OpenAI has launched GPT-5.4-Cyber, a large language model fine-tuned for defensive cybersecurity work. At the same time, it is widening the TAC program, short for Trusted Access for Cyber, beyond a limited pilot to thousands of verified individual defenders and hundreds of teams responsible for protecting critical software. OpenAI also said Codex Security has helped the security community remediate more than 3,000 high and critical vulnerabilities since its recent release.
A security-focused model built on OpenAI’s earlier work
GPT-5.4-Cyber is being positioned as the latest step in a longer cybersecurity roadmap. OpenAI said it began that push in 2023 with a $10 million Cybersecurity Grant Program and started evaluating the cyber capabilities of its models that same year. In 2025, the company released GPT-5.2 with dedicated cybersecurity training for the first time. GPT-5.3-Codex followed with stronger reasoning, and GPT-5.4 was later classified by OpenAI’s own Preparedness Framework as having high cyber capability.
The new GPT-5.4-Cyber model is based on GPT-5.4 but tuned to reduce refusal boundaries for legitimate security work. OpenAI said it also unlocks advanced defensive functions. One of the key additions is binary reverse engineering, which allows analysis of compiled executables without source code to identify malicious potential, vulnerabilities, and software security issues.
Access is wider, but still gated by identity checks
The main design decision in this launch is not only what the model can do, but who gets to use it. OpenAI described GPT-5.4-Cyber as a more permissive model for lawful cybersecurity operations. That also raises the chance that the same capability could be useful to attackers. Its answer is identity-based access control.
The TAC program has two levels. Individual users can obtain baseline access through KYC verification at chatgpt.com/cyber. Companies and research institutions must apply through OpenAI sales representatives for a higher trust tier in order to use the full feature set of GPT-5.4-Cyber. OpenAI refers to this structure as “democratized access,” using clear and objective standards to broaden availability while limiting abuse.
Open-source security efforts are expanding alongside the model
OpenAI also tied the launch to its broader security ecosystem. Codex for Open Source now covers more than 1,000 open-source projects. The company has also contributed funding to the Linux Foundation as part of a $12.5 million open-source security support program. On the remediation side, Codex Security has already assisted in fixing more than 3,000 high and critical flaws since going live.
The source material also noted comparisons with Anthropic’s “Claude Mythos.” In OpenAI’s case, the choice to keep broader cyber capabilities inside a verified-defender access model stands out as a central feature of the release.

