OpenAI locked vetted security researchers out of its cybersecurity program, then asked them to reapply

OpenAI built a special program to give trusted security researchers fewer restrictions when using its AI models. Then it locked some of them out without warning and asked them to restart the verification process from scratch. That’s not a great look for a company asking the security community to trust it with sensitive work.

According to TechCrunch, multiple researchers reported on OpenAI’s official support forums and on X that their access to the Trusted Access for Cyber program, known as TAC, had been revoked. When they opened ChatGPT’s Cyber page, a message told them their identity could not be verified or that their account was ‘ineligible at this time.’ OpenAI confirmed the problem was caused by an error on its end.

TAC is a vetted program that gives approved cybersecurity researchers access to OpenAI’s most advanced models with fewer guardrails than regular users get. The logic is straightforward: give trusted defenders better tools so they can find and report bugs faster, while keeping those same tools away from malicious actors who might use them to develop exploits. Anthropic runs a similar program called the Cyber Verification Program. Both programs require researchers to submit identification and go through a vetting process before gaining access.

The specific tier affected here is called Daybreak Blue, which OpenAI launched on August 10. It grants access to frontier models including GPT-5.6 Sol, with safeguards aimed at authorized defensive security work. Above that sits Daybreak Red, a higher tier that gives vetted users access to models built specifically for offensive security research, including exploit validation and security testing.

TechCrunch spoke to five researchers who lost access. One received an email from OpenAI citing ‘a technical issue affecting a limited number of users’ and asking them to reapply. ‘This was an issue on our end, and not the user experience we want to deliver,’ the email read. All five researchers reportedly live outside the United States and Europe, which suggests the problem may be concentrated in specific regions. That’s worth watching, because regional access gaps in security research programs can quietly disadvantage researchers in exactly the places where independent security work matters most.

The timing is awkward. In recent months, both defensive and offensive security researchers have complained that the guardrails imposed by OpenAI and Anthropic already block too much legitimate work. Now researchers who cleared the extra hurdles to get expanded access are finding that access isn’t stable. Being revoked without explanation and asked to re-verify undermines the trust these programs are supposed to build. OpenAI’s response so far has been a tweet acknowledging that ‘a limited set of users’ access to Daybreak Blue is no longer active’ and directing them to re-verify. That is a thin answer for researchers who submitted identification and waited to be cleared.

The broader issue here is accountability. If a company is positioning itself as a reliable partner for serious security research, access to its tools cannot be this fragile.