Technical issue disrupts OpenAI cyber research access

OpenAI has revoked access to its Trusted Access for Cyber (TAC) programme for some vetted cybersecurity researchers, with the company telling at least one affected user that a technical issue had affected a limited number of accounts. Researchers reported on OpenAI’s support forums and X that the ChatGPT Cyber page said their identity could not be verified or that their account was ineligible.
TAC gives approved researchers access to OpenAI’s advanced models with fewer cybersecurity restrictions than those available to ordinary users. The programme is intended to help trusted defenders identify vulnerabilities, review code, analyse malware, respond to incidents and validate patches, while limiting access for people who might use the same capabilities maliciously.
Daybreak Blue access affected
The reported disruption concerns Daybreak Blue, the latest TAC tier for individual researchers. OpenAI launched it on August 10 and describes it as a starting point for most defenders. It provides access to frontier general-purpose models, including GPT-5.6 Sol, with safeguards tailored to authorised defensive security work.
TechCrunch spoke to five researchers who said their access had been removed. An email shared with the publication said the revocation resulted from a technical issue and was not the experience OpenAI intended to deliver. In forum correspondence, support also attributed lost Daybreak Blue access to a recent technical issue and asked users to reapply and complete verification again.
Scope and regional pattern remain unclear
It is not yet clear how many accounts were affected or why. All five researchers who spoke to TechCrunch said they lived outside the United States and Europe, which may indicate a regional pattern, but OpenAI had not commented on the account issues when contacted.
The incident follows OpenAI’s expansion of its vetted cyber access structure. Alongside Daybreak Blue, it introduced Daybreak Red, a higher tier for models designed specifically for cybersecurity research. That tier is intended for authorised vulnerability research, exploit validation and security testing.
The model access structure builds on the approach outlined in OpenAI’s restricted Cyber access programme, where trusted researchers receive expanded cyber capabilities under verification controls while wider availability remains restricted. Anthropic operates a comparable Cyber Verification Program, reflecting a shared aim of providing defenders with useful tools without extending the same access to malicious actors.
Guardrails remain a point of debate
Both defensive and offensive security researchers have recently criticised the guardrails used by OpenAI and Anthropic, arguing that restrictions can obstruct legitimate work. The reported TAC removals add an access-management problem to that debate: even approved users can lose a capability they rely on while an account issue is investigated.
For organisations using vetted AI services in security operations, the practical implication is to treat access status as an operational dependency, maintain alternative workflows for research and validation, and plan for renewed identity verification when access controls change.

