OpenAI restricts GPT-5.5 Cyber access to critical defenders following Anthropic controversy
Access to the new penetration testing and vulnerability identification tool is limited to critical cyber defenders via a credential-based application, with broader distribution pending consultation with the U.S. government

OpenAI has announced a significant shift in its distribution strategy for the GPT-5.5 Cyber cybersecurity testing tool, restricting initial access exclusively to critical cyber defenders. This decision marks a reversal of the company's previous stance on the utility of such gatekeeping measures, following public criticism from CEO Sam Altman regarding similar limitations imposed by rival firm Anthropic on its Mythos tool.
The announcement, confirmed by Altman on X on Thursday, 30 April 2026, details that the rollout of GPT-5.5 Cyber will commence within the next few days. While Altman had previously dismissed restrictions on tools like Mythos as fear-based marketing, the new policy for GPT-5.5 Cyber implements strict controls to mitigate the risks associated with powerful AI capabilities. The tool is designed to facilitate penetration testing, vulnerability identification, and malware reverse engineering, presenting inherent dangers if misused by malicious actors.
To secure access, OpenAI has launched an application form on its website requiring users to submit detailed credentials and information regarding their intended use. This process is currently the sole method for obtaining the tool, which is intended to serve as a defensive toolkit helping organisations identify security holes and test their defences. The company acknowledges that while the tool aids in fortifying defences, the potential for misuse by bad actors necessitates a cautious approach to distribution.
The move to restrict access appears directly influenced by the controversy surrounding Anthropic's handling of the Mythos tool. Although Altman had initially criticised Anthropic for what he termed gatekeeping, OpenAI is now adopting a similar framework. However, reports suggest that despite Anthropic's rhetoric and restrictions, an unauthorised group reportedly managed to gain access to Mythos anyway, leading some critics to question the efficacy of such measures.
In response to the need for broader yet secure access, OpenAI states it is consulting with the U.S. government to identify additional users with legitimate cybersecurity qualifications. The objective is to expand the eligible user base beyond the initial group of critical cyber defenders once the government consultation process yields results. This ongoing effort aims to balance the necessity of widespread security testing with the imperative of preventing the tool from falling into the wrong hands.
