Researchers say OpenAI revoked their access to limited cyber program
A growing number of cybersecurity professionals have reported a sudden and unexplained loss of access to OpenAI’s specialized research tools. The affected individuals, all participants in the company’s Trusted Access for Cyber (TAC) program, found themselves locked out of the platform this past Wednesday, prompting concerns about the stability of OpenAI’s security-focused initiatives.
The Scope of the Disruption
The TAC program is designed to provide vetted security researchers with access to OpenAI’s most powerful AI models, albeit with fewer restrictive guardrails than those imposed on the general public. By allowing these experts to utilize advanced models for defensive tasks, OpenAI aims to accelerate the discovery and patching of software vulnerabilities.
However, users reported that when attempting to access the dedicated cybersecurity portal, they were met with error messages stating that their accounts were ineligible or that their identities could not be verified. While the exact number of impacted users remains unclear, multiple reports surfaced simultaneously on OpenAI’s official support forums and social media platform X.
"This was an issue on our end, and not the user experience we want to deliver," OpenAI stated in communication sent to affected researchers.
Understanding the TAC and Daybreak Tiers
The TAC program is a critical component of OpenAI’s strategy to balance AI safety with the practical needs of the cybersecurity community. The initiative includes different tiers tailored to specific research needs:
- Daybreak Blue: Launched on August 10, this tier provides individual researchers with access to frontier models—including the GPT-5.6 Sol—with safeguards specifically tuned for defensive security work such as malware analysis, incident response, and secure code review.
- Daybreak Red: A more advanced tier designed for authorized vulnerability research, exploit validation, and deep-level security testing.
These programs are intended to empower "trusted defenders" while preventing malicious actors from leveraging AI to develop sophisticated cyberattacks. To gain entry, researchers must undergo a rigorous vetting process, which includes submitting official identification.
OpenAI’s Response and Regional Patterns
In response to inquiries regarding the outage, OpenAI confirmed that the revocations were the result of a technical error rather than a policy shift. The company clarified that a "limited set of users" had their access to the Daybreak Blue tier deactivated.
Interestingly, the researchers who spoke with the media regarding this issue noted that they are based outside of the United States and Europe. This geographic commonality suggests that the technical glitch may have been isolated to specific international regions. OpenAI has instructed those affected to reapply and complete the verification process once more to restore their access.
The Broader Tension in AI Security
This incident highlights the ongoing friction between AI developers and the security community. In recent months, both offensive and defensive security researchers have voiced frustrations regarding the strict guardrails implemented by major AI labs like OpenAI and Anthropic—which operates a similar Cyber Verification Program (CVP).
Critics argue that these safety measures, while well-intentioned, often hinder legitimate security work. As the industry continues to refine these programs, the balance between preventing misuse and enabling essential research remains a delicate, and clearly evolving, challenge. For now, the affected researchers must navigate the re-verification process to regain the tools necessary for their defensive operations.