OpenAI Rolls Out GPT-5.5-Cyber to Critical Infrastructure Defenders — Pentesting and Malware RE Now in Scope
OpenAI is rolling out GPT-5.5-Cyber to “critical cyber defenders” — a named frontier model with explicit offensive security capabilities that GPT-5.4-Cyber did not publicly claim. The announcement came April 29 via Sam Altman on X, with a full Cybersecurity Action Plan published simultaneously.
GPT-5.5-Cyber is designed specifically for penetration testing, vulnerability discovery and exploitation, and malware reverse engineering. These are not hedged use cases — OpenAI is explicitly positioning the model as a toolkit for finding and exploiting security weaknesses before attackers do.
What changed from 5.4 to 5.5
GPT-5.4-Cyber, announced April 14, was framed as a “cyber-permissive” fine-tune of GPT-5.4 for defenders. GPT-5.5-Cyber is built on GPT-5.5, the model currently leading the Artificial Analysis Intelligence Index at 60 — four points ahead of the nearest competitors.
The capability jump is meaningful. GPT-5.5 leads SWE-bench Verified at 88.7% and posts 82.0% on Terminal-Bench 2.0 through the Codex CLI agent. Applied to security: higher code comprehension scores translate directly into better vulnerability discovery in complex codebases.
OpenAI is taking a dual-track distribution approach:
- Standard version: Broader access with robust safeguards for organizations that need defensive capabilities without offensive-grade access
- Permissive version: Available through the Trusted Access for Cyber (TAC) program for verified defenders including local water utilities, hospitals, and critical infrastructure operators
Scale of the rollout
The TAC program is scaling from hundreds to thousands of verified individuals and hundreds of teams. OpenAI is also committing $10 million in API grants for vetted security organizations — a direct subsidy to get frontier cyber capability into under-resourced defenders.
The application process requires eligibility requirements and a usage plan. Organizations covering critical infrastructure — specifically called out: local water utilities — are in scope. This is a deliberate contrast with Anthropic’s Glasswing coalition, which launched with 40 named enterprise partners.
The cyber arms race framing
OpenAI published a five-point Cybersecurity Action Plan alongside the rollout:
- Democratizing cyber defense
- Coordinating across government and industry
- Strengthening security around frontier cyber capabilities
- Preserving visibility and control in deployment
- Enabling users to protect themselves
The plan comes three weeks after OpenAI briefed state and federal officials in Washington on GPT-5.5-Cyber capabilities — including national security agencies. The federal access angle is complicated by OpenAI’s ongoing fallout from a Pentagon supply chain risk designation, which it received after refusing to allow its models in autonomous weapons or domestic surveillance.
The counterprogramming
Anthropic’s response to GPT-5.5-Cyber is Claude Security moving to public beta on the same day — April 30 — with a 40-plus partner ecosystem (CrowdStrike, Microsoft Security, Palo Alto Networks, SentinelOne, Wiz) integrating Opus 4.7 into existing enterprise security platforms.
The strategy split is clear: OpenAI is going direct-to-defender, with TAC as the primary distribution channel and government access as the premium tier. Anthropic is going platform-first, embedding into security tools that enterprises already run.
Both models are now explicitly in the offensive capability business. The difference is how they’re managing the access problem — and who they trust to hold the keys.