Multiple security researchers say OpenAI abruptly revoked access to a restricted access program that lifts some restrictions on using the company’s AI tools for cybersecurity research. OpenAI has confirmed that this issue is caused by an error.
On Wednesday, multiple researchers on OpenAI’s official support forums and X reported that their access to the Trusted Access for Cyber (TAC) program had been revoked. Officials said when they opened ChatGPT’s Cyber page, they were greeted with a message that either their identity could not be verified or their account was “not eligible at this time.”
TAC is a special program in which OpenAI provides researchers vetted by OpenAI with access to its cutting-edge AI models, which have fewer cybersecurity guardrails than models accessible to regular users. Anthropic offers a similar program called the Cyber Verification Program (CVP).
The idea behind TAC and CVP is to provide a better model for trusted defenders to report bugs and vulnerabilities to the enterprise, allowing flaws to be patched faster. It also aims to prevent cybercriminals and malicious hackers from accessing these models and using them to find bugs or develop exploits to hack companies.
To access TAC, cybersecurity researchers must submit an ID for review by OpenAI.
At this time, it is not entirely clear why these researchers had their access to TAC revoked or how many people are facing this issue.
TechCrunch interviewed five researchers who said they have this problem. According to one researcher, OpenAI sent an email saying that access to its latest scrutinized TAC tier, Daybreak Blue, was revoked “due to technical issues impacting a limited number of users.”
“This is an issue on our end and not the user experience we want to provide,” the message the researchers shared with TechCrunch said.
In a thread on OpenAI’s forums, researchers wrote that after contacting official support, the company also noted “recent technical issues” that caused some users to be unable to access Daybreak Blue.
In both messages, OpenAI asked researchers to reapply and complete the validation process.
The researchers TechCrunch spoke to all said they live outside of the United States and Europe, suggesting the revocation may be limited to certain regions.
OpenAI referred TechCrunch to a tweet in which it said, “Access to Daybreak Blue has been disabled for some users and they will need to re-authenticate to maintain access.”
Launched on August 10, OpenAI says Daybreak Blue is its latest tier for individual researchers, allowing access to “frontier general-purpose models such as GPT‑5.6 Sol with protections tailored to approved defensive security work.” “This is the recommended starting point for most defenders, supporting vulnerability discovery, secure code reviews, malware analysis, incident response, and patch validation.”
At the same time, the company also introduced an upper tier called Daybreak Red, which provides access to models created specifically for cybersecurity research. This allows vetted users to conduct “approved vulnerability research, exploit validation, and security testing.”
In recent months, security researchers on both the defensive and offensive sides have complained about the guardrails imposed by Anthropic and OpenAI, arguing that they prevent them from performing legitimate work.
Updated with comment from OpenAI.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.
