Safety & Security

OpenAI gates GPT-5.3-Codex cyber tools behind identity check

OpenAI launched Trusted Access for Cyber for GPT-5.3-Codex, requiring identity verification at chatgpt.com/cyber before letting developers run high-risk security work, alongside $10M in API credits for defenders.

Introducing Trusted Access for Cyber
Introducing Trusted Access for CyberAI-generated
By Elena Vasquez5 min read

Updated

Why it matters

  • OpenAI launched Trusted Access for Cyber, a pilot requiring identity verification for GPT-5.3-Codex cybersecurity work.
  • The company committed $10 million in API credits through its Cybersecurity Grant Program for defensive security teams.
  • Access paths include chatgpt.com/cyber for individuals, enterprise requests via OpenAI reps, and a separate invite-only researcher track.
  • GPT-5.3-Codex is described by OpenAI as its most cyber-capable frontier reasoning model as of release.
  • Prohibited uses include data exfiltration, malware creation or deployment, and destructive or unauthorized testing.

OpenAI is putting its most cyber-capable model behind a new identity-verified gate, pairing GPT‑5.3‑Codex with a $10 million API credit pool reserved for defensive security work.

The pilot, called Trusted Access for Cyber, requires individual developers to verify their identity at chatgpt.com/cyber before using GPT‑5.3‑Codex for "potentially high-risk cybersecurity work." Enterprises can request trusted access for an entire team through their OpenAI representative. Security researchers who need even more capable or permissive models can apply to a separate, invite-only program.

GPT‑5.3‑Codex is, in OpenAI's words, "our most cyber-capable frontier reasoning model to date." The company frames the access program as a way to redirect frontier-model power toward defensive use before adversaries adopt the same tools.

The stakes are concrete. Software vulnerabilities have multiplied as codebases grow and as attackers automate reconnaissance. OpenAI argues that frontier reasoning models, applied in the right hands, can compress vulnerability discovery and patching from weeks into hours.

What is Trusted Access for Cyber?

The pilot is an identity and trust-based framework. OpenAI says it wants to "help ensure enhanced cyber capabilities are being placed in the right hands" rather than block them outright.

The framing matters. OpenAI acknowledges that requests like "find vulnerabilities in my code" sit on a knife's edge: they may support responsible patching and coordinated disclosure, or they may prep an exploit. Naive safety filters have historically blocked both.

"Restrictions intended to prevent harm have historically created friction for good-faith work," OpenAI wrote. Identity verification, in its telling, lets the company lower those guardrails for verified defenders without dropping them for everyone.

The company trained GPT‑5.3‑Codex to refuse clearly malicious prompts such as credential theft. On top of that safety training, "automated classifier-based monitors will detect potential signals of suspicious cyber activity." Trusted users may still encounter friction as OpenAI "calibrates our policies and classifiers."

Why an identity check now?

The access controls arrive as OpenAI itself acknowledges that "there will soon be many cyber-capable models with broad availability from different providers, including open-weight models." Frontier-level cyber tooling is moving toward commodity status.

OpenAI wants its own models to anchor the defensive side first. The pilot explicitly "prioritizes getting our most capable models and tools in the hands of defenders first." That sequencing matches how OpenAI has previously staggered access for other high-impact use cases, including earlier rounds of the Cybersecurity Grant Program and custom red-team agreements.

The timing also tracks industry-wide pressure. Regulators in the United States and the European Union have been pressing AI providers on dual-use cyber capabilities, and labs face growing legal exposure when powerful offensive tooling is released without guardrails.

Who qualifies, and how?

OpenAI describes three on-ramps:

  • Individuals can verify at chatgpt.com/cyber and gain access for cybersecurity work.
  • Enterprises can request trusted access for an entire team through an OpenAI account representative.
  • Researchers who need models "even more cyber capable or permissive" than the default can express interest in an invite-only program via a Google Form.

Access carries conditions. "Users with trusted access must still abide by our Usage Policies and Terms of Use," OpenAI wrote. Prohibited activity includes data exfiltration, malware creation or deployment, and destructive or unauthorized testing.

The verification tier also carries obligations for OpenAI itself. The company warns that "developers and security professionals doing cybersecurity-related work may be impacted by these mitigations," because the same classifiers guarding against misuse can flag legitimate red-team exercises. OpenAI says it will adjust "based on what we learn from early participants."

What about the money?

The $10 million sits in API credits, not cash. OpenAI distributes them through the Cybersecurity Grant Program, which has run in earlier rounds and is now expanding alongside the new access framework.

The application page targets two groups: "teams that have a proven track record of identifying and remediating vulnerabilities in open source software and critical infrastructure systems." OpenAI did not disclose per-team allocations, award sizes, or a distribution timeline.

The dollar figure is small relative to the addressable cost of cybercrime, which industry estimates routinely place in the hundreds of billions of dollars annually. It signals intent more than it changes the economics of vulnerability research: the credits matter as a way to absorb compute costs for defenders running frontier models at scale.

What changes for defenders, in practice?

Engineers who already use OpenAI models to triage CVEs, write fuzz harnesses, or analyze malware samples will see two shifts. First, GPT‑5.3‑Codex raises the ceiling: OpenAI markets it as its strongest cyber reasoning model so far. Second, identity verification unlocks capabilities that previously got throttled or refused by default safety filters.

For offensive researchers working on red-team engagements under contract, the invite-only track is the relevant path. OpenAI's framing suggests access will skew toward teams with disclosed, verifiable defensive missions rather than independent offensive work.

The pilot also clarifies what OpenAI will and will not police. The company is not committing to an audit regime for verified users. It is committing to classifier monitoring, usage policy enforcement, and "evolving" the program as the pilot produces data.

What's next?

OpenAI's bet is structural: regulated, identity-bound access beats blanket refusals. If the pilot holds, it likely becomes a template for other high-impact domains, from biomedical reasoning to autonomous code execution.

If it leaks — if verified accounts become a conduit for misuse, or if classifiers misfire on benign red-team work — OpenAI will face pressure to tighten access again or to widen refusal defaults. The first indicator will be how transparently the company publishes calibration updates, not how many researchers sign up.

For now, the message to security teams is direct: verify, apply, and use the most capable model OpenAI has shipped to date before its capabilities become a commodity available to anyone.

Original: chatgpt.com

Share this article:

More from Elena Vasquez

Elena Vasquez

Show full bio

Market editor covering media and advertising at AI In Context.

209 articles

Related articles

  1. OpenAI ships GPT-5.5-Cyber, tiers access for defenders
  2. OpenAI Rolls Out GPT-5.4-Cyber to Vetted Defenders
  3. OpenAI ships GPT-5.4 Thinking with first High-tier cyber mitigations
  4. OpenAI ships GPT-5.6-Cyber and found a Chrome V8 zero-day with it
  5. OpenAI commits $10M in API credits to Trusted Access for Cyber program

« Previous article