Briefing

OpenAI Releases GPT‑5.5 and GPT‑5.5‑Cyber with Trusted Access for Cyber

ai-dev
deadline 1 Jun 2026 · OpenAI CVE-2025-55182

Patch your security tooling to use GPT‑5.5 with Trusted Access for Cyber for most defensive tasks, and enable Advanced Account Security by June 1 2026 for any users who need GPT‑5.5‑Cyber access.

What to do now

Enable Trusted Access for Cyber for your verified defenders, configure Advanced Account Security by June 1 2026, and plan to use GPT‑5.5‑Cyber only for authorized red‑team or penetration testing workflows.

Summary

On May 7 2026 OpenAI released GPT‑5.5, its most advanced model to date, and began rolling out GPT‑5.5‑Cyber in a limited preview for critical‑infrastructure defenders.

Both models are wrapped in the Trusted Access for Cyber (TAC) framework, an identity‑and‑trust system that lowers classifier‑based refusals for vetted users while still blocking malicious requests. TAC requires defenders to have phishing‑resistant authentication, with Advanced Account Security becoming mandatory on June 1 2026 for those accessing the most permissive GPT‑5.5‑Cyber tier.

The default GPT‑5.5 tier supports general‑purpose knowledge work and defensive workflows such as secure code review, vulnerability triage, malware analysis, detection engineering, and patch validation. GPT‑5.5‑Cyber, the preview tier, permits live‑target exploit testing, red‑team simulations, and controlled penetration testing, but only after stronger verification and misuse monitoring.

OpenAI emphasizes that GPT‑5.5‑Cyber is not expected to outperform GPT‑5.5 on all tasks; instead it offers a more permissive sandbox for specialized, authorized workflows. The release is positioned as part of a broader security flywheel, partnering with vendors to accelerate vulnerability disclosure, supply‑chain protection, incident detection, and network‑level mitigations. Defenders can use GPT‑5.5 to review WAF rules, analyze configuration drift, investigate incidents, and manage secure change across complex environments.

Key changes

  • GPT‑5.5 released with enhanced cybersecurity capabilities and Trusted Access for Cyber framework
  • GPT‑5.5‑Cyber preview tier allows live‑target exploit testing, red‑team, and penetration testing under stricter verification
  • TAC requires phishing‑resistant authentication; Advanced Account Security mandatory from June 1 2026 for highest tier
  • Default GPT‑5.5 supports secure code review, vulnerability triage, malware analysis, detection engineering, patch validation
  • GPT‑5.5‑Cyber provides lower classifier refusals for specialized defensive tasks but still blocks credential theft, exploitation, etc
  • OpenAI partners with vendors to create a security flywheel: vulnerability disclosure, supply‑chain tools, EDR/SiEM, WAF, network mitigations

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting