OpenAI Revokes Researchers' Access to Limited Cyber Program

Security experts report that OpenAI unexpectedly revoked access to its restricted Cybersecurity Research program, which relaxes certain usage limits for security testing. The company has since confirmed the revocations were the result of a technical error.
On Wednesday, multiple researchers on OpenAI’s support forums and X reported losing access to the Trusted Access for Cyber (TAC) program. Users reported seeing error messages stating their identity could not be verified or that their accounts were “ineligible at this time” when accessing ChatGPT’s Cyber page.
TAC is an exclusive program granting vetted researchers access to OpenAI’s most advanced AI models with fewer cybersecurity restrictions than those available to the general public. Anthropic operates a similar initiative known as the Cyber Verification Program (CVP).
Both TAC and CVP aim to provide trusted security professionals with superior models to identify and report vulnerabilities, thereby accelerating patch deployment. These programs also seek to prevent malicious actors from exploiting these models to discover bugs or develop exploits against organizations.
Access to TAC requires cybersecurity researchers to submit identification documents and undergo a vetting process by OpenAI.
It remains unclear why these specific researchers lost access or how many users are affected by this issue.
TechCrunch consulted five researchers who experienced the problem. One researcher shared an email from OpenAI stating that access to Daybreak Blue, the latest vetted tier of TAC, was revoked “due to a technical issue affecting a limited number of users.”
“This was an issue on our end, and not the user experience we want to deliver,” the message read, as shared by the researcher with TechCrunch.
In a discussion on OpenAI’s forums, another researcher noted that official support cited a “recent technical issue” causing some users to lose access to Daybreak Blue after contacting support.
Both messages instructed researchers to reapply and complete the verification process to restore access.
All researchers TechCrunch spoke with reside outside the U.S. and Europe, suggesting the revocations may be geographically limited.
OpenAI directed TechCrunch to a tweet stating that a “limited set of users’ access to Daybreak Blue is no longer active and they will need to re-verify to maintain their access.”
Daybreak Blue, launched on August 10, is the current tier for individual researchers, providing access to “frontier general-purpose models, including GPT‑5.6 Sol, with safeguards tailored to authorized defensive security work,” according to OpenAI. The company describes it as the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.
Simultaneously, OpenAI introduced a higher tier called Daybreak Red, which grants access to models specifically designed for cybersecurity research. This tier allows vetted users to conduct “authorized vulnerability research, exploit validation, and security testing.”
In recent months, both defensive and offensive security researchers have criticized the guardrails imposed by Anthropic and OpenAI, arguing that these restrictions hinder legitimate security work.
Updated with comment from OpenAI.
Related article
OpenAI Partners with Yubico to Bolster GPT-5.6 Security via Hardware Passkeys
Jerrod Chong, CEO of Yubico | Image Credit: YubicoOpenAI’s upcoming GPT-5.6 will mandate hardware-backed passkeys starting in September, a move that Yubico CEO Jerrod Chong says confirms their product as the premier defense against account compromise
AI Guardrails Stifle Offensive Cybersecurity Researchers
For months, AI leaders have implemented strict vetting protocols and safety guardrails to prevent malicious actors from exploiting their models. However, these restrictions are now obstructing legitimate network defenders and offensive cybersecurity
OpenAI Leads 100-Signatory Push for Cyber Defence
OpenAI’s letter begins stating "we have a limited window to strengthen cyber defences". Credit: Getty ImagesMajor tech firms – including AWS, Google and Microsoft – urge governments to fund defensive tools, while critics call the manifesto self-servi
Related Special Topic Recommendations
Comments (0)
0/500

Security experts report that OpenAI unexpectedly revoked access to its restricted Cybersecurity Research program, which relaxes certain usage limits for security testing. The company has since confirmed the revocations were the result of a technical error.
On Wednesday, multiple researchers on OpenAI’s support forums and X reported losing access to the Trusted Access for Cyber (TAC) program. Users reported seeing error messages stating their identity could not be verified or that their accounts were “ineligible at this time” when accessing ChatGPT’s Cyber page.
TAC is an exclusive program granting vetted researchers access to OpenAI’s most advanced AI models with fewer cybersecurity restrictions than those available to the general public. Anthropic operates a similar initiative known as the Cyber Verification Program (CVP).
Both TAC and CVP aim to provide trusted security professionals with superior models to identify and report vulnerabilities, thereby accelerating patch deployment. These programs also seek to prevent malicious actors from exploiting these models to discover bugs or develop exploits against organizations.
Access to TAC requires cybersecurity researchers to submit identification documents and undergo a vetting process by OpenAI.
It remains unclear why these specific researchers lost access or how many users are affected by this issue.
TechCrunch consulted five researchers who experienced the problem. One researcher shared an email from OpenAI stating that access to Daybreak Blue, the latest vetted tier of TAC, was revoked “due to a technical issue affecting a limited number of users.”
“This was an issue on our end, and not the user experience we want to deliver,” the message read, as shared by the researcher with TechCrunch.
In a discussion on OpenAI’s forums, another researcher noted that official support cited a “recent technical issue” causing some users to lose access to Daybreak Blue after contacting support.
Both messages instructed researchers to reapply and complete the verification process to restore access.
All researchers TechCrunch spoke with reside outside the U.S. and Europe, suggesting the revocations may be geographically limited.
OpenAI directed TechCrunch to a tweet stating that a “limited set of users’ access to Daybreak Blue is no longer active and they will need to re-verify to maintain their access.”
Daybreak Blue, launched on August 10, is the current tier for individual researchers, providing access to “frontier general-purpose models, including GPT‑5.6 Sol, with safeguards tailored to authorized defensive security work,” according to OpenAI. The company describes it as the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.
Simultaneously, OpenAI introduced a higher tier called Daybreak Red, which grants access to models specifically designed for cybersecurity research. This tier allows vetted users to conduct “authorized vulnerability research, exploit validation, and security testing.”
In recent months, both defensive and offensive security researchers have criticized the guardrails imposed by Anthropic and OpenAI, arguing that these restrictions hinder legitimate security work.
Updated with comment from OpenAI.
OpenAI Partners with Yubico to Bolster GPT-5.6 Security via Hardware Passkeys
Jerrod Chong, CEO of Yubico | Image Credit: YubicoOpenAI’s upcoming GPT-5.6 will mandate hardware-backed passkeys starting in September, a move that Yubico CEO Jerrod Chong says confirms their product as the premier defense against account compromise
AI Guardrails Stifle Offensive Cybersecurity Researchers
For months, AI leaders have implemented strict vetting protocols and safety guardrails to prevent malicious actors from exploiting their models. However, these restrictions are now obstructing legitimate network defenders and offensive cybersecurity
OpenAI Leads 100-Signatory Push for Cyber Defence
OpenAI’s letter begins stating "we have a limited window to strengthen cyber defences". Credit: Getty ImagesMajor tech firms – including AWS, Google and Microsoft – urge governments to fund defensive tools, while critics call the manifesto self-servi





Home






