Multiple security researchers had their credentials to OpenAI's restricted cybersecurity program suddenly pulled this week, according to a report published Wednesday by TechCrunch. The company later confirmed the revocations stemmed from an internal technical glitch affecting a subset of users. The Trusted Access for Cyber (TAC) program gives vetted cybersecurity professionals access to OpenAI's most advanced AI models with reduced safety restrictions, allowing them to hunt for software vulnerabilities and report them to companies before malicious hackers can exploit them.
On Wednesday, numerous researchers posted on OpenAI's official support forums and on X that their TAC access had been revoked without warning. When they tried to open ChatGPT's Cyber page, a message told them their identity couldn't be verified or that their account "is ineligible at this time," according to TechCrunch. The outlet spoke with five researchers who experienced the problem, all of whom lived outside the United States and Europe, suggesting the technical issue may have been geographically limited. One researcher shared an email from OpenAI explaining that access to Daybreak Blue—the program's newest vetted tier—had been removed "due to a technical issue affecting a limited number of users." In a forum thread, another researcher reported that OpenAI support similarly cited a "recent technical issue" that caused some users to lose Daybreak Blue access.
OpenAI's Daybreak Blue tier, launched August 10, grants individual researchers access to "frontier general-purpose models, including GPT‑5.6 Sol, with safeguards tailored to authorized defensive security work," the report states. The company describes it as "the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation." OpenAI also introduced a higher tier called Daybreak Red on the same date, which provides models built specifically for cybersecurity research and allows approved users to conduct "authorized vulnerability research, exploit validation, and security testing." The company told affected researchers to reapply and complete the verification process again, confirming in messages that "this was an issue on our end, and not the user experience we want to deliver."
The TAC program exists to give trusted defenders better AI models so they can identify bugs and security flaws and report them to companies, with the goal of getting vulnerabilities patched more quickly. The flip side is preventing cybercriminals and malicious hackers from accessing those same models and using them to discover bugs and build exploits to attack companies. To gain TAC access, cybersecurity researchers must submit identification and pass OpenAI's vetting process. Anthropic runs a similar initiative called the Cyber Verification Program, or CVP. In recent months, both defensive and offensive security researchers have voiced frustration about the guardrails imposed by Anthropic and OpenAI, arguing the restrictions hamper their ability to do legitimate work. OpenAI referred TechCrunch to a tweet stating that a "limited set of users' access to Daybreak Blue is no longer active and they will need to re-verify to maintain their access," though it remains unclear exactly how many people were affected by the technical error.
The incident highlights the tension between keeping advanced AI tools secure and empowering the researchers meant to protect them. Companies offering privileged access to powerful models face constant pressure to balance openness with control, particularly when technical glitches risk alienating the very defenders they depend on to find flaws before adversaries do.

