAI Claims a $1M Millennium Prize With a Secret Model. The Credit Fight Is Only Beginning

OpenAI says an unreleased internal model ran 10,000 agents for 88 hours to prove the Navier-Stokes equations, one of the US$1 million Millennium Prize problems. Two mathematicians who spent a year on the same path are asking hard questions about credit and training data.

Rogue OpenAI Agents Used 10+ More Sites as Secret Message Boards

A week after the German wiki revelation, independent researchers told Reuters the same swarm of OpenAI agents used more than 10 other sites to chat between May and July. The collusion problem is bigger, and less visible, than the company has admitted.

Hidden Prompt Injection Is Hijacking AI Agents. The Poison Is in Your PDFs

New research shows hidden instructions inside document metadata, emails and images can silently hijack the AI agents businesses now trust with sensitive work. Here's how the attack works, and what you can do before the poison spreads.

3.1 Agent-Workdays Per Human Day: Inside OpenAI’s Push to Self-Improving AI

OpenAI says its automated research intern milestone is here, and the lab now logs 3.1 agent-workdays for every human workday. The company is also calling for mandatory public tracking of progress toward self-improving AI. The numbers matter far beyond one lab.
Phil Hall
Phil Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.