What GPT-5.4-Cyber is
GPT-5.4-Cyber is an OpenAI variant of GPT-5.4 designed for authorized cybersecurity work. OpenAI developed it for verified defenders participating in the Trusted Access for Cyber program. The model is intended for situations where a security professional needs detailed assistance with vulnerability research, security testing, malware analysis, or related defensive investigations.
Its cyber-specific positioning matters because defensive security work can involve dual-use information. The same technical concepts may help an organization understand and fix a weakness or help an unauthorized attacker exploit it. GPT-5.4-Cyber was designed to provide broader assistance for legitimate defensive workflows than a standard model would normally provide, while access remained subject to verification and program approval.
This is therefore not simply a general-purpose GPT-5.4 model with a cybersecurity name. It is a specialized variant with a particular access channel, safety posture, and intended audience. The available first-party information does not describe it as a broadly available model for ordinary applications.
Where it fits in OpenAI's lineup
GPT-5.4-Cyber belongs to the GPT-5.4 family, but it occupied a specialized cybersecurity position rather than serving as a general model for all workloads. OpenAI's current model information identifies GPT-5.6-Cyber as the newer advanced cybersecurity model, while GPT-5.4-Cyber is no longer listed among current models.
OpenAI announced the GPT-5.4-Cyber deprecation on September 11, 2026. The model remains accessible through restricted channels as of September 26, 2026, but its API shutdown is scheduled for October 1, 2026. GPT-5.6-Cyber is the provider's recommended replacement. That recommendation is especially important for any organization considering new integration work: a deployment started on GPT-5.4-Cyber would have only a short remaining service window.
Cybersecurity capabilities
OpenAI describes GPT-5.4-Cyber as fine-tuned for additional cyber capabilities and fewer restrictions on legitimate defensive use. The documented use cases include advanced defensive workflows and binary reverse engineering. Binary reverse engineering means examining compiled software rather than relying on its original source code. In practice, that can support analysis of suspicious programs, identification of weaknesses, and investigation of how a piece of software behaves.
The model is also positioned for vulnerability research, malware analysis, security testing, and defensive cybersecurity operations. These uses can include explaining technical findings, helping investigators reason about an observed behavior, or assisting a security team in understanding a potentially vulnerable component. The supplied research does not provide benchmark scores, named tool integrations, or detailed task-by-task performance measurements, so its capabilities should be understood from OpenAI's stated positioning rather than from independently verified test results.
Access, authorization, and safety boundaries
GPT-5.4-Cyber was offered to customers in the highest tiers of OpenAI's Trusted Access for Cyber program. Access required identity verification and program approval. This distinction is important: the model was not presented as an unrestricted public endpoint that any developer could select from a normal model list.
Access to a more permissive cybersecurity model does not remove the need for authorization controls. Organizations using it should limit access to approved personnel, define which systems and data may be analyzed, and retain review and monitoring procedures for generated content. OpenAI's cybersecurity documentation distinguishes its Trusted Access for Cyber program from the identity of any one model, so program membership should not be treated as proof that every cyber-related model has identical behavior or availability.
GPT-5.4-Cyber should not be selected for unauthorized intrusion, offensive activity without permission, or a public-facing product that cannot tolerate an imminent model migration. The model's intended purpose is defensive work performed with appropriate authorization.
Technical specifications that are and are not published
The available first-party material verifies the model's identity, cybersecurity specialization, restricted access, deprecation status, and shutdown date. It does not provide a complete standalone technical specification for the cyber variant.
| Specification | Verified information |
|---|---|
| Provider | OpenAI |
| Model family | GPT-5.4 |
| Primary purpose | Authorized defensive cybersecurity and security research |
| Documented specialty | Advanced defensive workflows and binary reverse engineering |
| Access | Restricted Trusted Access for Cyber channels |
| Status | Deprecated but accessible as of September 26, 2026 |
| API shutdown | October 1, 2026 |
| Recommended replacement | GPT-5.6-Cyber |
| Context length | Not publicly verified for this variant |
| Maximum output | Not publicly verified for this variant |
| Pricing | No standalone public pricing located |
The research does not independently verify a separate context window, maximum output-token limit, token prices, public fine-tuning availability, or a complete endpoint matrix. It also does not establish whether every tool, function-calling, streaming, caching, batch, or structured-output feature available elsewhere in OpenAI's platform applies to GPT-5.4-Cyber. Developers should not infer those details from the base GPT-5.4 family or from another OpenAI model.
