Category
Security Research
Topic
AI Access for Security Research
Audience
Penetration testers & security researchers
Reading time
approx. 6 minutes

Some providers of frontier AI models are now beginning to grant selected researchers and organisations access to models that go far beyond what is available publicly. In doing so, they are transforming the landscape of security research. This article provides an overview of the current situation and what this means for the industry.

The current landscape

Most members of the community are likely to be familiar with Claude Mythos Preview and the associated Project Glasswing from Anthropic. The model has caused quite a stir in recent weeks: in internal tests, it has identified various Zero-Day vulnerabilities in common infrastructure, including all mainstream operating systems and browsers. Anthropic has deliberately chosen not to release the model publicly. Instead, it is running in a strictly controlled preview programme involving around 40 organisations, including AWS, Apple, Cisco, Google and Microsoft.

Ordinary penetration testing firms or independent security researchers currently have no access to Mythos.

However, Anthropic does offer to reduce the restrictions on its current models for security researchers if published research – in the form of CVEs (discovered security vulnerabilities), talks and blog articles – can provide evidence of such vulnerabilities. See claude.com/form/cyber-use-case.

OpenAI is taking a different approach. Since February 2026, the Trusted Access for Cyber (TAC) programme has provided a more accessible option. Individuals can verify their identity via chatgpt.com/cyber, whilst organisations can do so via an OpenAI sales contact. The highest access level unlocks GPT-5.4-Cyber, a model specifically fine-tuned for security tasks with reduced restrictions for legitimate research work, including capabilities such as binary reverse engineering. The programme is set to be expanded to include thousands of individuals and hundreds of teams.

Google offers Sec-Gemini v1, an experimental model designed specifically for Threat Intelligence, vulnerability analysis and Incident Response. Access is also restricted and currently available only to selected research institutions, NGOs and security researchers via an application form. The focus is clearly on the defensive side.

What this means for security researchers

Anyone wishing to use state-of-the-art AI models for their research currently has no structured access to them. OpenAI’s TAC is the only option with a reasonably public application process. Anthropic’s Glasswing is effectively closed. Google’s Sec-Gemini is defence-oriented and not designed for research or commercial Pentests.

What remains is the same basis as for everyone else: the publicly available models with their well-known limitations.

The other option: local AI

Anyone who does not wish to become dependent on external providers will find locally operated models to be a genuine alternative. We have already examined the possibilities, limitations and technical requirements for this in detail: Local AI in Pentesting and security research.

The uncomfortable questions behind it

Regardless of whether or not one gains access to these programmes, there are fundamental questions that the industry should be addressing.

Dependence on the provider

Anyone who relies on cloud-based AI services for security-critical work is creating a dependency. Access conditions can change, programmes can be discontinued, and pricing models can shift overnight. What is possible today as a TAC member could be behind a new access barrier tomorrow. For a service on which clients and ongoing projects depend, this poses a genuine operational risk.

Data protection and data processing

Anyone who sends sensitive customer data – such as source code, network diagrams, configurations or logs – to an external AI service risks more than just a breach of contract. Even with well-drafted privacy policies, it is difficult to fully understand what actually happens to this data. Will the data be used for future training runs? Will it be logged? Who can access it? These questions are not merely academic in the context of commercial Pentesting and security research; they are of practical relevance.

What criteria are used to make these decisions?

Perhaps the most fundamental problem is the lack of transparency. The criteria used to decide who gains access to these models are not transparent. Anthropic’s Glasswing partner list reads like a ‘Who’s Who’ of tech giants. OpenAI’s TAC promises broader access, but what standards apply during verification? How is it decided whether a security researcher or a company qualifies as a ‘legitimate defender’?

This is not an abstract criticism. It is about who has the final say on what constitutes responsible security research and who, as a result, is allowed to use the most powerful tools.

“As long as access to the most powerful AI models depends on non-transparent criteria, the publicly available base remains the most honest starting point for independent security research.”
Mint Secure GmbH

How Mint Secure supports you

Regardless of which AI tools you use or deliberately avoid: we help you to carry out security-critical work in a responsible and transparent manner.

🎯

Penetration Testing

Manual and methodical security analyses, regardless of the availability of AI tools.

📋

Security Consulting

Consulting on tooling decisions, data protection and processes when using AI in security-critical work.

🛠️

Technical Security Services

Support with the secure evaluation and integration of new tools and AI models into your existing processes.

Any questions about the topic of AI in security research? We’d be happy to discuss this with you. Get in touch.

Conclusion

Structured access to the most powerful AI models remains out of reach for most security researchers.

Whether it’s Anthropic’s Glasswing, OpenAI’s TAC or Google’s Sec-Gemini: all three programmes are tightly curated, vary in their level of openness and are allocated according to criteria that lack transparency. Those who aren’t part of these programmes work with publicly available models or locally operated alternatives, with all the known limitations.

Mint Secure can provide consulting on the opportunities and risks involved in the use of AI in your security work. Talk to us.