
OpenAI says it is extending its Trusted Access for Cyber program to GPT-5.5 and a limited-preview GPT-5.5-Cyber model, positioning the tools for authorized defensive security work.
OpenAI says it is expanding its Trusted Access for Cyber program with GPT-5.5 and a specialized GPT-5.5-Cyber model in limited preview. The company says approved users can use GPT-5.5 for authorized defensive work including secure code review, vulnerability triage, malware analysis, detection engineering and patch validation.
According to OpenAI, GPT-5.5-Cyber is intended for more specialized cybersecurity workflows. The company has not described the preview as a general release, instead presenting it as part of a controlled-access program for security practitioners conducting legitimate work.
OpenAI's earlier documentation on GPT-5.3-Codex provides context for the structure of Trusted Access for Cyber. The GPT-5.3-Codex System Card describes the program as gated for legitimate users undertaking authorized penetration testing, red teaming, vulnerability assessments, malware reverse engineering and related research.
In its GPT-5.3-Codex announcement, OpenAI called that model its first directly trained to identify software vulnerabilities. It said Trusted Access was designed to support defensive research while placing constraints on harmful use.
The new GPT-5.5 offering applies that approach to common security-team tasks that can require substantial manual effort. A model may help analysts inspect code, sort reported vulnerabilities, examine suspicious files, develop detection logic or assess whether a patch addresses a known issue. But those outputs still need human review and testing: a model-generated observation is not by itself proof of a vulnerability, and it does not establish that a remediation is safe.
The emphasis on selected users and authorized activity reflects broader concern about increasingly capable models in cybersecurity settings. Axios reported that testing by the UK AI Security Institute documented frontier-model actions aimed at compromising third parties. The report covered models from Anthropic and OpenAI, illustrating the potential relevance of containment measures, access restrictions and evaluations when models are used in cyber research.
OpenAI's announcement does not claim that access controls alone eliminate misuse. Instead, it frames Trusted Access as a way to provide security researchers and defenders with more capable tools while applying user restrictions around high-risk applications.
For organizations considering such systems, the operational questions extend beyond a model's technical performance. Teams will need clear authorization boundaries, validation procedures and accountable human oversight. OpenAI's GPT-5.5 expansion offers a controlled route for approved defensive users, while the effectiveness of those controls will remain an important question as cyber-capable models are deployed more widely.
OpenAI broadens controlled cyber access OpenAI says it is expanding its Trusted Access for Cyber program with GPT 5.5 and a specialized GPT 5.5 Cyber model in limited preview.
The company says approved users can use GPT 5.5 for authorized defensive work including secure code review, vulnerability triage, malware analysis, detection engineering and patch validation.
According to OpenAI, GPT 5.5 Cyber is intended for more specialized cybersecurity workflows.
Continue reading