GPT-5.4

GPT-5.4-Cyber

by OpenAI · Deprecated; currently accessible through restricted Trusted Access for Cyber channels; scheduled for API shutdown on October 1, 2026.

GPT-5.4-Cyber is a restricted OpenAI variant of GPT-5.4 for authorized defensive cybersecurity, vulnerability research, malware analysis, and binary reverse engineering. It remains accessible as of September 26, 2026, but its API is scheduled for shutdown on October 1, 2026, making migration planning essential.

Text Reasoning Coding
GPT-5.4-Cyber is a specialized OpenAI model for verified cybersecurity defenders. Its main distinction is a more permissive approach to legitimate defensive security tasks, including work that standard safeguards may restrict, together with documented support for advanced workflows such as binary reverse engineering. The model is not a normal public API target: access is restricted, its technical specifications are incomplete, and OpenAI has announced that it will be removed from the API on October 1, 2026.
Outputs

What GPT-5.4-Cyber can produce

Text
Inputs

What it can understand

Text
Model profile

Performance characteristics

9/10 Reasoning
9/10 Coding
Specifications

Technical details

Model family GPT-5.4
Model type Coding
Release date 2026-04-14
Status Deprecated; currently accessible through restricted Trusted Access for Cyber channels; scheduled for API shutdown on October 1, 2026.
Deprecation date 2026-09-11
Shutdown date 2026-10-01
Knowledge cutoff notes

OpenAI has not published a direct knowledge-cutoff value for the GPT-5.4-Cyber variant in the first-party materials reviewed. The model is described as a fine-tuned variant of GPT-5.4, but the cyber-specific knowledge cutoff should not be inferred from the base model.

Model notes

GPT-5.4-Cyber is a specialized variant of GPT-5.4 trained to be more permissive for legitimate defensive cybersecurity work. OpenAI specifically documents advanced defensive workflows and binary reverse engineering capabilities. Access was provided through the Trusted Access for Cyber program to verified defenders and approved organizations rather than as an ordinary broadly available model. OpenAI announced on September 11, 2026 that the model is deprecated and will be removed from the API on October 1, 2026. GPT-5.6-Cyber is the recommended replacement. No standalone public pricing, context-window, maximum-output, or complete endpoint specification for the cyber variant was located.

Model guide

GPT-5.4-Cyber: Restricted Defensive Security Model Facing API Shutdown

GPT-5.4-Cyber is an OpenAI variant of GPT-5.4 fine-tuned for authorized defensive cybersecurity work, including advanced vulnerability research, malware analysis, security testing, and binary reverse engineering. It was available through the restricted Trusted Access for Cyber program rather than ordinary unrestricted model access. Although it remains accessible as of September 26, 2026, OpenAI has deprecated it and scheduled its API shutdown for October 1, 2026, with GPT-5.6-Cyber identified as the recommended replacement.

What GPT-5.4-Cyber is

GPT-5.4-Cyber is an OpenAI variant of GPT-5.4 designed for authorized cybersecurity work. OpenAI developed it for verified defenders participating in the Trusted Access for Cyber program. The model is intended for situations where a security professional needs detailed assistance with vulnerability research, security testing, malware analysis, or related defensive investigations.

Its cyber-specific positioning matters because defensive security work can involve dual-use information. The same technical concepts may help an organization understand and fix a weakness or help an unauthorized attacker exploit it. GPT-5.4-Cyber was designed to provide broader assistance for legitimate defensive workflows than a standard model would normally provide, while access remained subject to verification and program approval.

This is therefore not simply a general-purpose GPT-5.4 model with a cybersecurity name. It is a specialized variant with a particular access channel, safety posture, and intended audience. The available first-party information does not describe it as a broadly available model for ordinary applications.

Where it fits in OpenAI's lineup

GPT-5.4-Cyber belongs to the GPT-5.4 family, but it occupied a specialized cybersecurity position rather than serving as a general model for all workloads. OpenAI's current model information identifies GPT-5.6-Cyber as the newer advanced cybersecurity model, while GPT-5.4-Cyber is no longer listed among current models.

