Accelerating the cyber defense ecosystem that protects us all
Key Points
- Trusted Access for Cyber program expands defender access
- $10M in API credits awarded to vetted security teams
- GPT-5.4-Cyber provided to CAISI and UK AISI for evaluations
Summary
OpenAI announced "Trusted Access for Cyber," a program to broaden advanced defensive AI capabilities to qualified defenders while scaling access with trust, verification, and safeguards. The initiative includes $10M in API credits to vetted teams (open-source security projects, vulnerability researchers, and enterprise defenders), early partners across finance, security vendors, and infrastructure providers, and selective access to GPT-5.4-Cyber for independent evaluations by CAISI and the UK AISI.
Key Points
- Program goal: make frontier-model defensive capabilities available broadly but gated by trust, validation, and safeguards.
- Funding: $10M in API credits via a Cybersecurity Grant Program; initial recipients include Socket, Semgrep, Calif, and Trail of Bits.
- Enterprise and research partners: Bank of America, BlackRock, BNY, Citi, Cisco, Cloudflare, CrowdStrike, Goldman Sachs, JPMorgan Chase, Morgan Stanley, NVIDIA, Oracle, SpecterOps, Zscaler, and others.
- Evaluation & oversight: GPT-5.4-Cyber access provided to CAISI and UK AISI for cyber-capability and safeguard assessments.
- Eligibility & expectations: Open to teams with proven track records in identifying and remediating vulnerabilities in open source and critical infrastructure; participants are expected to share defensive research and improve ecosystem resilience.
- Safety model: access and privileges will scale with demonstrated trust, verification, and accountability; safeguards will evolve as capability grows.
Practical actions for engineers
- If you run or work on security tooling or vuln research, consider applying to the grant program (focus on demonstrated remediation and OSS impact).
- Integrate advanced models cautiously: require verification, audit trails, and secure handling of sensitive data when using AI-assisted defenses.
- Share reproducible findings and remediation guidance with maintainers and the wider community to amplify protective impact.
Outcome
This program aims to accelerate defensive research, expand real-world validation of model-based tools, and harden the broader software and infrastructure ecosystem by empowering a diverse set of vetted defenders.