OpenAI glitch locks vetted security researchers out of cyber program
A technical error revoked access to the 'Daybreak Blue' tier for defensive researchers, with some struggling to regain entry.
A technical glitch at OpenAI has stripped vetted security researchers of their access to the Trusted Access for Cyber (TAC) program. The incident specifically impacted the 'Daybreak Blue' tier, leaving legitimate security professionals unable to utilize specialized AI tools designed for defensive work.
OpenAI acknowledged the failure via its community forums, a post on X, and direct emails to affected users, attributing the lockout to a "technical issue." In one email to a researcher, the company stated, "This was an issue on our end, and not the user experience we want to deliver." The 'Daybreak Blue' tier, launched on August 10, 2026, provides researchers with access to frontier models, including GPT-5.6 Sol, which features safeguards tailored for defensive security operations.
The TAC Framework
The Trusted Access for Cyber program addresses a fundamental tension in AI safety: providing security professionals with the advanced capabilities needed to find and patch vulnerabilities without giving malicious actors the tools to create exploits. By vetting users, OpenAI offers models with fewer guardrails than those available to the general public, an approach that mirrors the Cyber Verification Program (CVP) operated by Anthropic.
Within the TAC ecosystem, OpenAI maintains different levels of access. While 'Daybreak Blue' serves as the entry point for defenders, the 'Daybreak Red' tier is reserved for higher-level offensive security research, including the validation of exploits.
Implications for Security Research
This incident exposes a vulnerability in OpenAI's account management and verification pipeline. Because the TAC program relies on a strict vetting process to balance utility with safety risks, any failure in the administrative layer creates an immediate barrier to legitimate research. When a glitch not only revokes access but complicates the re-verification process, it undermines the reliability of the program's controls.
For the security community, the lockout represents more than a temporary inconvenience; it demonstrates that the infrastructure supporting these high-stakes tools is susceptible to the same types of failures the researchers are tasked with preventing in other systems.
What Remains Unresolved
While OpenAI has admitted to the error, the path to restoration remains inconsistent. The company has instructed affected users to re-verify their identities to regain access. However, the effectiveness of this remedy is still being tested as researchers attempt to navigate the verification pipeline to recover their previously approved status. It remains to be seen if OpenAI will implement more robust redundancies to prevent vetted users from being purged by future technical glitches.