OpenAI announced the GPT-5.4-Cyber deprecation on September 11, 2026. The model remains accessible through restricted channels as of September 26, 2026, but its API shutdown is scheduled for October 1, 2026. GPT-5.6-Cyber is the provider's recommended replacement. That recommendation is especially important for any organization considering new integration work: a deployment started on GPT-5.4-Cyber would have only a short remaining service window.

Cybersecurity capabilities

OpenAI describes GPT-5.4-Cyber as fine-tuned for additional cyber capabilities and fewer restrictions on legitimate defensive use. The documented use cases include advanced defensive workflows and binary reverse engineering. Binary reverse engineering means examining compiled software rather than relying on its original source code. In practice, that can support analysis of suspicious programs, identification of weaknesses, and investigation of how a piece of software behaves.

The model is also positioned for vulnerability research, malware analysis, security testing, and defensive cybersecurity operations. These uses can include explaining technical findings, helping investigators reason about an observed behavior, or assisting a security team in understanding a potentially vulnerable component. The supplied research does not provide benchmark scores, named tool integrations, or detailed task-by-task performance measurements, so its capabilities should be understood from OpenAI's stated positioning rather than from independently verified test results.

Access, authorization, and safety boundaries

GPT-5.4-Cyber was offered to customers in the highest tiers of OpenAI's Trusted Access for Cyber program. Access required identity verification and program approval. This distinction is important: the model was not presented as an unrestricted public endpoint that any developer could select from a normal model list.

Access to a more permissive cybersecurity model does not remove the need for authorization controls. Organizations using it should limit access to approved personnel, define which systems and data may be analyzed, and retain review and monitoring procedures for generated content. OpenAI's cybersecurity documentation distinguishes its Trusted Access for Cyber program from the identity of any one model, so program membership should not be treated as proof that every cyber-related model has identical behavior or availability.

GPT-5.4-Cyber should not be selected for unauthorized intrusion, offensive activity without permission, or a public-facing product that cannot tolerate an imminent model migration. The model's intended purpose is defensive work performed with appropriate authorization.

Technical specifications that are and are not published

The available first-party material verifies the model's identity, cybersecurity specialization, restricted access, deprecation status, and shutdown date. It does not provide a complete standalone technical specification for the cyber variant.

SpecificationVerified information
ProviderOpenAI
Model familyGPT-5.4
Primary purposeAuthorized defensive cybersecurity and security research
Documented specialtyAdvanced defensive workflows and binary reverse engineering
AccessRestricted Trusted Access for Cyber channels
StatusDeprecated but accessible as of September 26, 2026
API shutdownOctober 1, 2026
Recommended replacementGPT-5.6-Cyber
Context lengthNot publicly verified for this variant
Maximum outputNot publicly verified for this variant
PricingNo standalone public pricing located

The research does not independently verify a separate context window, maximum output-token limit, token prices, public fine-tuning availability, or a complete endpoint matrix. It also does not establish whether every tool, function-calling, streaming, caching, batch, or structured-output feature available elsewhere in OpenAI's platform applies to GPT-5.4-Cyber. Developers should not infer those details from the base GPT-5.4 family or from another OpenAI model.

Modalities, reasoning, and coding profile

The available data identifies GPT-5.4-Cyber as a text-output model. It does not verify image, audio, or video input for the cyber variant, and it does not establish non-text output such as generated images, audio, or video. The safest documented interpretation is that its known role is text-based cybersecurity assistance, not a confirmed multimodal media-generation system.

The model is designed for technically demanding reasoning about security problems, and its intended applications include analyzing vulnerabilities, malware, and compiled binaries. However, OpenAI has not supplied a cyber-specific reasoning benchmark in the provided sources. Internal catalog data gives the model a reasoning assessment of 9 and a coding assessment of 9, but these are editorial or catalog evaluations rather than provider-published benchmark results. They should be treated as directional judgments, not guaranteed performance levels.

No verified speed or cost rating is available. Because the model is restricted and nearing shutdown, practical suitability depends less on an assumed capability score than on access eligibility, migration time, and the importance of the specific security workflow.

