The short answer: OpenAI’s stated reason is cyber AI’s dual-use problem. A powerful cybersecurity model can help defenders identify and patch vulnerabilities faster, but similar capabilities can also help malicious actors probe, exploit, or automate attacks. OpenAI’s public position is that stronger cyber capabilities should first go to verified defenders under a “trusted access” model, rather than being opened to everyone immediately .
The controversy began with Anthropic’s Mythos. Reports said Anthropic restricted access to the cybersecurity model to selected users, and that Altman criticized that approach .
Then OpenAI adopted a selective rollout for its own cyber model. Business Today and Techloy reported that, on April 30, 2026, Altman posted on X that OpenAI would start rolling out GPT-5.5-Cyber “to critical cyber defenders” in the next few days . TechCrunch also reported that OpenAI was using an application process in which applicants provide credentials and explain their planned use before gaining access .
That sequence is why the story landed so sharply. The issue is not only that OpenAI limited access. It is that OpenAI did so after criticizing Anthropic for a similar-looking restriction. The Register framed the tension the same way, noting that OpenAI was preparing a limited release to a handpicked group of cyber defenders after taking a swipe at Anthropic for doing much the same thing .
OpenAI’s explanation centers on “trusted access.” According to reports on Altman’s post, OpenAI said it would work with the wider ecosystem and government to figure out trusted access for cyber capabilities, while aiming to help secure companies and infrastructure quickly .
That fits with OpenAI’s existing Trusted Access for Cyber, or TAC, program. OpenAI describes TAC as a way to unlock the defensive potential of advanced cyber models while reducing misuse risk . The company has also said it is scaling TAC to thousands of verified individual defenders and hundreds of teams responsible for defending critical software .
In that context, GPT-5.5-Cyber’s restricted release is not a standalone surprise. It follows a broader OpenAI argument: as cyber-capable models become more powerful, they should be deployed in stages to vetted defenders before any wider access is considered .
Cybersecurity models are hard to release like ordinary productivity software because many of their most useful features cut both ways. TechCrunch reported that GPT-5.5-Cyber can perform tasks such as penetration testing, vulnerability identification, and vulnerability exploitation . Datagrom reported that the tool can also perform malware reverse engineering .
For a security team, those capabilities can be valuable. They can help find weaknesses, test defenses, and speed up remediation. But in the wrong hands, similar capabilities can also support offensive activity. OpenAI has made the same broader point: cybersecurity is an area where AI progress can strengthen the ecosystem while also introducing new risks, and advanced models can accelerate vulnerability discovery and remediation .
That is the strongest policy case for a limited rollout. The more a model can assist with penetration testing, exploit analysis, or malware-related work, the stronger the incentive to make sure early users are legitimate defenders rather than unknown actors .
This is the part public evidence cannot fully answer. We do not have enough information to say what Altman’s internal reasoning was, or whether OpenAI’s policy changed after new risk assessments, business considerations, government discussions, or other factors.
One charitable reading is that Altman’s criticism was aimed less at access control itself and more at how Anthropic positioned or marketed the Mythos restriction. India Today’s report that he called the move “fear-based marketing” points in that direction . Under that interpretation, OpenAI might argue that selective access is acceptable when it is framed as a practical safety mechanism rather than as dramatic marketing.
But even if that reading is fair, the optics remain difficult. OpenAI still ended up using a similar broad structure: a powerful cyber model is not immediately available to the general public, and access is filtered through a process for qualified users . That is why the criticism of OpenAI is mainly about consistency, not necessarily about whether limiting access is irrational.
Not necessarily. Public reports do not establish that the two companies use identical review criteria, technical safeguards, monitoring rules, or permitted-use boundaries. Those details matter, and they are not fully visible from the outside.
What does look similar is the overall access model: both companies held back broad public access to advanced cybersecurity AI and instead prioritized selected or verified users . OpenAI’s main distinction is that it ties the approach to TAC, a named program for verified individual defenders and teams protecting critical software .
So the safest conclusion is not that the policies are identical. It is that OpenAI has converged on the same broad idea it had criticized from the outside: powerful cyber AI should first be placed in the hands of trusted defenders, not released to everyone at once .
OpenAI’s most direct public reason for restricting GPT-5.5-Cyber is the dual-use risk of cybersecurity AI. The company says advanced cyber capabilities can speed up defensive work, including vulnerability discovery and remediation, but can also be misused; TAC is meant to reduce that risk by giving access first to verified defenders .
What cannot be proven from public reporting is exactly why Altman criticized Anthropic’s limited Mythos release and then accepted a similar-looking rollout for OpenAI’s own model. The verified facts are narrower: Altman reportedly criticized Anthropic’s approach, OpenAI later announced a restricted GPT-5.5-Cyber rollout to “critical cyber defenders,” and OpenAI justified the move through trusted access and defender-first deployment .
That makes the episode more complicated than a simple charge of hypocrisy. As a safety policy, restricted access to a powerful cyber model is easy to understand. As communication, however, OpenAI left itself open to the criticism that it mocked a playbook it soon needed to use.