🛡️ A retired four-star general who used to run the National Security Agency walked into a Tokyo press briefing on May 21 with a proposal: let OpenAI's new cyber-defense model help protect Japan's power grids, hospitals, and government networks. Paul Nakasone wasn't there to sell ChatGPT. He was there to pitch "GPT-5.5 Cyber," a model so capable at finding software vulnerabilities that OpenAI keeps it behind a vetting process — and to make sure Japan, not someone else, became the first international government to receive it.
A general walks into a Tokyo briefing
The setting was a hotel conference room in central Tokyo. The cast included Paul Nakasone, the retired US Army general who led the NSA and US Cyber Command for nearly six years before joining OpenAI's board in June 2024, and Sasha Baker, OpenAI's Head of National Security Policy and a former Acting Under Secretary of Defense for Policy.
Their message, delivered to Japanese reporters at a briefing covered by Mainichi Shimbun and Nikkei: OpenAI is now ready to deliver its most capable cybersecurity AI to the Japanese government and Japanese companies. They had already spent the week in conversations with Japanese officials about critical-infrastructure defense — the systems behind electricity, finance, telecommunications, and government operations.
Baker put the ask plainly. The company wants Japan's government and businesses to access GPT-5.5 Cyber and the broader GPT-5.5 family. "We hope the Japanese government will be our first partner," she told the reporters present, according to Mainichi's account of her remarks.
That phrasing matters. "First partner" implies a roadmap — Japan as the prototype for what an allied government's deployment of frontier cyber-AI looks like, and a template OpenAI can take elsewhere.
What "GPT-5.5 Cyber" actually is
GPT-5.5 Cyber is a controlled-access variant of OpenAI's GPT-5.5 model, rolled out in early May 2026 as part of a program called Trusted Access for Cyber. The full GPT-5.5 went public in late April with what OpenAI described as its strongest safety guardrails to date. The "Cyber" version is the same underlying model with those guardrails loosened — deliberately — for vetted security teams who need to do work that the consumer-facing model refuses.
What does that mean in practice? Vulnerability identification and triage. Malware analysis. Binary reverse engineering. Detection engineering. Patch validation. These are the bread-and-butter tasks of corporate and government security teams, and they often involve handling code, payloads, or techniques that the general-purpose ChatGPT would politely decline to touch.
The same capability cuts both ways, which is why access is restricted. A model that can spot a flaw in a power-grid control system can also be weaponized to exploit it. OpenAI's stated solution is a vetting layer: only verified defenders working at government agencies, critical-infrastructure operators, security vendors, cloud platforms, and financial institutions get in. Individual members of the program will be required to enable phishing-resistant account security starting June 1, 2026.
In other words, GPT-5.5 Cyber is built on the principle that the people most likely to abuse a powerful cyber-AI shouldn't be able to walk into it through a sign-up page.
The Anthropic shadow: "Mythos" did it differently
It's hard to read this Tokyo visit without seeing the shadow of a rival. Roughly a month before OpenAI launched GPT-5.5 Cyber, Anthropic — the maker of Claude — introduced "Claude Mythos Preview," a model specifically engineered for autonomous vulnerability discovery. Mainichi's article notes that "Claude Mythos" has similar capabilities, with access kept extremely narrow.
The contrast is sharper than it first appears. Anthropic routed Mythos through what it calls Project Glasswing, a tightly controlled consortium of roughly fifty organizations. The pitch: a slower, more selective approach is needed to keep the AI cyber-arms race from spiraling. Anthropic CEO Dario Amodei reportedly briefed senior Trump-administration officials on the model's power.
OpenAI is taking the opposite road. Speaking to CNN in late April, Sasha Baker said the company doesn't believe it should be "the sole determinants of who gets access to our tools." GPT-5.5 Cyber will reach government entities, critical-infrastructure operators, security vendors, cloud platforms, and financial institutions — a much wider circle than Mythos.
Same goal: get advanced cyber-defense AI into the right hands faster than attackers can deploy their own. Different theories of "right hands." Both companies argue their approach is the responsible one. Tokyo is now, effectively, being asked to vote.
