Editorial illustration for OpenAI Revokes Access to Limited Cyber Program Daybreak Blue
OpenAI Revokes Cyber Program Access for Researchers
OpenAI Revokes Access to Limited Cyber Program Daybreak Blue
Wednesday brought a wave of complaints from security researchers who found themselves locked out of Trusted Access for Cyber, OpenAI's vetted program for using its top AI models with fewer cybersecurity restrictions than regular ChatGPT accounts get. On OpenAI's support forums and on X, multiple people described opening ChatGPT's Cyber page and hitting a wall: a message saying their identity couldn't be verified, or that their account was "ineligible at this time." OpenAI has confirmed the lockouts happened, attributing them to an error, though it hasn't said how many researchers were affected or why the system flagged them in the first place.
TAC exists because OpenAI wants trusted defenders, the people who report bugs and vulnerabilities so companies can patch them, to have access to more capable models than the general public. Getting in requires submitting an ID and passing OpenAI's vetting. Anthropic runs a comparable setup called the Cyber Verification Program.
Both companies frame these programs as a way to keep advanced capabilities out of the hands of hackers while still arming the people trying to stop them. TechCrunch spoke to five researchers who ran into the same wall this week. One of them received an email from OpenAI explaining what happened.
Several security researchers say OpenAI suddenly revoked their access to a limited-access program that removes some restrictions on using its AI tools for cybersecurity research. OpenAI confirmed that the issue was caused by an error.
Why this matters
For security researchers who rely on OpenAI's Cyber tools, this is a reminder that "access" through a gated program is conditional, not owned. Daybreak Blue exists precisely because OpenAI worries about misuse of frontier models for offensive security work, so the company built an identity-verification layer on top of it. When that layer glitches, as it apparently did Wednesday, researchers lose their tools with no warning and have to re-prove who they are before getting back to work they were already vetted for.
OpenAI's fix, pointing people to a tweet and a re-verification prompt, tells us the company still treats these tiers as informal experiments rather than production infrastructure people depend on for real deadlines. For founders building on top of OpenAI's cyber-focused offerings, or researchers coordinating disclosure timelines, that's a real operational risk worth pricing in. Trust programs like TAC are supposed to signal maturity in how AI labs handle sensitive dual-use capabilities.
An unexplained mass revocation, even one chalked up to error, suggests the gatekeeping mechanics are still rougher than the marketing around them.
Common Questions Answered
What is Trusted Access for Cyber and how does it differ from regular ChatGPT accounts?
Trusted Access for Cyber, also known as Daybreak Blue, is OpenAI's vetted program that allows security researchers to use its top AI models with fewer cybersecurity restrictions than regular ChatGPT accounts provide. The program includes an identity-verification layer that OpenAI implemented to prevent misuse of frontier models for offensive security work while still enabling legitimate cybersecurity research.
Why did security researchers suddenly lose access to the Daybreak Blue program on Wednesday?
OpenAI confirmed that an error caused the sudden revocation of access to the Daybreak Blue program. Multiple security researchers reported seeing error messages indicating their identity couldn't be verified or that their accounts were "ineligible at this time" when trying to access the Cyber page.
What does the Daybreak Blue access revocation reveal about gated AI programs?
The incident demonstrates that access to gated programs like Daybreak Blue is conditional rather than owned by users, meaning researchers can lose their tools without warning. This highlights the risk that security researchers face when relying on third-party platforms for critical research tools, as they must re-verify their identity and regain access whenever technical issues occur.
Why did OpenAI implement identity verification for the Cyber program?
OpenAI built the identity-verification layer into Daybreak Blue specifically because the company worries about potential misuse of frontier AI models for offensive security work. This verification system is designed to ensure that only legitimate security researchers with verified identities can access the reduced-restriction tools available through the program.
Further Reading
- Researchers complain that OpenAI revoked their access to limited cyber program - TechCrunch
- OpenAI revokes access to limited cyber program amid researcher complaints - TechCrunch
- OpenAI Daybreak - Trusted Access for Cyber Overview - OpenAI Help Center
- Trusted Access for Cyber - Common Issues and Troubleshooting - OpenAI Help Center
- OpenAI extends 'Daybreak' security project and reveals new cyber model but for approved users only - TechRadar