Technology

OpenAI Pulls Cybersecurity Researchers' Access to Its TAC Program Nine Days After Launching New Tier

Martin HollowayPublished 2w ago5 min readBased on 15 sources
Reading level
OpenAI Pulls Cybersecurity Researchers' Access to Its TAC Program Nine Days After Launching New Tier
Photo by Tima Miroshnichenko on Pexels

OpenAI has revoked access to its Trusted Access for Cyber (TAC) program for several security researchers, just nine days after launching a new tier that opened its frontier models to vetted defensive security work. According to TechCrunch, five researchers confirmed they had their TAC access pulled, with OpenAI citing a "technical issue affecting a limited number of users" in at least one email to an affected participant.

The TAC program, launched in February 2026, is OpenAI's identity-and-trust framework for granting vetted cybersecurity practitioners access to its most capable models with fewer cybersecurity guardrails than consumer-facing deployments carry. Think of it as a background-check system: researchers must submit identification and pass a vetting process to enroll. The program serves as the governance layer for OpenAI's broader Daybreak cybersecurity initiative, which targets both enterprise customers and individual defenders responsible for critical infrastructure protection.

On August 10, 2026, OpenAI launched the Daybreak Blue TAC tier, the latest access level for individual researchers. Daybreak Blue grants access to frontier general-purpose models including GPT-5.6 Sol, with safeguards tailored specifically to authorized defensive security work. OpenAI also introduced a higher tier, Daybreak Red, which provides access to purpose-built cybersecurity models for vetted users conducting authorized vulnerability research, exploit validation, and security testing. The expansion came alongside a new cyber-trained AI model and a broader scaling of the Daybreak program (TechCrunch.

One researcher told TechCrunch that OpenAI's email attributed their revocation from the Daybreak Blue tier to the technical issue and instructed them to reapply and complete the verification process again. The five researchers TechCrunch spoke to all reside outside the U.S. and Europe, suggesting the revocations may be geographically scoped, though the full extent of affected users is not yet clear.

The revocations land against a complicated backdrop for AI-mediated cybersecurity research. Both OpenAI and Anthropic have built vetted-access programs to thread a narrow needle: give defenders the tooling they need while preventing the same models from being turned to offensive use by malicious actors. Anthropic operates a parallel program called the Cyber Verification Program (CVP). In June, cybersecurity researchers complained that Anthropic's model Fable had guardrails too restrictive for legitimate cybersecurity work (TechCrunch. A July TechCrunch report documented how AI guardrails across major labs were impeding offensive security researchers broadly (TechCrunch.

OpenAI itself has not been immune to security missteps in this domain. In July, the company misconfigured a "highly isolated" testing environment and sandbox, which security experts attributed to an AI-powered hack on Hugging Face (TechCrunch. In April, OpenAI restricted access to its Cyber program shortly after publicly criticizing Anthropic for limiting access to its own Mythos program (TechCrunch. The company also disclosed in April that it found no evidence of user data access, system compromise, or software impact following the Axios developer tool compromise (OpenAI.

The TAC program has scaled rapidly since its introduction. OpenAI announced in April that it was expanding to thousands of verified individual defenders and hundreds of enterprise teams, and introduced GPT-5.4-Cyber, a model with fewer restrictions on sensitive cybersecurity tasks for the highest tier of approved users (Reuters. By May, OpenAI framed TAC as a framework that "expands access to frontier cyber capabilities while strengthening protections against their misuse" (OpenAI.

Asking researchers to reapply and re-complete verification after revocation is not catastrophic, but it is friction. For defenders who have built workflows around these models, even a temporary access gap disrupts ongoing security research and testing pipelines. If the revocations are indeed regionally concentrated, that raises a separate set of questions about how geographic eligibility is determined and communicated within the vetting process.

The broader tension is one the industry has not resolved. Guardrails strict enough to deter misuse are frequently too strict for legitimate work; programs designed to grant privileged access to vetted users introduce their own operational complexity and failure modes. OpenAI's TAC program is still in its first year, and the Daybreak Blue tier is nine days old. Whether the revocations are a genuine technical glitch or a symptom of deeper scaling challenges in the trust-and-verification pipeline remains unclear from the available facts. What is clear is that the demand for less-guardrailed AI models in security research is real and growing, and the supply pipeline for vetted access is still finding its operational footing.