Tech

OpenAI revokes TAC program access for cybersecurity researchers

OpenAI has attributed sudden access revocations in its Trusted Access for Cyber program to a technical error, prompting affected researchers to re-verify their identities.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · View original source
Researchers say OpenAI revoked their access to limited cyber program
Technology

OpenAI has confirmed that a technical error caused the sudden revocation of access to its Trusted Access for Cyber (TAC) program for a limited number of cybersecurity researchers. The issue specifically affected users of the Daybreak Blue tier, which provides access to advanced AI models with reduced guardrails.

Multiple researchers reported that when they accessed the Cyber page on ChatGPT, they received messages stating that their identity could not be verified or that their accounts were ineligible. OpenAI acknowledged the disruption, describing it as an error on the company’s end that did not reflect the user experience it aims to deliver.

The TAC program is designed to provide vetted defensive security researchers with access to frontier models to facilitate the rapid reporting and patching of vulnerabilities. By offering models with fewer restrictions than those available to the general public, OpenAI aims to help trusted defenders identify bugs while preventing malicious actors from exploiting the technology.

Daybreak Blue, launched on 10 August, grants access to frontier general-purpose models, including GPT-5.6 Sol, with safeguards tailored for authorized defensive security work. It supports activities such as vulnerability discovery, secure code review, malware analysis, and incident response. A higher tier, Daybreak Red, was also introduced to provide access to models specifically designed for authorised vulnerability research and exploit validation.

TechCrunch spoke to five researchers who experienced the access revocation, all of whom reside outside the United States and Europe. This geographic concentration suggests the technical issue may be limited to specific regions, although the total number of affected individuals remains unknown. OpenAI has asked affected users to reapply and complete the verification process to restore their access.

The incident occurs against a backdrop of ongoing complaints from both defensive and offensive security researchers regarding the guardrails imposed by AI providers. Critics have argued that these restrictions hinder legitimate security work, a sentiment that has also been directed at Anthropic, which operates a similar initiative known as the Cyber Verification Program.

Continue reading

More from Tech

Read next: Ethernet Cable Length Matters Most at Higher Network Speeds
Read next: Engadget weighs MagSafe against USB-C for MacBook charging
Read next: Essay challenges reported claims of a 10% AI extinction risk