The launch of OpenAI's GPT-5.5-Cyber has made a significant move in a particularly sensitive area: the cybersecurity of critical infrastructure. This is not just another chatbot or a simple update, but rather a variant of its advanced model trained to work with vulnerabilities, malware analysis, and complex attack simulations, in a context where both European governments and companies are trying to stay informed about the true capabilities of these tools.
The deployment of this model has also come at a time of heightened competitive tension , just after the launch of Anthropic's Mythos, and amidst Brussels' negotiations to gain access to the most powerful systems. The result is a cocktail that blends cutting-edge innovation, rhetoric about "dual-use" (defense and attack), and the European Union's concern about regulating something that, without direct access, it can barely measure.
What is GPT-5.5-Cyber and how does it differ from other models?
GPT-5.5-Cyber is a specialized variant of GPT-5.5 designed for advanced cybersecurity tasks. OpenAI presents it as a tool focused on controlled vulnerability exploitation, penetration testing, malware reverse engineering, and incident analysis, with a design geared towards environments where a failure is not just a technical error, but a risk to essential services.
The company itself emphasizes that this is not a "generalist" model for writing texts or summarizing meetings, but rather a system tailored to high-risk workflows in electrical, financial, healthcare, and other critical infrastructure networks. The idea is that accuracy and consistency in these scenarios take precedence over the typical versatility of everyday assistants.
According to information shared by OpenAI, the preliminary version of GPT-5.5-Cyber does not aim for a spectacular leap in raw capacity compared to its predecessor, but rather a much more permissive configuration in security tasks when it comes to accredited defenders, while maintaining a series of safeguards to prevent clearly malicious uses.
In this context, the model is integrated as one more piece within the OpenAI and Microsoft security ecosystem : it is reserved for scenarios where it is necessary to work with exploits in laboratory environments, Capture-the-Flag (CTF) simulations and complex analyses that traditionally required days or weeks of manual auditing.
Technical performance: CTF tests and complex attack simulations
The UK's AI Security Institute (AISI) was one of the first organizations to systematically evaluate GPT-5.5-Cyber, comparing it to both previous versions of GPT and Anthropic's Mythos. The tests focused on 95 CTF-style cybersecurity tasks, organized by difficulty level.
In basic challenges, the OpenAI model handles tasks without major difficulties, but the difference emerges at higher levels. In the Expert tier, focused on autonomous research and exploitation of vulnerabilities against targets with modern mitigations, GPT-5.5 achieves an average success rate of 71,4% compared to 52,4% for GPT-5.4—a considerable gap for such specialized tasks.
In that same category, AISI highlights its ability to tackle problems such as reverse engineering binaries without source code, developing reliable exploits for stack overflows, or advanced cryptographic attacks, such as key recovery using padding oracle techniques. These are technical tests that, in the hands of a professional, can require many hours of focused work.
The comparison with Mythos is closer. On average, GPT-5.5-Cyber performs slightly better than Claude Mythos in Expert tasks (71,4% vs. 68,6%), although Anthropic achieves a better result in one of the flagship simulations: a 32-step attack on a corporate network, where Mythos completes three out of ten attempts and GPT-5.5-Cyber only manages two.
However, none of the evaluated models have managed to solve the simulated attack on an industrial control system known as "Cooling Tower," which requires seven steps and, according to the Institute itself, still outperforms current systems even when active defense is removed from the test environment.
Restricted access: the Trusted Access for Cyber program
Beyond the numbers, the key to GPT-5.5-Cyber lies in how it is accessed. OpenAI has opted for a highly restricted access scheme , under the umbrella of the Trusted Access for Cyber program launched in February 2026 and endowed with $10 million in API credits for critical cyber defense organizations.
This program doesn't function like a normal subscription, but rather as a pre-accreditation system . Interested entities must justify their role as defenders of critical infrastructure, detail the types of systems they protect (banking, energy, healthcare, government networks, etc.), and demonstrate proven experience in digital defense, often aligned with public initiatives or large corporate programs.
OpenAI refers to the profiles they want on board as "critical cyber defenders": electricity grid operators, systemically important financial institutions, large providers of essential services, and, in general, any actor whose downfall would have cascading effects on the economy or security. The company claims to have robust safeguards and monitoring mechanisms in place to detect suspicious activity generated through the model.
The program leverages the alliance with Microsoft and its Secure Future Initiative, making a significant portion of Azure's security partner ecosystem a natural candidate for access. This combination, in practice, reinforces a growing trend: cutting-edge AI for cybersecurity is moving away from being an open-source product and increasingly toward the category of regulated infrastructure.
Sam Altman, CEO of OpenAI, confirmed that the rollout of GPT-5.5-Cyber would take place in the "coming days" following the announcement, exclusively for verified critical defenders, with no date set for wider access. The company itself acknowledges that the preview is, in part, a period of fine-tuning and filtering, where the model is still far from being considered mature for mass deployment.
Europe is making moves: the European Commission wants early access
While OpenAI was refining its access program, alarm bells were ringing in Brussels. The European Commission has confirmed that it is in active talks with OpenAI to gain preliminary access to GPT-5.5-Cyber, with the aim of assessing its capabilities and risks firsthand before the model is rolled out to more organizations.
Thomas Regnier, the Commission's digital policy spokesperson, has publicly stated that European authorities "welcome" OpenAI's proactive approach, which has shown a willingness to provide controlled access to the model. According to Regnier, the plan is for a range of European stakeholders—including governments, businesses, cybersecurity authorities, and the European AI Office—to be able to use GPT-5.5-Cyber within a supervised framework.
