Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

OpenAI flags ‘high’ cybersecurity risks from future advanced models

OpenAI has reported significant progress in the cybersecurity capabilities of its AI models, with its GPT-5.1-Codex-Max model scoring 76% in capture-the-flag challenges as of November 2025, up from 27% for GPT-5 in August.

The San Francisco-based AI developer is preparing for future models that could reach high levels of cybersecurity proficiency, including the potential to assist with advanced intrusion operations.

OpenAI is adding safeguards to ensure its models are used primarily for defensive purposes, and is working with global security experts to address risks.

The company outlined measures such as training its models to refuse unsafe requests, monitoring for malicious activity, and collaborating with red team organizations to test defenses.

OpenAI will soon launch a trusted access program to offer enhanced cybersecurity capabilities to vetted users, and has introduced Aardvark, a private beta tool that helps developers find and fix software vulnerabilities.

The company is also forming a Frontier Risk Council to advise on responsible development, and continues to work with industry partners on shared threat models.

🔗 Source: OpenAI

🧠 Food for thought

Implications, context, and why it matters.

CTF scores don’t prove AI can run real offensive operations

  • OpenAI lists a 76% CTF score 1, yet it gives no detail on the exact benchmarks, the methods, or how it stacks up against human teams or rival labs.
  • CTFs use gamified puzzles with fixed flags plus known bugs, which rarely match the mess of real-world offensive work that needs reconnaissance, adaptive choices, and operational security across many systems.
  • If OpenAI did not test GPT-5.1-Codex-Max on zero-day cases or only on standard CTF sets, the number may just mean benchmark tuning rather than near-term help with advanced intrusion work 1. OpenAI calls that a future risk 1.

Security vendors can get ready for OpenAI’s trusted access program

  • OpenAI will run a trusted access program and a private Aardvark beta 1. This could open near-term deals for security vendors and managed security service providers (third-party firms that monitor plus manage security for clients). It also targets Development, Security, and Operations (DevSecOps) platforms that want AI help for vulnerability detection.
  • Early entrants who study eligibility rules, API limits, or timing can move faster. They can set up co-selling deals with OpenAI partners and ship features that stand out before the field gets crowded.
  • Teams that build AI governance should check how OpenAI safeguards fit their rules 1. That includes refusal training and malicious activity monitoring. Map those controls to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and industry-specific regulations.

Recent OpenAI developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.