OpenAI Accidentally Revokes Cyber Researchers' Access
OpenAI accidentally revoked access to its Trusted Access for Cyber program for several researchers, disrupting defensive security work on its advanced AI models.

OpenAI recently cut off several cybersecurity researchers from its Trusted Access for Cyber (TAC) program, an issue the artificial intelligence startup later attributed to a technical error. Affected users attempting to access ChatGPT's Cyber page were met with error messages stating that their identities could not be verified or that their accounts were currently ineligible. The company has instructed those affected to re-verify their identities to restore access.
The TAC program, which launched its latest tier called Daybreak Blue on August 10, is designed to give vetted defenders access to frontier models like GPT-5.6 Sol. These models feature relaxed security guardrails, allowing researchers to perform defensive tasks such as malware analysis, secure code review, incident response, vulnerability discovery, and patch validation. OpenAI also offers a higher tier, Daybreak Red, which provides specialized models for offensive security testing and exploit validation.
While OpenAI did not disclose the exact number of affected users, reporters confirmed the issue with five researchers, all of whom reside outside the United States and Europe. This geographic concentration suggests the technical glitch may have been regional. In emails sent to affected participants, OpenAI blamed a "technical issue affecting a limited number of users" and apologized for the disruption.
For cybersecurity practitioners, programs like TAC and Anthropic's Cyber Verification Program (CVP) are critical for staying ahead of malicious actors. However, security professionals have increasingly complained that strict guardrails on mainstream AI tools hinder legitimate research. Accidental lockouts like this one highlight the fragility of relying on proprietary AI platforms for sensitive defensive workflows, forcing researchers to re-verify their credentials and pause active vulnerability investigations.
This is our own summary of reporting by TechCrunch AI



