OpenAI has detailed the first rollout of its Trusted Access for Cyber program, pairing $10 million in API credits with broader access to GPT-5.4-Cyber for defensive security work. At the same time, 15 companies and institutions — including Bank of America, BlackRock, Citi, JPMorgan Chase, NVIDIA, Oracle, Cloudflare, and CrowdStrike — have joined as supporters.
Announced on the 16th, the program is built around a tiered access model that matches more advanced capabilities with higher levels of trust, verification, and safeguards. OpenAI’s stated premise is straightforward: top-tier cybersecurity capabilities should reach defenders widely, but access should expand only alongside stronger trust and security controls.
$10 million in API credits targets open-source and vulnerability research
According to OpenAI, the grant pool is meant to support organizations that do not have around-the-clock security teams. The first beneficiaries span four different areas. Socket and Semgrep focus on software supply chain security, scanning dependencies for malicious code and known vulnerabilities. Calif and Trail of Bits are using frontier models alongside vulnerability researchers for binary reverse engineering and high-severity flaw discovery.
OpenAI said it will keep looking for partners with proven work in open-source software and critical infrastructure. The initial scope is broad, but the use cases remain tied to defensive cybersecurity tasks.
Backers include banks, cloud firms, security vendors, and chip makers
The published support list includes Bank of America, BlackRock, BNY, Citi, Cisco, Cloudflare, CrowdStrike, Goldman Sachs, iVerify, JPMorgan Chase, Morgan Stanley, NVIDIA, Oracle, SpecterOps, and Zscaler. The mix brings together traditional finance, cloud infrastructure, cybersecurity providers, and semiconductor leadership.
The lineup shows that OpenAI is trying to build a cross-industry defense network rather than a narrow initiative limited to security vendors. The participation of major financial institutions also points to concrete enterprise demand for defensive AI systems.
U.S. and U.K. agencies are evaluating GPT-5.4-Cyber
On the government side, OpenAI has provided access to GPT-5.4-Cyber to the U.S. AI Safety Institute at NIST’s Center for AI Standards and Innovation (CAISI) and to the U.K. AI Security Institute (UK AISI). Both agencies are expected to independently assess the model’s cybersecurity capabilities and protective mechanisms.
OpenAI describes GPT-5.4-Cyber as a model fine-tuned for defensive cybersecurity workflows, including binary reverse engineering, vulnerability scanning, and malware analysis. The company said the model is already being used by thousands of identity-verified individual defenders and hundreds of teams.

