Several cybersecurity researchers recently experienced a sudden loss of access to OpenAI’s Trusted Access for Cyber (TAC) program, which provides vetted experts with fewer restrictions on using advanced AI models for security work. Upon attempting to use ChatGPT’s Cyber page, affected users received messages indicating issues with identity verification or ineligibility. The TAC program, designed to help ethical hackers report vulnerabilities quickly and securely, requires researchers to pass identity checks for entry. OpenAI confirmed that this access disruption stemmed from a technical error on their part, not user violations.
The incident primarily impacted researchers residing outside the United States and Europe, though the full scope of affected individuals remains unclear. OpenAI communicated with some users via email, confirming the access revocation was due to a technical fault that impacted a limited group. The company has asked those affected to reapply and complete the verification process again to regain entry to the program. OpenAI’s Daybreak Blue is the most recent TAC tier, providing access to frontier models like GPT-5.6 Sol tailored specifically for cybersecurity professionals.
OpenAI launched Daybreak Blue on August 10 to support a range of defensive cybersecurity tasks including vulnerability discovery and malware analysis. Alongside this, the company also introduced Daybreak Red — a higher level grant allowing for authorized vulnerability research and exploit validation. Both tiers aim to balance providing trusted defenders powerful tools while safeguarding against misuse by malicious actors. OpenAI’s approach aligns with similar initiatives like Anthropic’s Cyber Verification Program, intended to facilitate responsible AI use in security.
This event highlights ongoing tensions in the AI cybersecurity research space about balancing rigorous user verification, access control, and proper monitoring of model use. Some researchers have voiced concerns about AI guardrails limiting legitimate work, but programs like TAC are part of efforts to provide safer environments for responsible security testing. OpenAI acknowledged the recent technical issue was not intentional and is working to ensure users can re-verify and regain program access smoothly. This underscores the complexity of running restricted-access AI services amidst evolving cybersecurity challenges.
Start the discussion with a take, question, or market read.