AI News AI资讯 2d ago Updated 2d ago 更新于 2天前 56

Researchers say OpenAI revoked their access to limited cyber program 研究人员称OpenAI撤销了其对有限网络项目的访问权限

OpenAI revoked access to its Trusted Access for Cyber (TAC) program for a limited number of vetted cybersecurity researchers, citing a "technical issue" Affected researchers, all based outside the U.S. and Europe, received messages stating their accounts were "ineligible" or could not be verified on ChatGPT's Cyber page OpenAI confirmed the revocations were an internal error and asked affected users to reapply and re-verify to restore access The incident impacts Daybreak Blue, the tier granting OpenAI突然撤销了部分安全研究人员对其TAC(Trusted Access for Cyber)项目的访问权限,官方确认系技术错误导致 受影响用户主要位于美国和中国以外的地区,需重新完成身份验证流程才能恢复访问 TAC项目为经过审核的研究人员提供访问OpenAI最先进AI模型(如GPT-5.6 Sol)的权限,安全限制较普通用户更少,专用于防御性网络安全研究 OpenAI同期推出Daybreak Blue(基础层)和Daybreak Red(高级层)两个层级,分别支持漏洞发现、代码审查和漏洞利用验证等安全研究任务

72
Hot 热度
65
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • OpenAI revoked access to its Trusted Access for Cyber (TAC) program for a limited number of vetted cybersecurity researchers, citing a "technical issue"
  • Affected researchers, all based outside the U.S. and Europe, received messages stating their accounts were "ineligible" or could not be verified on ChatGPT's Cyber page
  • OpenAI confirmed the revocations were an internal error and asked affected users to reapply and re-verify to restore access
  • The incident impacts Daybreak Blue, the tier granting access to frontier models like GPT-5.6 Sol for defensive security work, and potentially Daybreak Red, the higher tier for authorized vulnerability research and exploit validation
  • The TAC program was designed to balance giving trusted defenders access to less-restricted models while preventing malicious actors from exploiting those same tools

Why It Matters

This incident highlights the fragility of trust-based access programs that sit at the intersection of AI safety and cybersecurity research. For AI practitioners and security researchers, it underscores the risk of relying on platforms that can arbitrarily revoke access to critical research tools, potentially disrupting ongoing vulnerability discovery and defensive security work.

Technical Details

  • The TAC program offers vetted researchers access to OpenAI's most advanced models with reduced cybersecurity guardrails, including Daybreak Blue (frontier general-purpose models like GPT-5.6 Sol) and Daybreak Red (models purpose-built for authorized vulnerability research, exploit validation, and security testing)
  • Access requires ID submission and a vetting process; affected users reported errors stating identity could not be verified or accounts were "ineligible at this time"
  • Anthropic operates a parallel program called the Cyber Verification Program (CVP) with a similar trust-based model
  • The revocations appear geographically concentrated, with all five contacted researchers residing outside the U.S. and Europe, though OpenAI has not confirmed a regional pattern
  • OpenAI launched Daybreak Blue on August 10, positioning it as the starting tier for defensive security work including vulnerability discovery, secure code review, malware analysis, incident response, and patch validation

Industry Insight

  • AI companies should invest in robust, transparent access-management infrastructure for research programs, as technical glitches can erode trust with the security community that these programs depend on for legitimate defensive work
  • The concentration of affected users outside the U.S. and Europe raises questions about whether verification systems have geographic biases or gaps that disproportionately impact international researchers
  • As defensive and offensive security researchers continue to push back against AI guardrails, programs like TAC and CVP will face increasing scrutiny; companies must balance safety concerns with the practical needs of the security community to avoid driving researchers toward less-restricted or less-accountable platforms

TL;DR

  • OpenAI突然撤销了部分安全研究人员对其TAC(Trusted Access for Cyber)项目的访问权限,官方确认系技术错误导致
  • 受影响用户主要位于美国和中国以外的地区,需重新完成身份验证流程才能恢复访问
  • TAC项目为经过审核的研究人员提供访问OpenAI最先进AI模型(如GPT-5.6 Sol)的权限,安全限制较普通用户更少,专用于防御性网络安全研究
  • OpenAI同期推出Daybreak Blue(基础层)和Daybreak Red(高级层)两个层级,分别支持漏洞发现、代码审查和漏洞利用验证等安全研究任务

为什么值得看

本文揭示了大模型公司在开放AI安全研究与维护访问控制之间的平衡难题,直接影响全球网络安全研究生态。事件凸显了AI治理机制的技术脆弱性,以及地域性访问限制可能引发的公平性质疑。

技术解析

  • TAC项目架构:OpenAI的Trusted Access for Cyber项目通过身份验证和审核流程,向可信研究人员开放受限访问权限,允许在受控环境下使用较少安全限制的模型进行防御性安全研究
  • 模型层级设计:Daybreak Blue面向个人研究者,提供GPT-5.6 Sol等前沿通用模型,支持漏洞发现、安全代码审查、恶意软件分析和补丁验证;Daybreak Red为更高层级,提供专门针对网络安全研究的模型,支持授权漏洞研究、漏洞利用验证和安全测试
  • 身份验证机制:研究人员需提交身份证明并通过OpenAI审核才能获得TAC访问权限,系统通过身份验证确认用户资格
  • 访问控制问题:此次事件暴露了访问控制系统的技术缺陷,导致部分已验证用户被错误撤销权限,影响范围主要集中在非美欧地区

行业启示

  • AI安全研究治理模式面临挑战:大模型公司通过白名单机制控制高级模型的访问权限,虽旨在防止恶意使用,但技术故障可能意外阻碍合法安全研究,需建立更稳健的权限管理和恢复机制
  • 地域性访问限制引发公平性质疑:事件显示访问撤销可能具有地域倾向性,AI公司需在安全管控与全球研究社区公平访问之间寻求更透明的平衡方案
  • 防御性AI研究生态依赖平台稳定性:网络安全研究人员高度依赖这些受限访问项目开展漏洞发现和响应工作,平台的技术可靠性直接影响整体网络安全防御能力,行业需推动建立更开放的替代研究渠道

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究 Policy 政策