Security-product builders and enterprise buyers still routing work to gpt-5.4-cyber face a same-day shutdown date and a replacement instruction that names no model.
IN BRIEF: OpenAI’s API deprecations documentation states that the gpt-5.4-cyber model is deprecated and will be removed from the API on October 1, 2026, and tells customers to migrate to the most capable cyber model available to them.
OpenAI has set October 1, 2026, as the date it will remove gpt-5.4-cyber from the API. The notice, dated in the documentation as 2026-09-11 and headed “2026-09-11: GPT-5.4-Cyber,” is the nearest shutdown on the company’s public deprecations list. For any founder, security vendor, or enterprise buyer whose production path still calls that model, the operative fact is the cutoff, not a product announcement.
The page states the position in one sentence: “The gpt-5.4-cyber model is deprecated and will be removed from the API on October 1, 2026. Migrate to the most capable cyber model available to you before the shutdown date.” The accompanying table repeats the same instruction. Shutdown date: Oct 1, 2026. Model / system: gpt-5.4-cyber. Recommended replacement: “The most capable cyber model available to you.”
That replacement line is the operational gap. OpenAI does not name a successor model ID, a version, or a migration mapping. The instruction is relative — “the most capable cyber model available to you” — which leaves the target dependent on whatever cyber model a given account can already call. A buyer comparing vendors, or a founder whose pitch cites gpt-5.4-cyber by name, cannot point to a single documented substitute on this page.
OpenAI defines the terms that govern the cutoff. “Deprecation” is the process of retiring a model or endpoint. When a deprecation is announced, the model “immediately becomes deprecated.” Every deprecated model has a shut-down date. “At the time of the shut down, the model or endpoint will no longer be accessible.” The page uses “sunset” and “shut down” interchangeably for that loss of access. “Legacy” is a separate tag for models that no longer receive updates and that “will be deprecated at some point in the future.” gpt-5.4-cyber is not described as legacy. It is described as deprecated, with a shut-down date.
The documented notice window is short relative to the minimums OpenAI publishes on the same page. The company says that, unless safety or compliance concerns require a faster timeline, generally available models receive at least six months’ notice and specialized variants of generally available models receive at least three months. Examples of specialized variants given on the page are chat variants such as gpt-5.1-chat-latest, Codex variants such as gpt-5.3-codex, and deep research variants such as o3-deep-research. Preview models, identified by “preview” in the name, may be retired with much shorter notice, such as two weeks. The page says OpenAI does not recommend preview models for business-critical production workloads unless the customer can migrate on short notice. gpt-5.4-cyber is not labeled a preview model in the notice.
The announcement date on the heading is 2026-09-11. The shut-down date is October 1, 2026. The notice does not state that safety or compliance concerns required a faster timeline, and it does not place gpt-5.4-cyber in the specialized-variant examples. The interval between those two dates is shorter than both the six-month and three-month minimums the page sets out for the ordinary cases. Customers are told they are notified by email if they are actively using a model being deprecated, and that the deprecation is documented on this page, with blog posts for larger changes. This entry is the documentation record.
The page leaves one residual path. “In some cases, developers may be able to provision dedicated capacity for continued access after a model’s shutdown date.” The route given is to contact OpenAI’s sales team. That is an option to explore, not a stated entitlement, and it is not specific to gpt-5.4-cyber.
Later entries on the same list sit well after this date. Transcription models including whisper-1, gpt-4o-transcribe, gpt-4o-mini-transcribe, and gpt-4o-transcribe-diarize are listed for February 26, 2027, with gpt-live-transcribe or gpt-transcribe as the recommended replacements. A cluster of dated GPT-5 and o3 snapshots, including gpt-5-2025-08-07, gpt-5-mini-2025-08-07, gpt-5-nano-2025-08-07, gpt-5-pro-2025-10-06, o3-2025-04-16, and o3-pro-2025-06-10, is listed for December 11, 2026, pointed at gpt-5.6-sol, gpt-5.6-terra, or gpt-5.6-luna. Image models including gpt-image-1-mini, gpt-image-1.5, and chatgpt-image-latest are listed for December 1, 2026. None of those rows is the cyber-model instruction. On this page, October 1, 2026, belongs to gpt-5.4-cyber alone.
For category narrative, the naming matters. OpenAI’s own wording treats “cyber” as a model class: the recommended replacement is “the most capable cyber model available to you,” not a general-purpose flagship. A security-product company that has told customers or investors it runs on gpt-5.4-cyber now has a vendor record that the identifier will be removed from the API on the stated date, and no public model ID to substitute in the same sentence. Enterprise procurement teams that freeze model identifiers in contracts, eval harnesses, or data-processing records have a documentation date to reconcile against those freezes. The page does not describe capability deltas, pricing, abuse controls, or whether access to the unnamed cyber successor is uniform across accounts.
WHY IT MATTERS: The shut-down date and the unnamed replacement sit on the same official page, so the continuity risk is documentary, not rumored. Any workload, pitch, or contract that still names gpt-5.4-cyber is tied to an identifier OpenAI says will no longer be accessible at shut-down, with the successor defined only as whichever cyber model that customer can already reach.
No tracking, no middleman. Follow by RSS (nothing is collected) — or add your email to our self-hosted list.
RSS feed →
