Researchers say OpenAI revoked their access to limited cyber program
OpenAI revoked access to its Trusted Access for Cyber (TAC) program for a limited number of vetted cybersecurity researchers, citing a "technical issue" Affected researchers, all based outside the U.S. and Europe, received messages stating their accounts were "ineligible" or could not be verified on ChatGPT's Cyber page OpenAI confirmed the revocations were an internal error and asked affected users to reapply and re-verify to restore access The incident impacts Daybreak Blue, the tier granting
Analysis
TL;DR
- OpenAI revoked access to its Trusted Access for Cyber (TAC) program for a limited number of vetted cybersecurity researchers, citing a "technical issue"
- Affected researchers, all based outside the U.S. and Europe, received messages stating their accounts were "ineligible" or could not be verified on ChatGPT's Cyber page
- OpenAI confirmed the revocations were an internal error and asked affected users to reapply and re-verify to restore access
- The incident impacts Daybreak Blue, the tier granting access to frontier models like GPT-5.6 Sol for defensive security work, and potentially Daybreak Red, the higher tier for authorized vulnerability research and exploit validation
- The TAC program was designed to balance giving trusted defenders access to less-restricted models while preventing malicious actors from exploiting those same tools
Why It Matters
This incident highlights the fragility of trust-based access programs that sit at the intersection of AI safety and cybersecurity research. For AI practitioners and security researchers, it underscores the risk of relying on platforms that can arbitrarily revoke access to critical research tools, potentially disrupting ongoing vulnerability discovery and defensive security work.
Technical Details
- The TAC program offers vetted researchers access to OpenAI's most advanced models with reduced cybersecurity guardrails, including Daybreak Blue (frontier general-purpose models like GPT-5.6 Sol) and Daybreak Red (models purpose-built for authorized vulnerability research, exploit validation, and security testing)
- Access requires ID submission and a vetting process; affected users reported errors stating identity could not be verified or accounts were "ineligible at this time"
- Anthropic operates a parallel program called the Cyber Verification Program (CVP) with a similar trust-based model
- The revocations appear geographically concentrated, with all five contacted researchers residing outside the U.S. and Europe, though OpenAI has not confirmed a regional pattern
- OpenAI launched Daybreak Blue on August 10, positioning it as the starting tier for defensive security work including vulnerability discovery, secure code review, malware analysis, incident response, and patch validation
Industry Insight
- AI companies should invest in robust, transparent access-management infrastructure for research programs, as technical glitches can erode trust with the security community that these programs depend on for legitimate defensive work
- The concentration of affected users outside the U.S. and Europe raises questions about whether verification systems have geographic biases or gaps that disproportionately impact international researchers
- As defensive and offensive security researchers continue to push back against AI guardrails, programs like TAC and CVP will face increasing scrutiny; companies must balance safety concerns with the practical needs of the security community to avoid driving researchers toward less-restricted or less-accountable platforms
Disclaimer: The above content is generated by AI and is for reference only.