OpenAI’s limited-access cybersecurity research program is facing new attention after several researchers said their access was suddenly revoked. The company confirmed that the issue was caused by an error, but affected users were still told they would need to go through verification again.
The program, called Trusted Access for Cyber, gives vetted security researchers access to advanced AI models with fewer cybersecurity restrictions than regular users receive. The access is intended for authorized defensive work, including finding vulnerabilities and helping companies patch flaws faster.
What Happened
On Wednesday, multiple researchers reported on OpenAI’s official support forums and on X that they had lost access to the Trusted Access for Cyber program. When they opened ChatGPT’s Cyber page, they saw messages saying their identity could not be verified or that their account “is ineligible at this time.”
TechCrunch spoke to five researchers who said they had experienced the problem. One researcher said OpenAI sent an email explaining that access to Daybreak Blue, the latest vetted tier of Trusted Access for Cyber, had been revoked “due to a technical issue affecting a limited number of users.”
The message shared with TechCrunch said: “This was an issue on our end, and not the user experience we want to deliver.” In a separate thread on OpenAI’s forums, a researcher wrote that OpenAI support also pointed to a “recent technical issue” that caused some users to lose access to Daybreak Blue.
In both cases, OpenAI asked the researchers to reapply and complete the verification process. OpenAI also referred TechCrunch to a tweet saying a “limited set of users’ access to Daybreak Blue is no longer active and they will need to re-verify to maintain their access.”
Why Trusted Access for Cyber Exists
Trusted Access for Cyber is built around a tradeoff. Security researchers often need powerful tools to test systems, review code, analyze malware, validate patches, and understand how vulnerabilities can be discovered or exploited. At the same time, the same capabilities can be misused by cybercriminals and malicious hackers.
OpenAI’s approach is to vet cybersecurity researchers before giving them access to models with fewer guardrails for cybersecurity work. To get access to Trusted Access for Cyber, researchers have to submit an ID and be vetted by OpenAI.
The program is meant to give trusted defenders better models so they can report bugs and vulnerabilities to companies. The intended outcome is faster patching, while limiting access for people who might use the same models to find bugs and develop exploits to hack companies.
Anthropic offers a similar program called the Cyber Verification Program, or CVP. Both programs reflect the same core problem: defensive security work can resemble offensive security testing, so AI companies are trying to separate authorized researchers from malicious users through restricted access and verification.
Daybreak Blue and Daybreak Red
Daybreak Blue is the latest tier for individual researchers in OpenAI’s Trusted Access for Cyber program. OpenAI launched it on August 10 and describes it as a tier that grants access to “frontier general-purpose models, including GPT‑5.6 Sol, with safeguards tailored to authorized defensive security work.”
According to OpenAI, Daybreak Blue is “the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.” That makes the tier important for researchers who rely on the program to conduct legitimate defensive security work.
OpenAI also introduced a higher tier called Daybreak Red at the same time. Daybreak Red gives access to models made specifically for cybersecurity research and allows vetted users to do “authorized vulnerability research, exploit validation, and security testing.”
The revocations reported by researchers concern Daybreak Blue. At this point, it is not entirely clear why those researchers lost access, or how many users were affected.
Who Was Affected
All of the researchers TechCrunch spoke to said they live outside of the U.S. and Europe. That suggests the access issue may be limited to certain regions, though the source article does not establish that as confirmed.
The distinction matters because the program depends on verification. If access can be removed because of a technical issue, researchers may have to interrupt their work, reapply, and wait for identity checks to be completed again. For a program built around trusted access, the user experience around verification is part of the operational reliability of the tool.
OpenAI said only a limited set of users had inactive access to Daybreak Blue. The company’s explanation so far points to a technical issue rather than a deliberate removal based on user conduct.
The Larger Guardrails Debate
The incident lands in the middle of a broader debate among cybersecurity researchers about AI guardrails. In recent months, both defensive and offensive security researchers have complained about restrictions imposed by Anthropic and OpenAI, saying those guardrails can prevent legitimate work.
That tension is central to programs like Trusted Access for Cyber and the Cyber Verification Program. AI companies are trying to make powerful models available for authorized defensive work while preventing malicious use. Researchers, meanwhile, want enough access to do real security testing without being blocked by broad restrictions.
The Daybreak Blue access issue does not settle that debate. It does, however, show how important the mechanics of trust, eligibility, and re-verification have become. For security researchers, access to advanced AI models is not just a feature; it can shape how they review code, validate patches, analyze incidents, and report vulnerabilities.