Modalities, reasoning, and coding profile
The available data identifies GPT-5.4-Cyber as a text-output model. It does not verify image, audio, or video input for the cyber variant, and it does not establish non-text output such as generated images, audio, or video. The safest documented interpretation is that its known role is text-based cybersecurity assistance, not a confirmed multimodal media-generation system.
The model is designed for technically demanding reasoning about security problems, and its intended applications include analyzing vulnerabilities, malware, and compiled binaries. However, OpenAI has not supplied a cyber-specific reasoning benchmark in the provided sources. Internal catalog data gives the model a reasoning assessment of 9 and a coding assessment of 9, but these are editorial or catalog evaluations rather than provider-published benchmark results. They should be treated as directional judgments, not guaranteed performance levels.
No verified speed or cost rating is available. Because the model is restricted and nearing shutdown, practical suitability depends less on an assumed capability score than on access eligibility, migration time, and the importance of the specific security workflow.
When to choose GPT-5.4-Cyber
GPT-5.4-Cyber may be appropriate when all of the following conditions apply:
- The work is authorized and defensive, such as vulnerability research, malware analysis, security testing, or binary reverse engineering.
- Your organization has approved access through the Trusted Access for Cyber program.
- You need the specialized cyber-permissive behavior described by OpenAI rather than a general-purpose model's standard restrictions.
- You can complete a migration or transition before the October 1, 2026 API shutdown.
For example, a verified security team investigating a suspicious compiled executable or studying a weakness in an authorized test environment could have a reason to use this model during its remaining availability. The model's specialty may be more relevant in that setting than a cheaper or faster general-purpose text model that is not intended for the same class of defensive analysis.
When another option is more appropriate
GPT-5.4-Cyber is a poor choice for a new long-lived integration because its shutdown date is already announced. Even if it meets a current research need, building a dependency on it without a migration plan creates avoidable operational risk. GPT-5.6-Cyber is the named replacement and should be evaluated first for organizations that need a continuing OpenAI cybersecurity model.
A standard model may be more suitable for ordinary coding, documentation, customer support, or general application features that do not require cyber-specific permissiveness. A conventional model can also be preferable when the organization needs clearly documented pricing, stable public availability, or a complete set of API specifications that the supplied research does not establish for GPT-5.4-Cyber.
Conversely, the newer replacement may not be an automatic drop-in substitute. Before switching, test prompts and outputs, review authorization controls, confirm tool permissions, and check monitoring requirements. OpenAI's recommendation identifies the migration direction, but the research does not guarantee identical behavior, limits, pricing, or endpoint support between the two cyber variants.
Migration considerations before shutdown
Teams still using GPT-5.4-Cyber should inventory every application, prompt, tool permission, and security workflow that depends on the model. Test the replacement with representative but authorized tasks, including the types of vulnerability explanations, malware-analysis questions, and binary-research prompts that matter to the organization.
Also review output handling. Cybersecurity outputs can contain sensitive technical details, so logging, access control, retention, and human review should remain part of the deployment design. Finally, establish a firm cutoff before October 1, 2026 rather than treating the shutdown date as the migration date itself. The model's remaining availability is useful for transition work, but it is not evidence of long-term support.
Bottom line
GPT-5.4-Cyber is a narrowly targeted OpenAI model for approved defensive cybersecurity users, with documented strengths in advanced cyber workflows and binary reverse engineering. Its principal limitation is now operational rather than purely technical: it is deprecated and scheduled for API removal on October 1, 2026. Use it only where restricted access is available and where a near-term migration plan is acceptable; for new work intended to continue beyond that date, evaluate GPT-5.6-Cyber or another currently supported option instead.

