In short
- According to a new report, OpenAI joins Anthropic in locking down the most powerful cyber AI.
- Border models and products now seem too risky to release publicly.
- Top-tier AI is shifting to controlled, invite-only access.
OpenAI is currently building a cybersecurity product that it plans to release exclusively through its ‘Trusted Access for Cyber’ program, according to Axios. The program was announced earlier in February and it is intended to be a controlled rollout that keeps certain products away from the general public and only in the hands of defensive security companies.
OpenAI launched the program following the release of GPT-5.3-Codex, currently the most capable offering in cybersecurity, and is supporting participant access with $10 million in API credits.
The news comes amid growing concerns among cybersecurity experts about the potential for increasingly powerful AI products to overwhelm existing systems. Earlier this week, Anthropic scared himself with his own creation, Claude Mythos.
Anthropic said Mythos is the company’s most capable AI model and proved so effective at finding security vulnerabilities (zero-days in every major operating system and browser) that it decided only a hand-picked group of organizations should have access to it.
Now OpenAI is reportedly doing something similar.
Anthropic is currently fighting a legal battle after the Pentagon labeled it a supply chain risk after the company refused to lift restrictions on Claude’s use for surveillance and autonomous weapons applications. Federal agencies have been investigating AI companies’ security protocols with increasing intensity since early April.
So far, OpenAI has not shared any public information officially confirming or denying the reports.
The reason for the restrictions is not subtle. Anthropic’s Mythos Preview, which leaked before the official rollout, was found to be able to identify “tens of thousands of vulnerabilities” that even advanced human bug hunters would struggle to pinpoint. The model is described as “extremely autonomous” and reasons with the sophistication of a senior security researcher. That kind of capability, available to anyone with an API key, is something that keeps security teams awake at night.
Anthropic’s response was Project Glasswing – a controlled access initiative that Mythos Preview gives only to vetted organizations: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Nvidia, Palo Alto Networks, and about forty others involved in maintaining critical infrastructure.
OpenAI’s decision to shut down products like these seems like an attempt to get ahead of that regulatory burden. By voluntarily restricting access before a government agency says so, OpenAI positions itself as the responsible actor in a space where Anthropic is being pressured.
The limitations also reflect something deeper than caution about one specific model. Anthropic’s own security report acknowledged that Cybench, the benchmark used to assess whether an AI poses a serious cyber risk, is “no longer sufficiently informative about the current capabilities of boundary models” – because Mythos has cleared it completely. The instrument built to measure the hazard is no longer suitable for what is being built. Anthropic added that its overall security determination “involves judgment calls” and that many assessments leave “more fundamental uncertainty.”
As part of the rollout, Anthropic has committed up to $100 million in usage credits and $4 million in direct donations to open-source security organizations. OpenAI has not announced a similar commitment beyond its access program, although both companies frame their limited programs as a net benefit to defensive security. The idea is that giving defenders better tools before attackers get them is worth the trade-off of limiting general access.
The pattern emerging in the frontier AI industry is that the most capable models will no longer appear as broad product launches. They will be distributed more like classified research – selectively, in concert, among organizations that have the infrastructure and intent to use them responsibly.
Daily debriefing Newsletter
Start every day with today’s top news stories, plus original articles, a podcast, videos and more.