OpenAI GPT-5.4-Cyber Reaches Its API Shutdown Date
The October 1 cutoff ends the model's scheduled API availability, but OpenAI names no single replacement identifier for every customer or workload.
Edited by Tyronne Panaino
OpenAI's published API deprecation schedule reaches the October 1 shutdown date for GPT-5.4-Cyber. The company announced the deprecation on September 11 and directed customers toward the most capable cyber model available to them, without naming one replacement model identifier that applies universally.
The cutoff matters to developers whose applications explicitly request GPT-5.4-Cyber. OpenAI defines shutdown as the point when a model or endpoint is no longer accessible, so a pinned model name can become an operational failure rather than merely an older option.
The schedule moves from warning to cutoff
OpenAI distinguishes a deprecated model from a legacy one. Deprecation begins a retirement process and includes a shutdown date; legacy status indicates that a model no longer receives updates and may be deprecated later. For GPT-5.4-Cyber, the published retirement entry sets October 1, 2026 as the removal date.
That distinction is important for production systems. A legacy label can support a planned migration, while a shutdown date creates a specific boundary for requests that still name the retiring model. Applications with hard-coded identifiers, fallback lists or evaluation baselines tied to GPT-5.4-Cyber need to treat the schedule as an availability change.
This article reports the official cutoff, not an independent availability test. The run did not send a live API request from an entitled account, so it does not establish the exact minute at which access changed for every customer or region.
OpenAI leaves the replacement account-dependent
The deprecation table recommends the most capable cyber model available to the customer. It does not provide one successor identifier, a compatibility guarantee or a statement that every account receives the same alternative.
That generic direction creates a verification task for affected teams. They need to identify which cyber-capable model their account can access, then test request formats, output behavior, refusal boundaries, latency, usage limits and monitoring before treating the migration as complete. Those checks are practical implications of the cutoff rather than capabilities established by the deprecation notice.
The page also does not publish a benchmark comparison between GPT-5.4-Cyber and its possible replacements. A newer or more capable label does not by itself prove equivalent behavior for a particular security workflow. Teams handling authorized defensive testing should preserve their existing approval, logging and human-review controls while they evaluate a replacement.
What to verify next
The next verifiable checkpoints are OpenAI documentation naming current cyber-model options, account-level model listings and successful application tests using the selected replacement. Developers should also confirm that fallback logic does not silently route sensitive work to a model with different access or safety conditions.
Status
Confirmed. Internal confidence is medium because OpenAI's official developer documentation establishes the announcement date, shutdown date and generic replacement direction, while live account access and replacement behavior were not independently tested in this run.
Sources
Update note: Last reviewed 2026-10-01. We will revise this post if OpenAI changes the cutoff record or names a more specific replacement path.
Sources
- OpenAI API documentation — Deprecations — official
Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.