OpenAI Revokes Cybersecurity Researchers’ Access to Limited Cyber Program

A growing number of cybersecurity researchers have voiced frustration after unexpectedly losing access to OpenAI’s exclusive security initiative, the Trusted Access for Cyber (TAC) program.

Designated to give vetted cybersecurity professionals access to frontier models with fewer guardrails for defensive testing, the sudden revocation—and subsequent re-verification headaches—has sparked widespread concern across the security community.

Below, we break down what happened, why researchers are frustrated, and what this means for AI-assisted cybersecurity research.

KEY TAKEAWAY

The Controversy: Multiple cybersecurity professionals were abruptly revoked from OpenAI’s Trusted Access for Cyber (TAC) program.

OpenAI’s Response: OpenAI cited a “technical issue” and asked affected users to re-verify.

The Problem: Many researchers report that the identity re-verification system is failing or tagging them as “ineligible,” leaving them locked out without clear support.

What Is OpenAI’s Trusted Access for Cyber (TAC) Program?

OpenAI launched the Trusted Access for Cyber (TAC) initiative (often associated with specialized access tiers like Daybreak Blue) to empower defensive cyber researchers.

Under normal circumstances, frontier AI models come with strict safety guardrails that prevent them from analyzing malicious code or assisting with potential exploits. However, TAC grants vetted security experts access to models with relaxed restrictions, building upon OpenAI’s commitment to safety as seen in recent initiatives like OpenAI’s cross-industry AI safety testing

. This specialized access allows researchers to:

  • Analyze Malware & Vulnerabilities: Deconstruct complex exploits in a controlled environment.
  • Accelerate Bug Patching: Help organizations detect software flaws faster.
  • Report Frontier AI Flaws: Provide direct feedback to OpenAI to ensure models are safer against malicious prompt injection and abuse.

For many researchers, TAC has become a core component of their daily vulnerability research workflows.

Why Did OpenAI Revoke Access?

The incident began when security researchers noticed their specialized access had vanished without warning.

While some initial reports speculated about stricter compliance enforcement or policy changes, OpenAI clarified on social channels that a technical glitch caused a limited set of verified users to lose their active status. This unexpected pause comes alongside broader security checks across the company’s ecosystem, similar to the temporary safety review during the OpenAI Astra model security pause

OpenAI instructed impacted users to complete an identity re-verification step (typically handled via third-party verification platforms like Persona) to restore their access.

Why Researchers Are Frustrated: The Re-Verification Bottleneck

Despite OpenAI’s direction to simply re-verify, researchers report significant hurdles attempting to restore their credentials:

  1. System Ineligibility Errors: Many researchers attempting to re-verify at chatgpt.com/cyber are greeted with automated errors stating they are “unable to start identity verification” or “not currently eligible”.
  2. Support Loop Issues: Affected users on the OpenAI Developer Community forum note that support tickets are being closed with automated responses or shifted across multiple case numbers without real resolution.
  3. Disrupted Research Timelines: Because researchers rely on TAC to evaluate time-sensitive zero-day vulnerabilities, weeks-long lockouts severely hamper defensive security operations.

What This Means for AI and Cyber Defense

This disruption highlights an ongoing challenge in the AI industry: balancing model security controls with legitimate defensive research.

  • The Security Dilemma: Strict guardrails prevent threat actors from abusing AI for cyberattacks, but overly restrictive access—or buggy permission models—disadvantages the “white hat” defenders who keep platforms secure. This challenge reflects broader international discussions surrounding global AI governance treaties aimed at balancing safety and innovation.
  • Developer Trust: As AI companies transition from experimental products to critical infrastructure, seamless account management and responsive developer support are essential for maintaining trust with the security community.

Frequently Asked Questions (FAQ)

What is the Trusted Access for Cyber (TAC) program?

TAC is an OpenAI program that provides verified cybersecurity researchers with access to frontier models with modified guardrails, enabling them to safely test code, analyze malware, and research vulnerabilities.

Why was researchers’ access revoked?

OpenAI stated that a technical issue caused access to expire or become inactive for a subset of users, requiring them to re-verify their identity to regain entry.

How do I fix the “Unable to start identity verification” error for TAC?

Currently, this error is tied to an ongoing issue with OpenAI’s re-verification pipeline. Affected users are advised to submit a ticket through OpenAI Support, monitor official Developer Forum threads for updates, and avoid opening multiple duplicate tickets to prevent support delays.

Leave a Reply

Your email address will not be published. Required fields are marked *