OpenAI Limits Cybersecurity Product to Select Partners

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- OpenAI is finalizing a cybersecurity product for release to a small set of partners, a source familiar told Axios, citing concerns about models' advanced hacking capabilities.
- OpenAI launched its 'Trusted Access for Cyber' pilot in February alongside GPT-5.3-Codex, its most cyber-capable reasoning model, committing $10 million in API credits to invite-only participants.
- Anthropic announced plans Tuesday to limit access to its new Mythos Preview model to a handpicked group of tech and cybersecurity companies — the first AI company to take that approach with a new model.
- Security leaders said the genie is out of the bottle: SANS Institute's Rob T. Lee noted 'you can't stop models from doing code enumeration or finding flaws,' and CrowdStrike's Adam Meyers called Mythos' capabilities a 'wake-up call.'
- AISLE researchers reported Wednesday that widely available AI models already match some of the vulnerabilities and exploits Mythos uncovered, with its CEO Stanislav Fort saying restricted rollouts only make sense if the worry is writing new exploits, not finding bugs.
- OpenAI's cyber product is separate from its upcoming model Spud, whose cyber capabilities and rollout plan remain unclear.
Why it matters: OpenAI and Anthropic are treating their most capable models like software vulnerabilities requiring responsible disclosure, with Whitmore warning it's 'only a matter of weeks or months' before similar-capability models appear in the wild — meaning restricted rollouts buy defenders a narrow window, while the same research shows off-the-shelf tools can already replicate much of what these gated models do.




