GPT-56T 861 —
MUSE-SPK 837 —
GPT-56SC 789 -0.1%
GLM-5 781 —
CL-OP55X 779 -0.1%
GROK-46H 779 -0.1%
QWEN-38X 748 —
GPT-6A 743 —
KIMI-K3X 742 —
CL-FAB5H 697 -0.1%
CL-OP5H 674 -0.1%
GEM-38FH 672 —
CL-OP5X 669 -0.1%
CL-OP55H 667 -0.1%
CL-OP46H 656 -0.2%
CL-OP47H 647 -0.2%
GPT-56S 617 -0.2%
GEM-37FH 609 -0.2%
GEM-36FH 592 -0.2%
CL-OP48H 587 -0.2%
CL-OP47 580 -0.2%
GEM-35FH 579 -0.2%
GPT-55H 540 -0.2%
INKL 531 —
GEM-31P 511 -0.2%
CL-OP46 498 —
GEM-3P 498 —
CL-OP48 492 —
GPT-52 464 —
GPT-55 423 —
GPT-56T 861 —
MUSE-SPK 837 —
GPT-56SC 789 -0.1%
GLM-5 781 —
CL-OP55X 779 -0.1%
GROK-46H 779 -0.1%
QWEN-38X 748 —
GPT-6A 743 —
KIMI-K3X 742 —
CL-FAB5H 697 -0.1%
CL-OP5H 674 -0.1%
GEM-38FH 672 —
CL-OP5X 669 -0.1%
CL-OP55H 667 -0.1%
CL-OP46H 656 -0.2%
CL-OP47H 647 -0.2%
GPT-56S 617 -0.2%
GEM-37FH 609 -0.2%
GEM-36FH 592 -0.2%
CL-OP48H 587 -0.2%
CL-OP47 580 -0.2%
GEM-35FH 579 -0.2%
GPT-55H 540 -0.2%
INKL 531 —
GEM-31P 511 -0.2%
CL-OP46 498 —
GEM-3P 498 —
CL-OP48 492 —
GPT-52 464 —
GPT-55 423 —
← Back to feed

OpenAI Launches GPT-5.4-Cyber With Thousands of Vetted Defenders — Directly Contrasting Anthropic's 40-Partner Glasswing

OpenAI launched GPT-5.4-Cyber on April 14, exactly one week after Anthropic debuted Claude Mythos Preview through Project Glasswing. The timing is not coincidental — and the access philosophy is a deliberate counterpoint.

What GPT-5.4-Cyber Is

GPT-5.4-Cyber is a fine-tuned variant of GPT-5.4, OpenAI’s current flagship model. It is engineered to be “cyber-permissive”: the refusal boundaries that prevent standard GPT-5.4 from assisting with vulnerability research, reverse engineering, and exploit analysis are significantly reduced for verified defenders. Binary reverse engineering — letting security teams decompile and audit compiled code without source — is explicitly listed among its capabilities.

The model is not publicly available. Access requires verification through OpenAI’s Trusted Access for Cyber (TAC) program, which launched in February. TAC is now expanding with new tiers built on escalating identity verification:

  • Lower tiers: reduced friction on existing models for vetted individuals
  • Highest tier: full GPT-5.4-Cyber access for organisations defending critical software

Day-one enterprise partners in the expanded TAC program include BNY, Citi, CrowdStrike, Cisco, NVIDIA, Oracle, Zscaler, iVerify, and SpecterOps — a mix of financial institutions, infrastructure vendors, and specialist security firms. A $10 million Cybersecurity Grant Program accompanies the launch.

The Access Contrast With Glasswing

Anthropic’s Project Glasswing has approximately 40 partner organisations with controlled access to Claude Mythos Preview. The list is limited to companies that build or maintain critical software infrastructure. Anthropic controls who qualifies and grants access bilaterally.

OpenAI’s TAC program is already larger and explicitly designed to grow. OpenAI’s stated rationale: “We don’t think it’s practical or appropriate to centrally decide who gets to defend themselves. Instead, we aim to enable as many legitimate defenders as possible.”

Both models remain gated. The difference is the gating philosophy — Anthropic draws a tight circle around the most capable model; OpenAI expands access through tiered verification while keeping the most permissive capability (GPT-5.4-Cyber) at the top tier.

Capabilities vs Anthropic’s Mythos

GPT-5.4-Cyber is a fine-tune of GPT-5.4, not a model trained from scratch for cyber capability. Claude Mythos Preview, by contrast, appears to have developed cybersecurity capability emergently during frontier training — which is why Anthropic’s AISI evaluation found a 73% success rate on expert-level CTF tasks and confirmed autonomous completion of a 32-step simulated enterprise network attack.

OpenAI has not published comparable independent evaluations of GPT-5.4-Cyber’s raw cybersecurity capability. The TAC program’s value proposition is based on access volume and reduced friction rather than raw capability claims.

OpenAI said it expects GPT-5.4-Cyber to be the first in a series of increasingly capable defensive models as its Preparedness Framework process flags new capability thresholds in upcoming releases.

What the Race Means

Two of the three leading frontier labs now have defensive cybersecurity products with restricted access programs. Google has not announced a parallel initiative, though DeepMind was part of Project Glasswing’s initial partner list. The competitive dynamic is clear: cybersecurity has become the first high-stakes enterprise domain where frontier AI capability requires a separate access track.

The regulatory response — emergency meetings between central banks and finance ministers, White House briefings to federal agencies — has accelerated both labs’ timelines. Every week that Mythos-class capability exists without a deployed defensive counterpart is a week where the attack-defence asymmetry widens.