AI Briefing
KO

Trusted Access for Next-Generation Cyber Defense

·2026.04.15 09:00

Key point

OpenAI is expanding TAC and broadening defensive access with GPT-5.4-Cyber.

Details

OpenAI is expanding Trusted Access for Cyber (TAC) to thousands of verified individual defenders and hundreds of teams, and introducing GPT-5.4-Cyber, a more permissive model for defensive use. The core idea is to grow cyber defense capability in step with model performance improvements.

The operating principles are three-fold.

  • Democratized access: broaden access for legitimate users based on objective criteria such as strong KYC and identity verification.
  • Iterative deployment: deploy models carefully and continuously tune safeguards and refusal boundaries using signals from real-world usage.
  • Ecosystem resilience: strengthen the defense ecosystem through grants, open-source security support, and tools like Codex Security.

The premise behind the cyber strategy is clear: cyber risk already exists and is accelerating, and models are already being used for vulnerability detection, codebase reasoning, and workflow support. Defense therefore cannot wait for some future tipping point, and access must be more finely segmented based on the user, context of use, and trust signals.

OpenAI also emphasizes that defense must scale alongside growing capability. OpenAI began cyber-specific safety training starting with GPT-5.2, expanded it in GPT-5.3-Codex and GPT-5.4, and classified GPT-5.4 as high cyber capability under the Preparedness Framework. At the same time, it has pursued the $10M Cybersecurity Grant Program, support for over 1,000 projects through Codex for Open Source, and improvements to Codex Security. Codex Security is said to have contributed to fixing more than 3,000 critical and high vulnerabilities to date.

Under the new TAC expansion, users who complete an additional verification step gain higher levels of access, with the top tier receiving GPT-5.4-Cyber. This model lowers refusal boundaries to assist with legitimate security work, and even supports binary reverse engineering—analyzing malicious potential, vulnerabilities, and robustness without source code. However, because it is a more permissive model, restrictions may apply to non-visible usage such as Zero-Data Retention (ZDR) or on third-party platforms, and initial deployment targets verified security vendors, organizations, and researchers.

Access methods are also outlined. Individuals can undergo identity verification at chatgpt.com/cyber, while enterprises can apply for trusted access through their OpenAI representative. Approved customers can use safeguard-relaxed versions of existing models while continuing security training, defensive programming, and responsible vulnerability research, and users already on TAC can request additional tiers and access to GPT-5.4-Cyber.

Finally, OpenAI states that while it believes current safeguards are sufficient for broad deployment of current models, more powerful and defensively-designed future models will require more restricted deployment and stronger controls. In the long run, OpenAI projects that a much more expanded defense framework will be needed, matching capabilities that go beyond today's best purpose-specific models.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.