Why Japan, and why now
For overseas readers unfamiliar with Japan's cyber posture, a quick orientation. Japan's critical infrastructure has had a rough few years. Major hospitals have been knocked offline by ransomware. The Port of Nagoya — Japan's busiest port by cargo volume — was paralyzed for about three days in 2023 by a ransomware attack on its container-terminal control system. The country's National Cyber Office (NCO), a new coordinating body inside the Cabinet, has been racing to publish a national cyber-workforce framework while the threats keep arriving.
Layered on top of this: Japan sits next to two of the world's most active state-linked cyber actors, and the country's defense and intelligence relationship with the United States is among the most deeply integrated in the world. From Washington's perspective, hardening Japanese networks is hardening the front line of the Indo-Pacific.
Layered on top of that: a domestic enterprise-AI race is already underway. In April, NEC became the first Japanese company named as a global Anthropic partner, rolling Claude into its corporate workflows for roughly thirty thousand employees. Fujitsu has tied up with Canadian model-maker Cohere. NTT Data has its own arrangement with OpenAI. Until now, the action has mostly been in business productivity — Japan's biggest IT integrators picking dance partners for the enterprise market.
OpenAI's Tokyo move opens a different door: not enterprise productivity, but national security infrastructure. That is a category of relationship that, once established, tends to be sticky for years and to come with cleared-personnel programs, classified deployment guides, and joint exercises. Whoever lands it first sets the standard.
The China angle Nakasone wanted on the record
The briefing also gave Nakasone a chance to plant a flag on a political question. Asked about US President Donald Trump's recent diplomatic outreach to China, Nakasone — who spent years inside US Cyber Command tracking Chinese state hackers — was direct. Dialogue is good, he said, but in his view China remains the most serious threat.
He also flagged the broader concern that Chinese AI developers are pushing hard on similar capabilities. The worry, stated and unstated, is that a model with GPT-5.5 Cyber's vulnerability-finding skills will exist on the other side of the Pacific regardless of what Washington decides — so allied governments had better get on the defensive curve first.
It is the cleanest version of an argument that increasingly drives US tech-industry engagement with allied governments: the question is no longer whether powerful cyber-AI will exist, but who deploys it first and on which side of the network.
What this actually changes
For Japanese ministries and infrastructure operators, OpenAI's offer represents an unusually direct line to a frontier model — bypassing the usual route of going through a Japanese system integrator. Whether Tokyo takes that line, builds it through a domestic prime contractor, or hedges by signing with both OpenAI and Anthropic will say a lot about how the country sees its AI sovereignty. Past Japanese moves — the SoftBank/NEC/Sony/Honda "Physical AI" national project, the Cabinet's signals about sovereign-AI infrastructure — suggest Tokyo is not eager to depend on any single foreign vendor.
For the global market, this is an early data point in a question that did not exist twelve months ago: what does the diplomatic protocol look like when a US AI lab offers a national government a model whose misuse could shake a power grid? OpenAI has chosen broad-but-vetted distribution; Anthropic has chosen narrow-and-curated. The next few months will reveal which approach allied capitals trust.
For everyone else: a quiet shift in who shows up at a Tokyo cybersecurity briefing. Five years ago the visiting expert would have been a US military official or a Big Four consultancy partner. In May 2026, it was a retired four-star general representing an AI company — and the product on offer was a model.
How does your country think about giving private AI labs a role in defending national infrastructure? Is that something you'd want your government taking a deal on, or a line you'd want kept brighter?
Sources
- https://news.yahoo.co.jp/articles/62a360c9d6df41b9e68ad0cf0eed5c9030c08e01
- https://www.nikkei.com/article/DGXZQOUC211CY0R20C26A5000000/
- https://openai.com/index/gpt-5-5-with-trusted-access-for-cyber/
- https://www.cnbc.com/2026/05/07/openai-rolls-out-new-gpt-5point5-cyber-to-vetted-cybersecurity-teams.html
- https://www.cnn.com/2026/04/29/tech/openai-cybersecurity
- https://openai.com/index/openai-appoints-retired-us-army-general/
Global Discussion
5 comments