OpenAI commits $10M in API credits to Trusted Access for Cyber program
OpenAI commits $10M in API credits to four open-source security firms and signs up 17 enterprise partners including Bank of America, JPMorgan, and CrowdStrike for its Trusted Access for Cyber program.
Updated
Why it matters
- OpenAI committed $10 million in API credits through its Cybersecurity Grant Program.
- Initial recipients are Socket, Semgrep, Calif, and Trail of Bits.
- Seventeen enterprise partners signed on, including Bank of America, BlackRock, BNY, Citi, JPMorgan Chase, Goldman Sachs, Morgan Stanley, Cisco, Cloudflare, CrowdStrike, NVIDIA, Oracle, Palo Alto Networks, and Zscaler.
- OpenAI gave the U.S. Center for AI Standards and Innovation (CAISI) and the UK AI Security Institute (UK AISI) access to a model called GPT-5.4-Cyber for evaluation.
- BNY confirmed participation in a public statement released through the program.
OpenAI has committed $10 million in API credits to four open-source security organizations through a new program called Trusted Access for Cyber, the company announced this week. The grants target software supply chain and vulnerability research work, and they ship with a longer list of seventeen enterprise partners ready to test and integrate the tools inside production security stacks.
What does the program actually do?
Trusted Access for Cyber rests on a single premise stated by OpenAI: advanced cyber capabilities should reach defenders broadly, but access should scale with trust, validation, and safeguards. The company framed the launch around the breadth of defenders involved. "Cybersecurity is a team sport," OpenAI wrote, "and the systems people rely on are protected by organizations of many kinds, from major enterprises and security vendors to researchers, maintainers, public institutions, nonprofits, and smaller teams with limited security resources."
The $10 million in API credits covers work across that range. Initial recipients include:
- Socket and Semgrep, focused on software supply chain security
- Calif and Trail of Bits, pairing frontier models with vulnerability research experts
OpenAI said additional teams with proven track records in identifying and remediating vulnerabilities in open source software and critical infrastructure systems can apply through the program page.
Why does this matter now?
OpenAI's bet is that defensive security has fallen behind offensive uses of generative models. Smaller security teams and open-source maintainers often lack 24/7 incident response. The grant structure places frontier model access directly in their hands without forcing them to absorb API costs, and it embeds those defenders inside a feedback loop that reports back to the lab.
The move also places OpenAI inside a competitive scramble among frontier labs for credibility on cyber safety. Anthropic, Google DeepMind, and Microsoft have all published cyber evaluations or launched defensive-leaning programs in the past eighteen months. Direct, named partnerships with banks, cloud providers, and security vendors give OpenAI a measurable footprint in that race.
The stakes extend beyond market share. Frontier models can both find and exploit software flaws. Distributing those capabilities to defenders without enabling attackers has become a regulatory and diplomatic question in the United States, the United Kingdom, and the European Union. Programs like Trusted Access for Cyber are now part of how labs demonstrate they can self-govern before regulators reach for the levers.
Who else is signing up?
Seventeen enterprises and security vendors have agreed to participate. The full list:
- Bank of America
- BlackRock
- BNY
- Citi
- Cisco
- Cloudflare
- CrowdStrike
- Goldman Sachs
- iVerify
- JPMorgan Chase
- Morgan Stanley
- NVIDIA
- Oracle
- Palo Alto Networks
- SpecterOps
- US Bank
- Zscaler
The roster combines three of the largest US custodian banks, two endpoint security vendors, three cloud and networking infrastructure providers, two chip and infrastructure providers in NVIDIA and Oracle, and several specialist security firms. OpenAI described the group as "world-renowned for enterprise security leadership in their respective industries."
What are governments getting?
OpenAI has separately given the U.S. Center for AI Standards and Innovation (CAISI) and the UK AI Security Institute (UK AISI) access to a model the company calls GPT-5.4-Cyber. Both institutes will run evaluations focused on the model's cyber capabilities and its safeguards.
The placement matters. CAISI sits inside the US Commerce Department and runs the evaluations used by the US AI Safety Institute framework. UK AISI runs pre-deployment testing for several frontier labs. Independent access to a cyber-focused model variant gives both bodies a concrete artifact to grade, rather than a general-purpose model that might or might not perform on offensive-security benchmarks.
What does the industry say?
Financial sector participation is one of the louder signals in the announcement. BNY, one of the largest custodian banks in the world, released a statement through the program:
"BNY is committed to helping protect the security and resilience of the financial system as AI capabilities accelerate. We are working closely with those at the forefront of enabling these efforts. Building on our ongoing collaboration with OpenAI, we are pleased to participate in their Trusted Access for Cyber program."
The quote carries weight because banks have historically been among the most cautious adopters of frontier model APIs. Direct participation from Bank of America, Citi, Goldman Sachs, JPMorgan Chase, Morgan Stanley, and US Bank in a single cyber program is unusual. It signals that the financial sector has moved from internal-only experimentation toward shared, vendor-coordinated defensive deployments.
What happens next?
OpenAI said it will expand Trusted Access for Cyber as the program generates feedback. Safeguards will rise with capability. New partners will be added. The company framed the program as iterative: legitimate defenders should move faster, share what they find, and turn new insights into broader protection.
For the open-source security recipients, the immediate task is operational. Socket, Semgrep, Calif, and Trail of Bits will integrate API credits into existing product and research workflows, then surface results back to OpenAI. For the enterprise partners, the work centers on validation and integration testing inside production security stacks. For CAISI and UK AISI, the work is structured evaluation, with public reports likely within the next several quarters.
The program's success will be measured on three fronts. The first is whether the named recipients ship measurable vulnerability findings that would not have surfaced without model assistance. The second is whether the enterprise partners move from pilots to production deployments. The third is whether the government evaluations produce findings rigorous enough to shape frontier model policy in Washington and London.
OpenAI's $10 million commitment is the entry price for that test. The harder questions — how much trust the access creates, how broadly GPT-5.4-Cyber can be used without enabling offensive operations, and whether the program survives contact with real-world incident response — now sit with the participants themselves.
Source: OpenAI News
More from Rebecca Stone
Show full bio
Correspondent covering consumer brands and retail at AI In Context.
214 articles
Related articles
- OpenAI ships GPT-5.5-Cyber, tiers access for defenders
- OpenAI Commits $1 Billion to Protect Essential Services With AI
- OpenAI Rolls Out GPT-5.4-Cyber to Vetted Defenders
- OpenAI Publishes Policy for Disclosing Bugs It Finds in Others' Software
- OpenAI ships GPT-5.6-Cyber and found a Chrome V8 zero-day with it