Back to articles
AI Safety

OpenAI Says Technical Error Revoked Some Cyber Researchers’ Access

3 min read

Introduction

OpenAI’s controlled-access program for cybersecurity researchers has experienced a permissions failure. Several researchers said they suddenly lost access to Trusted Access for Cyber, or TAC. When they opened ChatGPT’s Cyber page, they saw messages saying that their identity could not be verified or that their account was currently ineligible. OpenAI later confirmed that the disruption was caused by a technical issue and told affected researchers to apply again and complete the verification process.

Key points

  • TAC is designed for vetted cybersecurity researchers and provides fewer cyber-related restrictions than the standard user experience.
  • The five researchers contacted by TechCrunch said they live outside the United States and Europe, although OpenAI has not confirmed a regional limitation.
  • At least one researcher received an email saying Daybreak Blue access had been revoked because of a technical issue affecting a limited number of users.
  • OpenAI said affected users would need to verify their identities again to maintain access.
  • Daybreak Blue and the higher-level Daybreak Red tier were introduced on August 10 for different types of authorized security work.

Why the program exists

TAC is intended to give trusted defenders access to more capable models with safeguards tailored to legitimate security research. Those researchers can use the systems for vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. The broader objective is to help companies identify and fix flaws faster, while limiting the ability of criminals and malicious hackers to use the same capabilities to develop exploits.

OpenAI describes Daybreak Blue as the latest vetted tier for individual researchers. It provides access to frontier general-purpose models, including GPT-5.6 Sol, with protections adjusted for authorized defensive work. Daybreak Red is a higher tier built around models intended specifically for cybersecurity research, including authorized vulnerability research, exploit validation, and security testing.

Implications

The incident highlights the operational difficulty of running programs that combine powerful models, identity checks, and differentiated safety policies. Even if the revocations were not the result of a policy change, an access failure can interrupt ongoing vulnerability validation and undermine researchers’ confidence in the platform’s reliability and support process.

The episode also adds context to a wider debate over AI safety guardrails. Security researchers have argued that overly restrictive protections can interfere with legitimate defensive work. At the same time, giving broader access to cyber capabilities requires dependable vetting and careful separation from malicious use. A technical error affecting approved researchers shows that both sides of this balance matter: the controls must be strict enough to reduce abuse, but stable enough not to block authorized users.

OpenAI has not said exactly how many accounts were affected or why the researchers encountered the problem. The next questions are whether re-verification restores access consistently and whether the company will explain the scope, cause, and preventive measures related to the incident.

Source: TechCrunch AI

Comments

Checking sign-in status...

Loading comments...

Related articles