OpenAI Attributes Cyber Program Access Loss to Technical Error
OpenAI confirmed on August 19 that a technical error caused multiple cybersecurity researchers to lose access to its Trusted Access for Cyber program. The program gives vetted participants access to models with fewer cybersecurity restrictions, and the disruption affected some users in the Daybreak Blue tier, with at least one researcher asked to reapply and repeat identity verification.
Multiple cybersecurity researchers reported on August 19 that they lost access to OpenAI's Trusted Access for Cyber (TAC) program, a limited-access offering for vetted security professionals. TechCrunch reports that affected users received ChatGPT Cyber messages stating that their identities could not be verified or that their accounts were ineligible.
OpenAI confirmed to TechCrunch that the access problem resulted from an error. According to an email seen by TechCrunch, access to Daybreak Blue, TAC's latest vetted tier, was revoked for a limited number of users because of a technical issue. Mezha reported that OpenAI asked at least one affected researcher to submit a new application and repeat identity verification.
A controlled-access program
TAC gives approved researchers access to OpenAI's advanced models with fewer cybersecurity guardrails than those available to ordinary users, TechCrunch reported. Applicants submit identification and undergo vetting before receiving access.
The program is designed for defensive work, including vulnerability discovery, code review, malware analysis, and responsible disclosure workflows. The underlying access-control problem was notable because TAC's model availability depends on both identity verification and eligibility decisions. TechCrunch said it was not yet clear how many users were affected or why their accounts were caught by the error.
Anthropic operates a comparable Cyber Verification Program for vetted researchers. Both programs seek to make more capable AI systems available for legitimate defensive research while restricting access by malicious actors.
Reliability implications for security research
For security teams, interrupted access can affect time-sensitive investigation and disclosure workflows, particularly where a researcher relies on a restricted model tier for code or vulnerability analysis. The reports do not establish any impact on specific vulnerability reports, customers, or research outcomes.
More broadly, controlled-access AI programs create a recurring operational tradeoff: providers need strong identity and abuse-prevention checks, while authorized users need dependable access during active security work. The reported incident illustrates why verification systems, appeal channels, and status communication are consequential design considerations for platforms serving professional security researchers.
Key Points
- 1OpenAI attributed revoked TAC access for a limited group of vetted researchers to a technical error.
- 2TAC combines access to less-restricted cyber capabilities with identity verification, making authentication reliability important for defensive research workflows.
- 3Comparable vetted-access programs illustrate an industry-wide tension between preventing misuse and maintaining dependable access for authorized defenders.
Scoring Rationale
The incident concerns access controls for advanced AI systems used in cybersecurity research, a relevant operational issue for security practitioners. It is a limited technical-access disruption rather than a model release, major vulnerability, or confirmed policy shift.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
