OpenAI Scales Trusted Access for Cyber Defenders
07 Jul 2026
OpenAI is expanding its Trusted Access for Cyber (TAC) program and launching GPT-5.4-Cyber, a version of GPT-5.4 fine-tuned specifically for cybersecurity use with what the company calls "cyber-permissive" capabilities. The move, announced April 14, 2026, extends verified access to thousands of individual defenders and hundreds of teams — a significant scale-up from the program's initial launch in February 2026.
What's happening
TAC provides advanced cyber capabilities to defenders whose access level is determined by trust, validation, and safeguards. OpenAI has introduced additional access tiers for users who authenticate themselves as cybersecurity defenders, and GPT-5.4-Cyber access has already been granted to the U.S. Center for AI Standards and Innovation (CAISI) and the UK AI Security Institute (UK AISI) for evaluations.
The expansion builds on groundwork laid over the past three years:
- 2023: OpenAI launched its Cybersecurity Grant Program.
- 2025: The company began including cyber-specific safeguards in model deployments.
- ~October 2025: Codex Security entered private beta.
- Early 2026: Codex Security moved to research preview.
- February 2026: TAC was introduced.
- April 14, 2026: Scaled TAC access and GPT-5.4-Cyber were announced.
The numbers behind the push
OpenAI has committed $10 million in API credits to its Cybersecurity Grant Program, with initial recipients including Socket, Semgrep, Calif, and Trail of Bits. Beyond the grant program, Codex for Open Source has reached over 1,000 open source projects, and Codex Security has contributed to fixes for over 3,000 critical and high vulnerabilities since launch.
The program is backed by a notably broad coalition — Bank of America, BlackRock, BNY, Citi, Cisco, Cloudflare, CrowdStrike, Goldman Sachs, iVerify, JPMorgan Chase, Morgan Stanley, NVIDIA, Oracle, Palo Alto Networks, SpecterOps, US Bank, and Zscaler are all listed as supporters.
What's still unclear
Several operational details remain undisclosed. OpenAI has not specified exactly what qualifies a user as a "verified" defender or detailed the validation process. There's no public information on pricing, general availability timelines for GPT-5.4-Cyber, or a technical breakdown of what "cyber-permissive capabilities" actually entail versus standard GPT-5.4. The company also hasn't disclosed how the $10 million in grant credits will be allocated, nor how many defenders and teams are currently enrolled against the stated targets of "thousands" and "hundreds."
Why founders should care
For cybersecurity startups, this expansion likely signals a growing pathway to advanced AI tooling through tiered, verified access — though the exact qualification bar remains undefined, so founders should not assume automatic eligibility. The grant program may represent a plausible funding or resourcing avenue for early-stage security tooling companies, particularly those already engaged in open-source vulnerability work similar to Codex Security's focus areas.
The involvement of government bodies like CAISI and UK AISI in evaluating GPT-5.4-Cyber suggests regulatory scrutiny of AI-cyber capabilities is probably increasing, and founders building in this space should track how these evaluations shape future access rules or compliance expectations. Additionally, the concentration of trusted access among large financial and tech institutions raises a real possibility that smaller or under-resourced defenders could face slower or more limited entry into these programs — a dynamic worth monitoring for startups that don't have enterprise-scale security credentials.
Finally, the scale of enterprise backing — from major banks to cybersecurity vendors — hints that demand for verified, safeguarded AI use in security contexts is likely to keep growing, which could shape procurement expectations for security startups pitching to similar customers.
Risks to watch
OpenAI's own framing acknowledges that cyber-permissive AI capabilities could be misused if verification or access controls are circumvented. The program's reliance on self-authentication for defender status also creates potential for exploitation by bad actors claiming defender credentials. Founders evaluating or building on top of these tools should weigh these risks alongside the opportunities.