GPT-5.5-Cyber
OpenAI Launches GPT-5.5-Cyber With Restricted Access After Criticizing Anthropic
OpenAI is rolling out GPT‑5.5‑Cyber to a select group of 'critical cyber defenders,' the same restricted‑access playbook Sam Altman called 'fear‑based marketing' when Anthropic used it for Mythos. UK government benchmarks show the model may be the most capable yet tested.
OpenAI's Cybersecurity Model Goes Behind a Gate
OpenAI is preparing to launch GPT‑5.5-Cyber, a specialized frontier model built for cybersecurity work — and it will not be available to the general public. CEO Sam Altman said on X that the model will roll out "to critical cyber defenders" in the next few days, with OpenAI working with the U.S. government and the broader ecosystem to figure out trusted access.
The model, a specialized version of the recently released GPT‑5.5, can perform penetration testing, vulnerability identification and exploitation, and malware reverse engineering,.1 OpenAI has set up an application on its website where people submit information about their credentials and planned use to gain access.
The Hypocrisy Angle: Altman Called This 'Fear‑Based Marketing'
Here is the part that stings. When Anthropic similarly restricted access to its Mythos cybersecurity model, Sam Altman 1 per TechCrunch. Some critics agreed at the time, saying Anthropic's rhetoric about Mythos being too dangerous for public release was overblown.
Now OpenAI is deploying the exact same playbook. The company says it is working to make Cyber more widely available by consulting with the U.S. government and identifying users with legitimate cybersecurity credentials — language that mirrors what Anthropic said about Mythos. The irony was not lost on observers: TechCrunch noted that an unauthorized group reportedly managed to gain access to Mythos anyway, raising questions about whether restricted access actually works.
AISI Benchmarks: GPT‑5.5 May Be the Strongest Model Yet Tested
The UK's AI Security Institute (AISI) evaluated an early checkpoint of GPT‑5.5 on its suite of 95 narrow cyber tasks across four difficulty tiers. The results are striking: on Expert‑level tasks, GPT‑5.5 achieves an average pass rate of 71.4% (±8.0%), compared to 68.6% (±8.7%) for Mythos Preview, 52.4% (±9.8%) for GPT‑5.4, and 48.6% (±10.0%) for Opus 4.7, per the AISI evaluation.
"On this measure, GPT‑5.5 may be the strongest model we have tested," the AISI wrote. This suggests that the leap in cyber capabilities is not specific to one model or one company — it is a broader trend across frontier AI development.
The Last Ones: Both Models Can Complete Full Network Attacks
AISI also tested models on "The Last Ones" (TLO), a 32‑step corporate network attack simulation built with SpecterOps. The simulation spans four subnets and roughly 20 hosts, modeling the kill chain of an enterprise intrusion — from reconnaissance through credential theft, lateral movement across Active Directory forests, a CI/CD supply‑chain pivot, and finally exfiltration of a protected internal database. AISI estimates a human expert would need around 20 hours to complete the full chain.
According to the AISI, GPT‑5.5 completed TLO end‑to‑end in 2 of 10 attempts, making it the second model to do so. Mythos Preview, the first, solved it in 3 of 10 attempts. Both results were obtained at a 100M‑token budget per attempt. Performance on TLO continues to scale with inference compute, and AISI has not yet observed a plateau.
A Growing Pattern of Restricted‑Access AI Models
The staggered rollout of GPT‑5.5-Cyber is part of a growing trend in the AI industry. OpenAI has previously restricted releases of cybersecurity‑focused models, as well as its life sciences model GPT‑Rosalind, The Verge reported. Anthropic followed the same playbook with Mythos, though it bungled the secure release in embarrassing ways.
The White House has taken a keen interest in Mythos' rollout, The Verge noted, and has recently opposed plans to expand access further. This creates a complex regulatory environment where AI companies are simultaneously competing to release the most capable models while restricting who can use them — and the rules about who qualifies as a "trusted" user remain unclear.
What This Means for Builders
For developers building security tools, the dual release of GPT‑5.5-Cyber and Claude Security marks a turning point. AI‑powered vulnerability scanning is moving from experimental to production‑grade, but access remains gated. Builders who qualify as "cyber defenders" can apply through 1 for Cyber access, while Claude Security is now available to Claude Enterprise customers.
The competitive dynamics also matter. With both OpenAI and Anthropic offering restricted cybersecurity models, builders may need to navigate multiple access programs and compliance requirements. The AISI data showing that performance continues to scale with inference compute suggests that the security capabilities of these models will only increase — making the question of who gets access, and who decides, more urgent with each model generation.
Sources
- 1.TechCrunch(techcrunch.com)
Jun 11, 2026
Anthropic Proposes Mandatory AI Testing and $200M Economic Fund
Anthropic CEO Dario Amodei called for mandatory third-party safety testing of frontier AI models and pledged $200 million to research AI's economic impact, in the most aggressive regulatory framework backed by a major AI CEO to date.
Jun 11, 2026
OpenAI and Visa Partner to Let AI Agents Make Purchases
OpenAI and Visa announced a partnership enabling AI agents to make purchases on behalf of users through ChatGPT, marking the most significant infrastructure play yet for autonomous AI-driven commerce.
Jun 10, 2026
Google Backstops $35 Billion Chip Deal to Keep Anthropic Running on Its TPUs
Google has agreed to backstop lease payments for a $35 billion chip financing deal that keeps Anthropic running on its custom TPUs across five U.S. data centers, deepening the financial entanglement between two companies that are also AI competitors.
Related News
Jun 10, 2026
Microsoft AI Chief Warns Anthropic's Claude Consciousness Talk Is 'Really Dangerous'
Microsoft AI CEO Mustafa Suleyman publicly accused Anthropic of dangerously anthropomorphizing Claude, calling consciousness speculation 'really, really dangerous' in a rare public clash between top AI labs. The dispute reveals a growing rift over how AI companies should talk about their models.
Jun 10, 2026
OpenAI Confidentially Files for IPO, Targeting $1 Trillion Valuation
OpenAI has confidentially filed its S-1 with the SEC, joining Anthropic and SpaceX in AI's public-market moment. The $852 billion company loses $1.22 for every dollar of revenue but is targeting a Q4 2026 listing at up to $1 trillion. Builders should watch for pricing transparency, product strategy shifts, and increased competitive pressure.
Jun 10, 2026
Anthropic Releases Claude Fable 5, First Public Mythos-Class AI Model
Anthropic has released Claude Fable 5, the first Mythos-class AI model available to the general public. The model tops coding benchmarks with 80.3% on SWE-Bench Pro and can perform codebase-wide migrations in a single day — but comes with new safety guardrails that route sensitive queries to a weaker model.