Expansion of 'Trust-Based Access' for Verified Defenders, Limited Preview Also Underway
OpenAI is expanding its approach to enable the safer utilization of advanced artificial intelligence (AI) in the field of cybersecurity defense. The plan is to support verified security personnel in using GPT-5.5's cybersecurity features exclusively for defensive purposes, and to review control and verification systems through a limited preview targeting high-risk tasks.
OpenAI announced on the 8th that it is expanding 'Trusted Access for Cyber (TAC)' and starting a preview of 'GPT-5.5-Cyber' for selected partners. This move is intended to broaden the scope of defender-centric AI utilization amidst the growing importance of cyber security response.
GPT-5.5 was introduced as a general-purpose model applicable to all aspects of cybersecurity, including vulnerability discovery, analysis, detection, verification, and patching. TAC is an approach designed to enable verified defenders participating in the program to utilize the functions necessary for defensive tasks more effectively while maintaining the model's generality and security.
OpenAI explained that GPT-5.5 with TAC enabled can serve as a fundamental starting point for security work for many security teams and developers. This allows users to perform defense-oriented tasks such as vulnerability identification and classification, malware analysis, binary reverse engineering, detection engineering, and patch verification on systems they manage or have inspection authority over.
On the other hand, requests that could lead to actual damage, such as external system attacks or unauthorized intrusion, are restricted as before.
GPT-5.5-Cyber is being provided as a limited preview for defenders responsible for critical infrastructure security, rather than as a general public model. OpenAI explained that this preview is a phased deployment designed to verify the approaches required for high-risk defense workflows—such as red team activities, penetration testing, and controlled vulnerability verification—as well as user verification, account-level controls, and misuse monitoring, rather than aiming for overall performance improvements.
OpenAI plans to support the security response process—from vulnerability discovery to patching, response, and network-level mitigation—by collaborating with partners in vulnerability research, software supply chain security, detection and monitoring, and network security. Additionally, considering the issue of open source vulnerability proliferation, it will provide access to Codex Security to select key open source project maintainers through the Codex for Open Source program.
“We will support verified defenders in effectively utilizing AI to detect, analyze, and respond to threats, while building a responsible utilization framework through a trust-based approach and phased verification,” said Ko Ki-seok, Head of Policy at OpenAI Korea.