# aisi-uk-gpt55-cyber-capabilities-evaluation-2026-04-30

## Veille

GPT-5.5 offensive cybersecurity evaluation by UK AISI — 95 CTF tasks, 32-step cyber range, universal jailbreak — AISI Blog

## Titre Article

Our evaluation of OpenAI's GPT-5.5 cyber capabilities

## Date

2026-04-30

## URL

https://www.aisi.gov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities

## Keywords

offensive cybersecurity, AI model evaluation, GPT-5.5, AISI UK, capture-the-flag, cyber range, universal jailbreak, Mythos Preview, Opus 4.7, GPT-5.4, red teaming, safeguards, vulnerability exploitation, reverse engineering, cryptography, long-horizon autonomy, SpecterOps, Crystal Peak Security, The Last Ones

## Authors

AI Safety Institute (AISI UK)

## Ton

**Profile**: Institutional technical-evaluation publication by the UK government's AI safety agency, technical-neutral register, advanced level.

**Description**: The tone is that of a governmental evaluation report: factual, methodical, and deliberately neutral. AISI presents its findings without sensationalism, with statistical rigor (confidence intervals, standard errors) that grounds the conclusions in scientific reproducibility. Authority derives from institutional mandate — AISI is the official UK body tasked with evaluating the safety of frontier AI models before deployment. The text balances transparency about growing offensive capabilities with acknowledgment of OpenAI's mitigation efforts. The target audience is threefold: policymakers, AI safety researchers, and the broader cybersecurity community.

## Pense-betes

- AISI uses a suite of 95 narrow cyber tasks in CTF format spread across 4 difficulty tiers (basic, intermediate, hard, expert) testing reverse engineering, web exploitation, and cryptography
- Basic tasks have been saturated (100%) by every frontier model since at least February 2026 — differentiation now occurs solely on expert-tier tasks
- On expert tasks (pass@1): GPT-5.5 scores 71.4% (+-8.0%), Mythos Preview 68.6% (+-8.7%), GPT-5.4 52.4% (+-9.8%), Opus 4.7 48.6% (+-10.0%) — GPT-5.5 is statistically comparable to Mythos but markedly higher than the previous generation
- At pass@5 (best of 5 attempts), GPT-5.5 achieves 90.5% (+-12.9%) on expert tasks — the highest score AISI has ever measured
- The advanced tasks were built in collaboration with Crystal Peak Security and Irregular, firms specializing in cybersecurity
- Token limits: 50M tokens per attempt for narrow tasks, 100M for cyber ranges — performance keeps improving up to these limits
- "The Last Ones" (TLO): a 32-step cyber range simulating a corporate network attack, built with SpecterOps, spanning 4 subnetworks and roughly 20 hosts, estimated at 20 hours for a human expert
- GPT-5.5 completed TLO end-to-end in 2 out of 10 attempts — the second model to do so. Mythos Preview (the first model) had succeeded in 3/10 attempts
- Critical safeguards finding: a universal jailbreak was identified after 6 hours of expert red-teaming, eliciting offensive content across every tested malicious cyber request, including in multi-turn agentic mode
- OpenAI updated its safeguards stack following this finding, but a configuration issue prevented AISI from verifying the effectiveness of the final version
- Structuring conclusion: offensive cyber capabilities emerge as a byproduct of general improvements in long-horizon autonomy, reasoning, and coding — implying future increases are inevitable
- OpenAI released GPT-5.5 with its "most robust safeguards to date," and launched a restricted-access GPT-5.5-Cyber product for defensive cybersecurity professionals

## RésuméDe400mots

In this pre-deployment evaluation, the UK's AI Safety Institute (AISI) documents the cyberoffensive capabilities of OpenAI's GPT-5.5, using its standardized suite of 95 capture-the-flag (CTF) tasks spread across four difficulty tiers, alongside end-to-end attack simulations called "cyber ranges."

On expert-tier tasks at pass@1, GPT-5.5 achieves an average success rate of 71.4% (+-8.0% standard error), substantially on par with Anthropic's Mythos Preview (68.6% +-8.7%) but markedly higher than GPT-5.4 (52.4%) and Opus 4.7 (48.6%). At pass@5, GPT-5.5 sets a record with 90.5% (+-12.9%), the highest score AISI has ever measured. Basic tasks have now been saturated at 100% by every frontier model since February 2026, leaving only the higher tiers discriminative.

The evaluation also includes "The Last Ones" (TLO), a 32-step cyber range built with SpecterOps that simulates a complete corporate network intrusion. This simulation spans four subnetworks and roughly twenty machines, and would take a human expert an estimated 20 hours. GPT-5.5 completed the end-to-end attack chain in 2 out of 10 attempts, becoming the second model to achieve this feat after Mythos Preview (3/10). Evaluations were conducted with limits of 50 million tokens per attempt for narrow tasks and 100 million for cyber ranges, with performance continuing to improve up to these caps.

On safeguards, AISI identified a universal jailbreak after six hours of expert red-teaming. This attack elicited offensive content across the entirety of OpenAI-provided malicious cyber requests, including in multi-turn agentic scenarios. OpenAI subsequently updated its safeguards stack, though a configuration issue prevented AISI from verifying the effectiveness of the final deployed version.

AISI concludes that the rapid progression of cyber capabilities is part of a broader trend: offensive skills emerge as a byproduct of improvements in long-horizon autonomy, reasoning, and coding. If this hypothesis holds, further increases in cyberoffensive capability are to be expected from upcoming frontier models. OpenAI responded by deploying GPT-5.5 with its most robust safeguards to date and by launching a restricted-access GPT-5.5-Cyber product intended for defensive cybersecurity professionals.

## GrapheDeConnaissance

- AISI UK —publie→ evaluation des capacites cyber de GPT-5.5 (DOCUMENT, 0.99)
- GPT-5.5 —mesure→ 71,4% pass@1 sur les taches expert (MESURE, 0.97)
- GPT-5.5 —converge_avec→ Mythos Preview (TECHNOLOGIE, 0.92)
- GPT-5.5 —surpasse→ GPT-5.4 (TECHNOLOGIE, 0.97)
- GPT-5.5 —surpasse→ Opus 4.7 (TECHNOLOGIE, 0.95)
- GPT-5.5 —résout→ The Last Ones (TLO) (TECHNOLOGIE, 0.95)
- SpecterOps —a_créé→ The Last Ones (TLO) (TECHNOLOGIE, 0.9)
- Crystal Peak Security —collabore_avec→ AISI UK (ORGANISATION, 0.88)
- Irregular —collabore_avec→ AISI UK (ORGANISATION, 0.88)
- AISI UK —a_créé→ jailbreak universel (CONCEPT, 0.97)
- jailbreak universel —surpasse→ GPT-5.5 (TECHNOLOGIE, 0.95)
- OpenAI —publie→ GPT-5.5-Cyber (TECHNOLOGIE, 0.9)
- capacites cyber offensives —est_basé_sur→ ameliorations autonomie et raisonnement (CONCEPT, 0.85)
- AISI UK —affirme_que→ les capacites cyber offensives vont continuer a croitre avec les prochains modeles (AFFIRMATION, 0.88)

---
Canonical: https://www.thekb.eu/en/fiches/aisi-uk-gpt55-cyber-capabilities-evaluation-2026-04-30/
