OpenAI is moving GPT-5.5-Cyber behind a restricted access program, placing the model in the hands of only verified cyber defenders. That decision gives the company a cautious posture in a field where the same tool can strengthen defenses or help attackers exploit weaknesses.
Sam Altman said on X that OpenAI will begin rolling out GPT-5.5-Cyber in the coming days. He described it as a frontier cyber model and said the first wave of access will be limited rather than broadly available.
The model is being distributed through Trusted Access for Cyber, or TAC. The program is reserved for cybersecurity professionals and organizations that pass verification before they can use the system.
Applicants are required to submit credentials and explain their intended use in detail. OpenAI says that process is meant to ensure the model is used responsibly for defense against cyberattacks.
The move is notable because Altman previously criticized restricted launches for security-focused AI systems. He had argued that some companies were trying to keep advanced AI in the hands of a smaller group, while also mocking the idea that a limited release necessarily made the technology sound more dangerous than it needed to be.
OpenAI’s latest step now looks much closer to the approach it once questioned. GPT-5.5-Cyber is not being opened widely from the start, and instead is being placed behind tight distribution controls.
A model built for defense, but not without risk
GPT-5.5-Cyber is designed to support cybersecurity work that requires powerful technical analysis. It can assist with penetration testing, help identify and exploit vulnerabilities, and support reverse engineering of malware.
Those capabilities make the model valuable for defenders who want to uncover weak points before hostile actors do. In practical terms, that means security teams can use it to find and close gaps earlier.
At the same time, the same abilities create clear risk. A tool that helps defenders map vulnerabilities can also be misused by malicious actors, which is why models like GPT-5.5-Cyber are often described as dual-use technologies.
That tension helps explain why OpenAI is limiting access so aggressively. The company is treating the model less like a general release and more like a controlled security instrument.
OpenAI is following an industry pattern
The approach also mirrors what Anthropic has done with its own restricted cyber model, Mythos. Anthropic introduced that model with similar limits and a tightly managed rollout process.
Its Project Glasswing involved partnerships with more than 40 companies, including Apple, Google, and Microsoft, for the initial launch. Reports also say Anthropic is considering expanding access to another 70 companies.
That expansion is reportedly being watched closely by the White House. OpenAI has not yet named specific companies that will receive early access to GPT-5.5-Cyber, but TAC already makes clear that the rollout will stay narrow.
The result is a more controlled release strategy across the sector as models become more capable in sensitive domains. For OpenAI, the decision also leaves Altman in a difficult position, since the company is now adopting a model of access restriction that he once criticized.
The debate over who should be allowed to use the most powerful AI systems is therefore still unresolved. With GPT-5.5-Cyber, questions about openness, safety, and control have only become more urgent.
