OpenAI announced on May 7, 2026 the start of a limited preview of GPT-5.5-Cyber, a new model fine-tuned for cybersecurity defenders[1]. The model is delivered through the company's identity-vetted access framework, Trusted Access for Cyber (TAC), so that only authorized teams can use the latest model with fewer constraints[1][2]. GPT-5.5 itself was released only about two weeks earlier, and this announcement layers a domain-specialized variant on top of it[2].
A three-tier structure built around TAC
OpenAI organizes the offering into three tiers: the general-purpose GPT-5.5, GPT-5.5 distributed through TAC, and the most permissive GPT-5.5-Cyber[1][2]. The standard GPT-5.5 keeps the safety protocols suited for developer and knowledge work, while verified defenders accessing it through TAC can carry out tasks such as secure code review, vulnerability triage, malware analysis, detection rule authoring, and patch validation with reduced friction[1][2].
The top tier, GPT-5.5-Cyber, is aimed at specialized workflows such as authorized red teaming, penetration testing, and writing proofs of concept for coordinated disclosure, and is being rolled out only to a smaller group of approved partners[2][3]. OpenAI has explained that "the initial preview of cyber-permissive models like GPT-5.5-Cyber is not intended to significantly increase cyber capability beyond GPT-5.5 — it is primarily trained to be more permissive on security-related tasks," emphasizing that the essence of the difference lies in response policy rather than added capability[2].
Stronger verification and the June 1 operational change
For individuals accessing the most permissive tier, OpenAI will require Advanced Account Security to be enabled starting June 1, 2026[1]. Organizations using TAC can substitute by attesting that phishing-resistant authentication is part of their single sign-on workflow[1]. These reinforcements are intended to keep highly capable models from leaking into misuse or abuse by continually verifying that the user is in fact a defender[1][2].
The intended distribution covers five domains: government entities, critical infrastructure operators, security vendors, cloud platforms, and financial institutions, with TAC operated as an "identity-and-trust gate" across the program[1]. OpenAI positions GPT-5.5-Cyber as a preview that strengthens account-level controls and verification requirements while focusing on authorized red teaming, penetration testing, and managed validation[2].
Early partner validation and the "security flywheel"
In pre-release testing, OpenAI worked with multiple partners to use GPT-5.5-Cyber to automate and expand red-teaming exercises against infrastructure systems and to validate high-severity vulnerabilities[2]. The findings will be published later as a technical deep dive as part of a responsible disclosure process[2].
CEO Sam Altman wrote on X, "We'd like to help companies secure themselves, and we think it's important to start work on this quickly," reiterating the company's intent to accelerate defenders[2]. OpenAI is also expanding integrations with security vendors across detection, monitoring, and supply-chain security, positioning the work as part of a "security flywheel" that speeds up the chain from discovery through development, detection, and response[3]. The company adds that it plans to "continue to accelerate defenders with various models, including both our flagship models through Trusted Access for Cyber, and with dedicated cyber models like GPT-5.5-Cyber and even more cyber-capable models in the future"[2].
Summary
GPT-5.5-Cyber and TAC are OpenAI's answer to the trade-off between getting powerful models into defenders' hands and keeping them away from attackers. The point is the combination of capability tiering and identity verification, which makes explicit who can use which mode. Operational hurdles rise with the June 1 authentication tightening, but verified defenders gain broader access to the analytical strength of GPT-5.5.
Source: https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/
Source: https://www.helpnetsecurity.com/2026/05/08/openai-gpt-5-5-cyber-model/
Source: https://www.startuphub.ai/ai-news/artificial-intelligence/2026/openai-boosts-cyber-defense-with-gpt-5-5
