Key Takeaways
- OpenAI’s Trusted Access for Cyber (TAC) program, which gives vetted researchers limited‑restriction access to advanced AI models for defensive security work, experienced an unintended revocation of access for a subset of users.
- Affected researchers reported seeing messages that their identity could not be verified or that their accounts were “ineligible at this time,” particularly when trying to access the Daybreak Blue tier.
- OpenAI confirmed the issue was a technical error on its side and asked impacted users to reapply and complete the verification process again.
- All researchers who spoke to TechCrunch reside outside the United States and Europe, suggesting the problem may be region‑specific.
- The incident has reignited debate among security professionals about how model safeguards affect legitimate vulnerability research and defensive work.
Overview of the Trusted Access for Cyber (TAC) Program
OpenAI’s Trusted Access for Cyber (TAC) program is a limited‑access initiative designed to provide vetted cybersecurity researchers with the company’s most advanced AI models while applying fewer cybersecurity guardrails than those imposed on the general public. By granting trusted defenders heightened model capabilities, OpenAI aims to accelerate the discovery and reporting of software bugs and vulnerabilities, enabling faster patching. The program also seeks to keep powerful models out of the hands of malicious actors who could misuse them to develop exploits. Participation requires researchers to submit identification documents and undergo a vetting process by OpenAI before they receive credentials to use the specialized tiers.
Recent Access Revocations Reported by Researchers
On Wednesday, several researchers posting on OpenAI’s official support forums and on the social platform X reported that their access to the TAC program had been abruptly revoked. When they attempted to visit the ChatGPT “Cyber” page, they encountered a notification stating that their identity could not be verified or that their account “is ineligible at this time.” The messages appeared without prior warning, leaving the researchers unable to continue their defensive security work that relied on the elevated model access. The sudden nature of the revocation prompted immediate concern among the affected community, who feared that an administrative mistake or policy change had mistakenly cut off legitimate users.
OpenAI’s Explanation of the Technical Error
In response to the reports, OpenAI acknowledged that the loss of access stemmed from a technical issue rather than an intentional policy shift. One researcher shared an email from OpenAI that explained the revocation of their Daybreak Blue access was “due to a technical issue affecting a limited number of users.” The correspondence added, “This was an issue on our end, and not the user experience we want to deliver.” Similar language appeared in a thread on OpenAI’s forums, where the company cited a “recent technical issue” that caused some users to lose access to Daybreak Blue and instructed affected individuals to reapply and complete the verification process again to restore their privileges.
Details About Daybreak Blue and Daybreak Red Tiers
Daybreak Blue, launched on August 10, is the newest tier aimed at individual researchers. It provides access to “frontier general‑purpose models, including GPT‑5.6 Sol,” with safeguards specifically tuned for authorized defensive security work such as vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. A complementary, higher‑privilege tier called Daybreak Red was introduced simultaneously, offering models built expressly for cybersecurity research. Daybreak Red enables vetted users to conduct authorized vulnerability research, exploit validation, and security testing—activities that require more permissive model behavior while still operating under strict usage policies. Both tiers are intended to balance the need for powerful AI assistance in security work with the imperative to prevent misuse.
Geographic Pattern of the Affected Researchers
All five researchers who spoke to TechCrunch about the revocation noted that they reside outside the United States and Europe. This geographic concentration has led to speculation that the technical glitch may have impacted a particular set of regions or that certain verification mechanisms behave differently for non‑U.S./EU accounts. OpenAI has not publicly disclosed which locales were affected, but the pattern suggests that the error could be tied to regional data handling, identity‑verification pipelines, or compliance checks that vary by jurisdiction. The company’s referral to a tweet stating that a “limited set of users’ access to Daybreak Blue is no longer active” aligns with the notion of a scoped, rather than global, disruption.
Implications for Cybersecurity Research and Model Safeguards
The incident has renewed discussion among defensive and offensive security professionals about the tension between model safeguards and the ability to conduct legitimate research. While guardrails are essential to prevent the creation of tools that could aid cybercriminals, overly restrictive limits can impede efforts to uncover and remediate vulnerabilities in software systems. Researchers argue that access to advanced models—subject to proper vetting and usage policies—can significantly improve the speed and depth of security analyses, especially when dealing with complex codebases or novel attack techniques. The temporary loss of TAC access, even if unintentional, highlights how platform‑level technical problems can disrupt critical defensive work and underscores the need for robust, transparent communication when such issues arise.
Responses from the Security Community and Future Outlook
Following OpenAI’s acknowledgment of the error, the affected researchers have begun the re‑application process as instructed, hoping to regain their Daybreak Blue privileges. Community members on forums and social media have urged OpenAI to provide more detailed post‑mortem information about the root cause of the glitch and to implement safeguards that prevent similar disruptions in the future. Some have also called for clearer criteria regarding how regional differences might affect access decisions, advocating for greater inclusivity in trusted‑access programs. As OpenAI continues to refine its TAC offering—and as competitors like Anthropic run analogous initiatives—the episode serves as a reminder that the reliability of privileged AI access is as important as the technical capabilities those models provide. Ensuring consistent, dependable access for vetted security researchers will be key to maximizing the defensive benefits of advanced AI while keeping misuse at bay.

