OpenAI lists gpt-5.4-cyber for API removal on October 1, 2026, and names no successor model | Narracomm Intelligence Record IDN/A DateOctober 1, 2026 BeatAI model lifecycle JurisdictionN/A EntityOpenAI (gpt-5.4-cyber) Instrument / cite2026-09-11 GPT-5.4-Cyber deprecation notice Source typeAPI documentation Confidenceconfirmed Primary source OpenAI API Deprecations
Teams pinning gpt-5.4-cyber have a shutdown date and a capability description in place of a model id, on a notice shorter than the floors OpenAI publishes for generally available and specialized models.
In brief: OpenAI’s API deprecations page, in a notice dated 2026-09-11, says gpt-5.4-cyber will be removed from the API on October 1, 2026, and tells users to migrate to the most capable cyber model available to them rather than to a named model id.
OpenAI has set October 1, 2026, as the API shutdown date for gpt-5.4-cyber and has not named a successor model. The notice, headed “2026-09-11: GPT-5.4-Cyber” on the company’s API deprecations page, is twenty days old. For any product that pins that model id in production traffic, the page is the controlling record, and the controlling record does not say what to call next.
The entry is two sentences. “The gpt-5.4-cyber model is deprecated and will be removed from the API on October 1, 2026. Migrate to the most capable cyber model available to you before the shutdown date.” The table under that heading repeats the instruction. Shutdown date: Oct 1, 2026. Model / system: gpt-5.4-cyber. Recommended replacement: “The most capable cyber model available to you.” No model id appears in the replacement cell. The row carries no version pin and no link to a migration guide.
On this page, deprecation is not a warning period that leaves the model in good standing. “When we announce that a model or endpoint is being deprecated, it immediately becomes deprecated.” A shutdown date then follows. “At the time of the shut down, the model or endpoint will no longer be accessible.” OpenAI uses “sunset” and “shut down” interchangeably for that loss of access. October 1 is the point at which the page says gpt-5.4-cyber stops answering, not a soft end of support. Fetched on the shutdown date itself, the entry still sits in the upcoming-deprecations list and still uses “will be removed.” The page does not record that removal has already taken effect.
The replacement line is an instruction to the caller, not a catalog entry. “The most capable cyber model available to you” puts the selection on whatever cyber model that account can already reach. The page does not define “cyber,” does not list the models that qualify, and does not say that every API customer can see the same set. Two deployments can follow the stated guidance and land on different ids. A contract or a security review that named gpt-5.4-cyber cannot be updated from this page alone.
The notice interval is the other fact the page makes checkable. OpenAI says it gives advance notice “so customers have time to plan and migrate,” and that, “Unless safety or compliance concerns require a faster timeline,” minimums apply. Generally available models get at least six months. Specialized variants of generally available models get at least three months; the examples given are chat variants such as gpt-5.1-chat-latest, Codex variants such as gpt-5.3-codex, and deep research variants such as o3-deep-research. Preview models, “identified by preview in the model name,” may be retired with much shorter notice, “such as 2 weeks.” If safety or compliance requires a faster retirement, the company “will provide as much notice as reasonably possible.” The overview frames retirements generally: “As we launch safer and more capable models, we regularly retire older models.” That sentence is not attached to this row.
gpt-5.4-cyber does not contain “preview” in the model id as printed on the page. The entry does not label it generally available, does not label it a specialized variant, and does not say that safety or compliance concerns drove the date. The span from the 2026-09-11 heading to October 1, 2026, is shorter than both the six-month and the three-month floors the page states, and it sits in the range the page associates with preview models and with the safety exception. Which of those OpenAI is applying is not on the page.
Notification, as described, runs through two channels when a deprecation is announced: email to customers actively using the model, and this documentation page. “Impacted customers will always be notified by email and in our documentation along with blog posts for larger changes.” The cyber entry does not link a blog post. A team that does not match OpenAI’s record of “actively using” the model has the page, not a promised email, as its notice.
One general clause sits below the notice-period rules and is not tied to this model. “In some cases, developers may be able to provision dedicated capacity for continued access after a model’s shutdown date,” by contacting sales. The page does not say that option is open for gpt-5.4-cyber, does not give a price, and does not give a term.
What an enterprise buyer can take from the primary record is narrow and firm. The model id is deprecated as of the 2026-09-11 announcement, the scheduled loss of API access is October 1, 2026, and the published replacement is a capability description rather than an id. What the record does not settle is which cyber model replaces it for a given account, whether the short clock was a safety retirement or an unlabeled exception to the stated floors, and whether dedicated capacity will be sold after the shutdown date.
Why it matters
A founder or security vendor who built a workflow on gpt-5.4-cyber cannot point a customer, an auditor, or an investor at a named replacement. The category narrative for cyber models on this API is now account-specific, and the twenty-day clock, set against the page’s own six- and three-month floors, is the item a buyer will ask about in diligence — not because the page explains the short notice, but because it does not.
Sources
No tracking, no middleman. Follow by RSS (nothing is collected) — or add your email to our self-hosted list.
RSS feed →