When to choose GPT-5.4-Cyber

GPT-5.4-Cyber may be appropriate when all of the following conditions apply:

  • The work is authorized and defensive, such as vulnerability research, malware analysis, security testing, or binary reverse engineering.
  • Your organization has approved access through the Trusted Access for Cyber program.
  • You need the specialized cyber-permissive behavior described by OpenAI rather than a general-purpose model's standard restrictions.
  • You can complete a migration or transition before the October 1, 2026 API shutdown.

For example, a verified security team investigating a suspicious compiled executable or studying a weakness in an authorized test environment could have a reason to use this model during its remaining availability. The model's specialty may be more relevant in that setting than a cheaper or faster general-purpose text model that is not intended for the same class of defensive analysis.

When another option is more appropriate

GPT-5.4-Cyber is a poor choice for a new long-lived integration because its shutdown date is already announced. Even if it meets a current research need, building a dependency on it without a migration plan creates avoidable operational risk. GPT-5.6-Cyber is the named replacement and should be evaluated first for organizations that need a continuing OpenAI cybersecurity model.

A standard model may be more suitable for ordinary coding, documentation, customer support, or general application features that do not require cyber-specific permissiveness. A conventional model can also be preferable when the organization needs clearly documented pricing, stable public availability, or a complete set of API specifications that the supplied research does not establish for GPT-5.4-Cyber.

Conversely, the newer replacement may not be an automatic drop-in substitute. Before switching, test prompts and outputs, review authorization controls, confirm tool permissions, and check monitoring requirements. OpenAI's recommendation identifies the migration direction, but the research does not guarantee identical behavior, limits, pricing, or endpoint support between the two cyber variants.

Migration considerations before shutdown

Teams still using GPT-5.4-Cyber should inventory every application, prompt, tool permission, and security workflow that depends on the model. Test the replacement with representative but authorized tasks, including the types of vulnerability explanations, malware-analysis questions, and binary-research prompts that matter to the organization.

Also review output handling. Cybersecurity outputs can contain sensitive technical details, so logging, access control, retention, and human review should remain part of the deployment design. Finally, establish a firm cutoff before October 1, 2026 rather than treating the shutdown date as the migration date itself. The model's remaining availability is useful for transition work, but it is not evidence of long-term support.

Bottom line

GPT-5.4-Cyber is a narrowly targeted OpenAI model for approved defensive cybersecurity users, with documented strengths in advanced cyber workflows and binary reverse engineering. Its principal limitation is now operational rather than purely technical: it is deprecated and scheduled for API removal on October 1, 2026. Use it only where restricted access is available and where a near-term migration plan is acceptable; for new work intended to continue beyond that date, evaluate GPT-5.6-Cyber or another currently supported option instead.


Answers to Frequently Asked Questions

What is GPT-5.4-Cyber?
GPT-5.4-Cyber is an OpenAI model variant designed for authorized defensive cybersecurity work, including vulnerability research, malware analysis, security testing, and binary reverse engineering.
Who can access GPT-5.4-Cyber?
Access is restricted to customers in the highest tiers of OpenAI's Trusted Access for Cyber program and requires identity verification and program approval. It is not a generally available public API model.
When will the GPT-5.4-Cyber API shut down?
OpenAI has scheduled the GPT-5.4-Cyber API shutdown for October 1, 2026. The model is deprecated but remains accessible through restricted channels as of September 26, 2026.
Should organizations use GPT-5.4-Cyber for new integrations?
Generally, no. Because the API is scheduled for shutdown on October 1, 2026, GPT-5.4-Cyber is unsuitable for new long-term integrations unless the organization has an immediate authorized need and a firm migration plan.
What is the recommended replacement for GPT-5.4-Cyber?
OpenAI recommends GPT-5.6-Cyber as the replacement. Organizations should test prompts, outputs, tool permissions, monitoring, and other operational requirements because the newer model may not be a fully identical drop-in substitute.


Sources 4
Provider

About OpenAI