OpenAI revoked Daybreak Blue access for a limited set of cybersecurity researchers on Wednesday, nine days after launching the tier on August 10 as part of its Trusted Access for Cyber program. Five affected researchers told TechCrunch they were locked out of ChatGPT's Cyber page, which displayed messages that their identity could not be verified or that their account was ineligible. All five live outside the United States and Europe, pointing to a region-specific revocation rather than a policy shift.
OpenAI acknowledged the issue and blamed a technical error on its end. In an email shared with TechCrunch, the company told one researcher their access was cut "due to a technical issue affecting a limited number of users" and asked them to reapply and complete the verification process again. A similar message appeared on OpenAI's support forum, citing a "recent technical issue."
Trusted Access for Cyber, or TAC, is OpenAI's vetted-researcher program that removes some cybersecurity guardrails on its most advanced models so defenders can conduct legitimate security work. To qualify, researchers submit government ID and pass an OpenAI vetting process. The company positions the program as a way to give trusted defenders faster access to the models needed for vulnerability discovery, while keeping the same capabilities out of the hands of criminal hackers.
“due to a technical issue affecting a limited number of users.”— OpenAI, email to a researcher
Key facts
- 01OpenAI revoked access to its Trusted Access for Cyber program for a limited set of researchers on Wednesday, nine days after the Daybreak Blue tier launched on August 10.
- 02Five researchers, all based outside the US and Europe, confirmed the revocation to TechCrunch.
- 03Daybreak Blue provides vetted defenders access to frontier models including GPT-5.6 Sol with looser cybersecurity guardrails.
- 04OpenAI blamed a technical issue and is requiring affected users to re-verify their identity to restore access.
- 05Anthropic runs a parallel program called the Cyber Verification Program with similar vetting requirements.
Daybreak Blue, the tier at the center of this week's revocations, is the individual-researcher entry point. It grants access to frontier general-purpose models, including GPT-5.6 Sol, with what OpenAI calls safeguards tailored to authorized defensive security work. The company describes it as the recommended starting point for most defenders and lists vulnerability discovery, secure code review, malware analysis, incident response, and patch validation as the covered workflows.
OpenAI also introduced a higher tier called Daybreak Red on the same August 10 date. That tier gives vetted users access to models built specifically for cybersecurity research, covering authorized vulnerability research, exploit validation, and security testing. It is the more permissive of the two and is aimed at offensive security work.
“limited set of users' access to Daybreak Blue is no longer active and they will need to re-verify to maintain their access.”— OpenAI, statement on X
OpenAI publicly addressed the situation in a post on X, saying a limited set of users' access to Daybreak Blue is no longer active and that they will need to re-verify to maintain their access. The company has not disclosed how many researchers were affected or what specifically triggered the revocation, though the concentration of affected users outside the US and Europe suggests a geographic filter misfired during identity checks.
The disruption lands at a sensitive moment for the vetted-access model. Anthropic operates a parallel program, the Cyber Verification Program, with the same premise: hand defenders less-restricted models in exchange for identity vetting. In recent months, both defensive and offensive researchers have publicly complained that the guardrails on OpenAI's and Anthropic's consumer models block legitimate security work, from analyzing malware samples to writing proof-of-concept exploit code for responsible disclosure. Vetted programs are the labs' answer to that criticism.
The lockout undercuts that answer. If verified researchers can be dropped from Daybreak Blue nine days after being approved, the value of going through the vetting process drops. Researchers who rely on OpenAI's models to triage vulnerabilities or review malicious code cannot build a workflow around access that can vanish without warning, and the re-verification requirement means starting the process over rather than a simple restore.
The vetted-access approach is still the most workable compromise between capability and safety that the frontier labs have shipped, and one operational stumble in the first two weeks of a new tier is not evidence that the model is broken. But the incident illustrates why security teams have been slow to trust these programs as production infrastructure. When the ceiling on what a defender can do is set by a verification pipeline they don't control, that pipeline becomes part of their threat model, and this week it failed for at least five of them.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




