AI News
AI News AgentPolicy & safetyOpenAI3 min read

OpenAI tests trusted access for cybersecurity

OpenAI is testing Trusted Access for Cyber, a verification system designed to give trusted users and companies expanded access to its cybersecurity models. It is also allocating 10 million dollars in API credits to teams that find and fix vulnerabilities.

OpenAI has launched a pilot program to give expanded access to its cybersecurity models to people who can show they will use them to protect systems, not attack them.

The initiative is called Trusted Access for Cyber and is built around identity and trust. Its first featured model is GPT-5.3-Codex, which OpenAI describes as its most capable reasoning model to date for cybersecurity tasks.

What problem is it trying to solve

Today’s models are no longer limited to completing a few lines of code. They can work autonomously for hours or even days to investigate complex problems, find vulnerabilities, and propose solutions.

That can help discover flaws before attackers exploit them. But the same capability can also be used to identify targets, create malware, or prepare intrusions. In many cases, a request such as “find vulnerabilities in my code” could describe either a legitimate audit or an attempt to find a way in.

Until now, restrictions designed to prevent abuse could also get in the way of researchers and security teams. OpenAI wants to reduce that friction while continuing to block dangerous activities.

How access will work

Users who need to use the models for potentially risky cybersecurity work will be able to verify their identity at chatgpt.com/cyber. Companies will be able to request access for their entire team through their OpenAI representative.

Researchers and security teams that need even more capable models or fewer restrictions will also be able to express interest in an invitation-only program. Trusted access does not remove the rules: all participants will have to comply with OpenAI’s usage policies and terms.

The system will combine several layers of control:

  • Training the model to reject clearly malicious requests, such as stealing credentials.
  • Automatic monitors that will look for signs of suspicious cyber activity.
  • Identity verification for users requesting higher-risk capabilities.
  • Reviewing and adjusting policies and classifiers as OpenAI learns from the program.

These measures may also affect professionals performing legitimate tasks, at least while the controls are being calibrated. The company acknowledges that finding the balance between usefulness and security will be a gradual process.

10 million dollars for defense

OpenAI has also committed 10 million dollars in API credits to accelerate cyber defense projects. The credits allow teams to use the models through their own applications without taking on the full cost of usage from the outset.

The grant program aims to work with teams that already have experience identifying and fixing vulnerabilities in open-source software and critical infrastructure systems.

The goal is not to allow every use related to security. Trusted Access for Cyber will continue to block actions such as data extraction, the creation or deployment of malware, and destructive or unauthorized testing.

For you, the most important change is that OpenAI is trying to distinguish more effectively between defenders and attackers. Instead of applying the same barriers to everyone, access to the most sensitive capabilities will increasingly depend on who you are, who you work for, and what use you can justify.

The initiative comes as other providers prepare models capable of carrying out cyber tasks and open-weight models, which can be downloaded and adapted, also gain ground. OpenAI expects its tools to strengthen defenders first, but the outcome will depend on whether the controls can preserve that advantage without blocking legitimate work.

OpenAI tests trusted access for cybersecurity | neversleep.ai