Altman Called Mythos Gatekeeping 'Fear-Based Marketing.' Then He Gated Cyber.
On April 21, Sam Altman publicly criticised Anthropic for limiting access to its cybersecurity tool Mythos, calling the tactic “fear-based marketing.” On April 30, OpenAI announced it would roll out its own cybersecurity tool, GPT-5.5 Cyber, exclusively “to critical cyber defenders” through a vetted application process.
The application on OpenAI’s website asks for credentials and intended use before access is granted. The capabilities described are almost identical to Mythos: penetration testing, vulnerability identification and exploitation, malware reverse engineering.
The Sequence
- April 9: Anthropic restricts Mythos to a select group of vetted cybersecurity organisations.
- April 21: Altman calls this “fear-based marketing” in a post on X.
- April 21 (same day): An unauthorised group reportedly gains access to Mythos anyway, via a Discord group that used Mercor data to guess the access URL.
- April 30: OpenAI announces Cyber will go only to “critical cyber defenders” and opens a credential-based application form.
The Capability Overlap
Both tools are built on top-tier frontier models and target the same professional users. Mythos is built on Claude’s security-tuned variant. Cyber runs on GPT-5.5. Both can autonomously chain offensive security techniques across multiple steps — the same capability that prompted the restricted release in the first place.
OpenAI says it is consulting with the U.S. government to identify and expand its vetted user base. Anthropic made similar statements about Mythos.
CISA Left Out
One detail both companies share: CISA staffers — the federal agency responsible for protecting U.S. critical infrastructure — have publicly stated they cannot access either tool. Staff at the Cybersecurity and Infrastructure Security Agency told Forbes they are unable to use the latest models from either Anthropic or OpenAI, which limits their ability to assess or defend against adversarial uses of the same capabilities.
OpenAI’s stated rationale for the controlled rollout is safety: the fear that a capable pentest and exploitation tool in the wrong hands accelerates offensive attacks. Anthropic’s rationale was identical. The practical gap between the two companies is currently nine days and one press statement.