OpenAI accidentally revoked access to its Trusted Access for Cyber (TAC) program for a number of cybersecurity researchers this week, the company confirmed, after a technical error left some users locked out of the initiative’s latest tier.
On Wednesday, multiple researchers reported on OpenAI’s support forums and on X that they had lost access to the program, with messages stating that their identity could not be verified or that their account was “ineligible at this time.” TechCrunch spoke to five affected researchers, all of whom said they live outside the U.S. and Europe, suggesting the issue may have been concentrated in specific regions.
Also read: AI won't cure cancer without better data. Vivodyne built robotic labs to fix that.
One researcher shared an email from OpenAI stating that access to Daybreak Blue, the latest vetted tier of TAC, was revoked “due to a technical issue affecting a limited number of users.” The message added: “This was an issue on our end, and not the user experience we want to deliver.” OpenAI also pointed to a tweet acknowledging the problem and asking affected users to re-verify their identity.
What is the Trusted Access for Cyber program?
TAC is a specialized program through which OpenAI provides vetted researchers with access to its most advanced AI models, but with fewer cybersecurity guardrails than standard consumer versions. The goal is to give trusted defenders better tools to identify and report vulnerabilities to companies, accelerating the patching process. Anthropic runs a similar initiative called the Cyber Verification Program (CVP).
Also read: Crypto Genesys Goes Live on 1win in Limited Platform Release
To qualify for TAC, researchers must submit identification and undergo a vetting process. Daybreak Blue, launched on August 10, is the recommended starting point for individual defenders, offering access to “frontier general-purpose models, including GPT-5.6 Sol,” with safeguards tailored to authorized defensive security work. OpenAI also introduced a higher tier, Daybreak Red, which provides models specifically designed for authorized vulnerability research and exploit validation.
The incident comes amid broader frustration from security researchers about the guardrails imposed by both OpenAI and Anthropic. In recent months, researchers have argued that overly restrictive safeguards hinder legitimate defensive work, such as analyzing malware or validating exploits. While OpenAI’s error was not intentional, it adds to the perception that access to these powerful tools remains fragile and subject to unexpected disruptions.
What this means for the security research community
For researchers who rely on TAC for daily work, even a temporary loss of access can be disruptive. Many use these models to analyze suspicious files, review code for vulnerabilities, or simulate attacks in controlled environments. A sudden revocation, even if accidental, can interrupt ongoing investigations and delay responsible disclosure timelines.
OpenAI has asked affected users to reapply and complete the verification process, but the incident raises questions about the reliability of such programs. It also highlights the delicate balance AI companies must strike: granting enough freedom to enable meaningful security research while preventing malicious actors from exploiting the same tools.
As the demand for AI-assisted cybersecurity grows, the reliability of access programs like TAC will be critical. Researchers and companies alike will be watching to see if OpenAI can prevent similar errors in the future and whether the re-verification process will be smooth for those affected.
Updated with comment from OpenAI.
This article is for informational purposes only and does not constitute financial advice. The cryptocurrency and AI markets are volatile and uncertain; readers should conduct their own research before making any investment decisions.

Be the first to comment