Glitch cuts vetted researchers off OpenAI
Archive item — written before sources were shown.
A technical error revoked vetted-researcher approval in OpenAI's cyber program, locking out security researchers outside the US and Europe without warning.
Multiple security researchers told TechCrunch that OpenAI abruptly revoked their approved status in Trusted Access for Cyber (TAC), the vetting program that grants defenders reduced-guardrail access to OpenAI’s models for vulnerability research, malware analysis, and incident response. Affected researchers found their verification page reset to “Start verification,” as if they had never been cleared, with some flagged “ineligible at this time.” OpenAI emailed the researchers that the issue was “a technical error affecting a limited number of users” and not the experience it intends, and asked them to reapply.
All five researchers who spoke to TechCrunch live outside the US and Europe, suggesting the fault may be tied to region-specific verification logic rather than a random glitch. TAC’s higher Daybreak Blue tier, built on GPT-5.6 Sol, is the specific access level affected; OpenAI has not said how many total accounts were hit or given a technical root cause.
What it means for you
TAC exists precisely so vetted defenders can use frontier models with fewer restrictions for legitimate security work, the same program behind the recent Daybreak-on-Bedrock rollout and the Daybreak Red cyber-model expansion. A silent, unexplained access revocation for a security team mid-investigation is a real operational risk, not just an inconvenience. If your incident-response or red-team workflow depends on a single vetted-access tier from any vendor, this is a case for keeping a documented fallback path and confirming your own access status regularly rather than assuming approval, once granted, stays granted.
- 01Researchers say OpenAI revoked their access to limited cyber programtechcrunch.com · primary reporting
- 02OpenAI glitch locks out vetted cyber researchers – and some can't get back intheregister.com · independent reporting
