OpenAI revokes TAC program access for cybersecurity researchers
OpenAI has attributed sudden access revocations in its Trusted Access for Cyber program to a technical error, prompting affected researchers to re-verify their identities.

OpenAI has confirmed that a technical error caused the sudden revocation of access to its Trusted Access for Cyber (TAC) program for a limited number of cybersecurity researchers. The issue specifically affected users of the Daybreak Blue tier, which provides access to advanced AI models with reduced guardrails.
Multiple researchers reported that when they accessed the Cyber page on ChatGPT, they received messages stating that their identity could not be verified or that their accounts were ineligible. OpenAI acknowledged the disruption, describing it as an error on the company’s end that did not reflect the user experience it aims to deliver.
The TAC program is designed to provide vetted defensive security researchers with access to frontier models to facilitate the rapid reporting and patching of vulnerabilities. By offering models with fewer restrictions than those available to the general public, OpenAI aims to help trusted defenders identify bugs while preventing malicious actors from exploiting the technology.
Daybreak Blue, launched on 10 August, grants access to frontier general-purpose models, including GPT-5.6 Sol, with safeguards tailored for authorized defensive security work. It supports activities such as vulnerability discovery, secure code review, malware analysis, and incident response. A higher tier, Daybreak Red, was also introduced to provide access to models specifically designed for authorised vulnerability research and exploit validation.
TechCrunch spoke to five researchers who experienced the access revocation, all of whom reside outside the United States and Europe. This geographic concentration suggests the technical issue may be limited to specific regions, although the total number of affected individuals remains unknown. OpenAI has asked affected users to reapply and complete the verification process to restore their access.
The incident occurs against a backdrop of ongoing complaints from both defensive and offensive security researchers regarding the guardrails imposed by AI providers. Critics have argued that these restrictions hinder legitimate security work, a sentiment that has also been directed at Anthropic, which operates a similar initiative known as the Cyber Verification Program.

