OpenAI Rolls Out GPT-5.5-Cyber to Cybersecurity Teams

OpenAI began rolling out GPT-5.5-Cyber in limited preview to vetted critical-infrastructure defenders on May 7, 2026, a more permissive cyber-focused variant of GPT-5.5 for authorized red-teaming, penetration testing, and exploit validation, according to OpenAI's own blog and CNBC. The UK AI Security Institute separately found GPT-5.5 is the second model (after Anthropic's Mythos) to complete its 32-step corporate-network attack simulation end-to-end, and that red-teamers developed a universal jailbreak eliciting violative cyber content in about six hours, with a safeguard configuration issue preventing AISI from verifying the fix. TechCrunch and The Register note OpenAI had criticized Anthropic's gated Mythos rollout weeks earlier before adopting a similar gated-access model for GPT-5.5-Cyber itself.
For security leaders, the most consequential fact here is not the product launch, it is the UK AI Security Institute's finding that expert red-teamers built a universal jailbreak against GPT-5.5-Cyber's safeguards in about six hours, and that a configuration issue meant AISI could not verify whether OpenAI's subsequent fix actually closed the gap. That is a concrete, independently sourced data point on how fragile current safeguards are for a model explicitly designed to be more permissive on offensive-security tasks.
What happened
OpenAI began rolling out GPT-5.5-Cyber in limited preview on May 7, 2026 to defenders responsible for securing critical infrastructure, according to OpenAI's own announcement and CNBC. Per OpenAI, access runs on a three-tier Trusted Access for Cyber (TAC) framework: standard GPT-5.5 for general use; GPT-5.5 with TAC for most defensive workflows such as vulnerability triage, malware analysis, and patch validation; and GPT-5.5-Cyber, the most permissive tier, reserved for a smaller set of vetted partners doing authorized red-teaming, penetration testing, and controlled exploit validation. OpenAI's post quotes its own framing: "GPT-5.5-Cyber lets a smaller set of partners study advanced workflows where specialized access behavior may matter." TechCrunch reports a company spokesperson said TAC overall has scaled to thousands of verified defenders and hundreds of teams.
Technical context
The UK AI Security Institute's own evaluation found GPT-5.5 achieved a 71.4% pass rate on its hardest ("Expert") cyber tasks, ahead of Mythos Preview's 68.6%, GPT-5.4's 52.4%, and Opus 4.7's 48.6%, and became the second model to complete AISI's 32-step simulated corporate-network attack chain end-to-end (in 2 of 10 attempts, versus Mythos's 3 of 10). AISI separately red-teamed GPT-5.5-Cyber's safeguards and identified a universal jailbreak that elicited violative content across every malicious cyber query OpenAI provided, including in multi-turn agentic settings, developed in about six hours of expert effort; a configuration issue in the version OpenAI subsequently provided meant AISI could not verify whether the updated safeguard stack closed that gap.
Industry context
The Register and TechCrunch note the rollout arrives weeks after OpenAI CEO Sam Altman publicly criticized Anthropic for gating access to its own cyber model, Claude Mythos Preview, to roughly 50 vetted organizations, at one point likening Anthropic's approach to fear-based marketing ("We have built a bomb, we are about to drop it on your head. We will sell you a bomb shelter for $100 million," per TechCrunch). OpenAI's GPT-5.5-Cyber preview uses a comparably gated access model. Separately, OpenAI's post names security and infrastructure partners including Cisco, CrowdStrike, Palo Alto Networks, Snyk, and Intel, with Cisco's chief security officer Anthony Grieco describing frontier models as "a powerful force multiplier for defenders."
For practitioners
Security teams evaluating access should track which TAC tier actually fits their workflow, since OpenAI positions GPT-5.5 with standard TAC, not GPT-5.5-Cyber, as sufficient for most legitimate defensive work including vulnerability triage and patch validation. AISI's jailbreak finding is a concrete reason to treat vendor safeguard claims for permissive cyber models as unverified until independently re-tested, and to plan monitoring and access controls accordingly rather than relying on the vendor's classifier-based restrictions alone.
What to watch
Watch for OpenAI's promised technical deep-dive documenting GPT-5.5-Cyber's alpha-testing red-teaming and vulnerability-validation results, whether AISI or another evaluator publishes a follow-up assessment of the fixed safeguard configuration, and whether government engagement (OpenAI cites conversations with federal and state officials) shapes eligibility criteria for broader access over time.
Key Points
- 1OpenAI rolled out GPT-5.5-Cyber in limited preview on May 7, 2026, its most permissive tier for vetted red-teaming and exploit validation.
- 2The UK AI Security Institute found GPT-5.5 is the second model to complete its 32-step attack simulation end-to-end, edging out Anthropic's Mythos.
- 3AISI red-teamers built a universal jailbreak in about six hours and could not verify OpenAI's subsequent safeguard fix due to a configuration issue.
Scoring Rationale
Upgraded from 7.2: beyond the product rollout, an independent government evaluator (UK AISI) reported both a competitive benchmark result and, more importantly, a universal jailbreak developed in six hours with an unverified fix, a concrete, high-stakes safety finding on a live, permissioned cyber-offensive model. That combination of real-world deployment plus an independently sourced safeguard failure pushes this into the major tier for security practitioners.
Sources
Primary source and supporting public references used for this report.
View 6 more sources
- OpenAI Launches Cybersecurity Preview To Challenge Anthropic's Mythosbenzinga.com
- Scaling Trusted Access for Cyber with GPT-5.5 and GPT-5.5-Cyberopenai.com
- Our evaluation of OpenAI's GPT-5.5 cyber capabilitiesaisi.gov.uk
- After dissing Anthropic for limiting Mythos, OpenAI restricts access to Cyber, tootechcrunch.com
- OpenAI locks GPT-5.5-Cyber behind velvet rope despite slamming Anthropic for doing exactly thattheregister.com
- Oracle CISO Perspective: Mythos, GPT 5.5-Cyber, and the CISO's New Threat Modelateam-oracle.com
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems


