Several cybersecurity researchers reported suddenly losing access to OpenAI’s Trusted Access for Cyber (TAC) program, a limited program that allows vetted researchers to use the company’s models with fewer restrictions than those imposed on ordinary users when conducting security research. OpenAI confirmed that the cancellations resulted from a technical error on its part.
Affected users saw messages stating that their identities could not be verified or that their accounts were not currently eligible when they opened the Cyber page in ChatGPT. Five researchers who spoke with TechCrunch said they encountered the problem, while the number of people affected and the geographic scope of the issue remain unclear.
What happened to users?
A message OpenAI sent to one researcher explained that access to the Daybreak Blue tier had been canceled because of a technical issue affecting a limited number of users. The company also indicated, in a response on its official forum and in a post on X, that access to this tier was no longer active for some users and that they needed to reverify in order to retain it.
OpenAI asked affected researchers to reapply to the program and complete the identity-verification process. All of the researchers who spoke with TechCrunch said they reside outside the United States and Europe, which could suggest that the issue is connected to certain regions, but the company did not confirm this or provide a definitive explanation of the geographic scope of the cancellations.
What does the TAC program offer?
Joining TAC requires submitting identity documents and undergoing an evaluation by OpenAI. The program aims to give trusted defenders more capable models to help them discover vulnerabilities and report them to companies, potentially speeding up the remediation of flaws. At the same time, the mechanism seeks to prevent cybercriminals from using the same models to develop intrusion methods or exploit vulnerabilities in companies.
Daybreak Blue is the latest tier intended for individual researchers, and OpenAI launched it on August 10. The tier provides access to advanced general-purpose models, including GPT-5.6 Sol, with safeguards configured for authorized security-defense work, such as vulnerability discovery, code review, malware analysis, incident response, and patch validation.
The company simultaneously launched a higher tier called Daybreak Red, which provides models customized for cybersecurity research, including authorized vulnerability research, exploit validation, and security testing.
Why does this error matter?
This type of program depends on distinguishing between authorized defensive use and malicious use. Therefore, mistakenly withdrawing access affects not only individual accounts but also disrupts researchers who use the models in security testing and reporting operations. The request for users to reverify also shows that access to advanced cybersecurity model capabilities is tied to the continued application of vetting procedures, even after a researcher has been accepted into the program.
The incident comes amid criticism from defensive and offensive researchers of the restrictions imposed by OpenAI and Anthropic, with these researchers saying that some limitations may hinder legitimate security work. Anthropic offers a similar program called the Cyber Verification Program (CVP).