The idea, in the spokesperson's own words, is to closely monitor the model's deployment and address security concerns as they arise, rather than legislating blindly. The Commission had already warned weeks earlier that its "regulate first" narrative would be undermined if it could not access the models it intended to monitor, especially when these address the exploitation of vulnerabilities and systemic risks.
This urgency is partly explained by the results of technical evaluations. AISI tests showed that GPT-5.5 and Mythos were capable of chaining together steps in complex simulations of corporate attacks and completing scenarios that previously required about 20 hours of human work . While not infallible, they sometimes perform well enough to shift the balance between defenders and attackers.
For the EU, early access becomes a strategic tool: without it, the regulator only has documentation and promises; with it, it can replicate tests, validate scenarios and compare the safeguards declared by companies, something essential in an environment where the sanctions foreseen by the AI Act can reach up to 7% of the global turnover of suppliers.
OpenAI vs Anthropic: two different strategies in the face of Brussels
The contrast between OpenAI and Anthropic has been one of the most contentious elements in the European debate. While the former offers regulated access to GPT-5.5-Cyber, the latter has opted to keep Mythos within a much more closed circle, with only a few dozen organizations having early access.
The European Commission admits it has also held meetings with Anthropic, but Regnier has been clear: for now, there is no access agreement comparable to the one being developed with OpenAI, and the talks are at a different stage. In practical terms, Brussels has much less visibility into how Mythos performs in real-world trials.
This imbalance comes at a particularly delicate time. Mythos was presented as a powerful tool for locating unknown vulnerabilities and linking them across multiple types of software, which raised concerns about a potential shift in the balance between defense and attack. Without access, the EU is forced to rely primarily on information provided by the company itself.
The controversy has intensified because Sam Altman harshly criticized Anthropic's strategy, accusing it of playing on fearmongering with a model he graphically compared to "making a bomb and selling you the bunker." However, the extremely limited access release of GPT-5.5-Cyber has brought OpenAI's position much closer to that of its competitor, something that has not gone unnoticed.
For Europe, the main difference lies not so much in the rhetoric as in the willingness to share the model with the regulator. With OpenAI, there is a concrete offer of supervised access to GPT-5.5-Cyber; with Anthropic, for the moment, there are only "good exchanges" and the intention to continue discussing Mythos. This asymmetry complicates the EU's ability to develop rules that truly take into account the behavior of the most advanced models.
Impact on Spain and the European cybersecurity ecosystem
This movement isn't confined to the upper echelons of Brussels. For cybersecurity companies and startups in Spain and the rest of Europe, GPT-5.5-Cyber represents a game-changer . AI defense is no longer just about acquiring another API; it's about fitting into a selective access regime where the type of infrastructure being protected and institutional partnerships are key factors.
Companies that manage banking, energy, transport or healthcare in European territory — and that are already subject to frameworks such as NIS2 or the AI Regulation itself — are facing a scenario in which the most advanced audit and defense tools may only be available to those who fit into the category of "critical defenders" defined by OpenAI.
For Spanish startups in the sector, this means rethinking their technology strategy. Relying on a single front-end AI provider, without an alternative plan, becomes a clear business risk , especially when access is conditional on criteria that go beyond technical capabilities: contracts with government agencies, participation in national security initiatives , roles within critical supply chains, etc.
For investment funds and industry partners, the ability to operate with a diversified AI stack—including tools from Google and Microsoft, or proprietary models for less sensitive tasks—is becoming as important an argument as product quality. The narrative of "democratizing" AI for cybersecurity thus clashes with a more segmented reality, in which not everyone will be able to use GPT-5.5-Cyber, even if they can afford it.
Meanwhile, technological dependence is once again a major issue. Voices from the European ecosystem, such as those from executives of AI companies based in France or operators like Telefónica , have long warned that the continent risks becoming a captive customer of models developed in the United States if it does not accelerate the development of its own alternatives, including in the field of advanced cybersecurity.
What GPT-5.5-Cyber can (and cannot) do in the hands of defenders
Within the limits that OpenAI itself has set, GPT-5.5-Cyber is designed to automate much of the most tedious work of security teams, always in controlled environments . Among the specific capabilities that have been tested are the detection and prioritization of vulnerabilities in enterprise infrastructures, the analysis of exploits in CTF-type scenarios, and the verification of patches in critical software.
The model can help build and run scripts to explore known attack surfaces, document detected vulnerabilities, and link incidents that, viewed in isolation, might go unnoticed. All of this, in theory, while always allowing for mandatory human review at the most critical stages of the process.
Another important aspect is understanding user intent . GPT-5.5-Cyber has been trained to distinguish legitimate defensive security queries from suspicious requests aimed at the actual exploitation of protected systems. This dividing line is not simple, but it is a central part of the safeguards that OpenAI claims to have incorporated into the model.
At the same time, the company acknowledges self-imposed limitations: the model is not intended to autonomously develop zero-day exploits against production systems or to support real offensive campaigns, although there are red teaming teams that, in laboratory environments, can use it to simulate attacks as part of their defensive work.
In practice, this positions GPT-5.5-Cyber as a defensive productivity tool : it accelerates analysis, helps find bugs and validate patches, but remains surrounded by technical and contractual controls designed to make it difficult for malicious actors to directly exploit it.
The arrival of GPT-5.5-Cyber presents a complex landscape: on the one hand, a model that sets new standards in cybersecurity testing and promises to save critical infrastructure defenders countless hours of work; on the other, limited access through Trusted Access for Cyber, intense negotiations with the European Commission, and direct competition with Anthropic's Mythos, played out on both technical and political fronts. For Spain and the rest of Europe, the message is clear: AI applied to security is no longer a general-purpose tool but a strategic resource, subject to access, regulation, and technological dependence criteria that will carry as much weight as its own benchmarks.