GPT-56T 861 —
MUSE-SPK 835 -0.7%
GPT-56SC 827 -5.3%
QWEN-38X 824 —
CL-OP55X 820 —
GPT-6A 820 —
GROK-46H 820 -5.2%
GLM-5 784 -8.4%
KIMI-K3X 742 -8.4%
CL-FAB5H 742 -5.7%
CL-OP5H 718 -6%
CL-OP5X 708 -18.2%
CL-OP46H 696 -6.2%
CL-OP47H 688 -6.1%
GEM-38FH 677 +0.1%
GEM-37FH 655 -24.3%
GPT-56S 619 —
GPT-55H 580 —
CL-OP47 579 -0.7%
INKL 531 —
GEM-31P 512 —
GEM-3P 498 —
CL-OP46 496 —
CL-OP48 489 -0.2%
GPT-56T 861 —
MUSE-SPK 835 -0.7%
GPT-56SC 827 -5.3%
QWEN-38X 824 —
CL-OP55X 820 —
GPT-6A 820 —
GROK-46H 820 -5.2%
GLM-5 784 -8.4%
KIMI-K3X 742 -8.4%
CL-FAB5H 742 -5.7%
CL-OP5H 718 -6%
CL-OP5X 708 -18.2%
CL-OP46H 696 -6.2%
CL-OP47H 688 -6.1%
GEM-38FH 677 +0.1%
GEM-37FH 655 -24.3%
GPT-56S 619 —
GPT-55H 580 —
CL-OP47 579 -0.7%
INKL 531 —
GEM-31P 512 —
GEM-3P 498 —
CL-OP46 496 —
CL-OP48 489 -0.2%
← Back to feed

OpenAI Rolls Out GPT-5.5-Cyber to Critical Infrastructure Defenders — Pentesting and Malware RE Now in Scope

OpenAI is rolling out GPT-5.5-Cyber to “critical cyber defenders” — a named frontier model with explicit offensive security capabilities that GPT-5.4-Cyber did not publicly claim. The announcement came April 29 via Sam Altman on X, with a full Cybersecurity Action Plan published simultaneously.

GPT-5.5-Cyber is designed specifically for penetration testing, vulnerability discovery and exploitation, and malware reverse engineering. These are not hedged use cases — OpenAI is explicitly positioning the model as a toolkit for finding and exploiting security weaknesses before attackers do.

What changed from 5.4 to 5.5

GPT-5.4-Cyber, announced April 14, was framed as a “cyber-permissive” fine-tune of GPT-5.4 for defenders. GPT-5.5-Cyber is built on GPT-5.5, the model currently leading the Artificial Analysis Intelligence Index at 60 — four points ahead of the nearest competitors.

The capability jump is meaningful. GPT-5.5 leads SWE-bench Verified at 88.7% and posts 82.0% on Terminal-Bench 2.0 through the Codex CLI agent. Applied to security: higher code comprehension scores translate directly into better vulnerability discovery in complex codebases.

OpenAI is taking a dual-track distribution approach:

  • Standard version: Broader access with robust safeguards for organizations that need defensive capabilities without offensive-grade access
  • Permissive version: Available through the Trusted Access for Cyber (TAC) program for verified defenders including local water utilities, hospitals, and critical infrastructure operators

Scale of the rollout

The TAC program is scaling from hundreds to thousands of verified individuals and hundreds of teams. OpenAI is also committing $10 million in API grants for vetted security organizations — a direct subsidy to get frontier cyber capability into under-resourced defenders.

The application process requires eligibility requirements and a usage plan. Organizations covering critical infrastructure — specifically called out: local water utilities — are in scope. This is a deliberate contrast with Anthropic’s Glasswing coalition, which launched with 40 named enterprise partners.

The cyber arms race framing

OpenAI published a five-point Cybersecurity Action Plan alongside the rollout:

  1. Democratizing cyber defense
  2. Coordinating across government and industry
  3. Strengthening security around frontier cyber capabilities
  4. Preserving visibility and control in deployment
  5. Enabling users to protect themselves

The plan comes three weeks after OpenAI briefed state and federal officials in Washington on GPT-5.5-Cyber capabilities — including national security agencies. The federal access angle is complicated by OpenAI’s ongoing fallout from a Pentagon supply chain risk designation, which it received after refusing to allow its models in autonomous weapons or domestic surveillance.

The counterprogramming

Anthropic’s response to GPT-5.5-Cyber is Claude Security moving to public beta on the same day — April 30 — with a 40-plus partner ecosystem (CrowdStrike, Microsoft Security, Palo Alto Networks, SentinelOne, Wiz) integrating Opus 4.7 into existing enterprise security platforms.

The strategy split is clear: OpenAI is going direct-to-defender, with TAC as the primary distribution channel and government access as the premium tier. Anthropic is going platform-first, embedding into security tools that enterprises already run.

Both models are now explicitly in the offensive capability business. The difference is how they’re managing the access problem — and who they trust to hold the keys.