In a move that has security researchers questioning their life choices, OpenAI has reportedly revoked access to its limited-access cybersecurity program for several researchers - apparently by accident. The company confirmed the issue was caused by an error, which is reassuring, because we all know errors never happen in cybersecurity.

On Wednesday, multiple researchers on OpenAI's official support forums and on X reported that their access to the Trusted Access for Cyber (TAC) program was revoked. When they opened ChatGPT's Cyber page, they were greeted with a message saying their identity could not be verified or that their account "is ineligible at this time." Nothing like a little identity crisis to start the day.

TAC is OpenAI's special program that gives vetted researchers access to its most advanced AI models with fewer cybersecurity guardrails than regular users get. Anthropic has a similar program called the Cyber Verification Program (CVP). The idea is to give trusted defenders better tools to find and report bugs, so companies can patch flaws faster - and keep the bad guys from using those tools to hack everyone. It's a noble goal, unless you're a malicious hacker, in which case, carry on.

To get into TAC, researchers must submit an ID and pass OpenAI's vetting. But now, some of these vetted researchers are being kicked out, and it's not clear why or how many. TechCrunch spoke to five researchers who had the problem. One said OpenAI emailed them that their access to Daybreak Blue - the latest vetted tier of TAC - was revoked "due to a technical issue affecting a limited number of users."

The email continued, "This was an issue on our end, and not the user experience we want to deliver." Ah, the classic "it's not you, it's us" - but for AI security programs.

In a forum thread, a researcher said OpenAI cited a "recent technical issue" after they contacted support. In both cases, OpenAI asked researchers to reapply and complete verification again. Because nothing says "we trust you" like making you prove your identity all over again.

All five researchers TechCrunch spoke to live outside the U.S. and Europe, suggesting the revocations may be regional. OpenAI pointed to a tweet saying a "limited set of users' access to Daybreak Blue is no longer active and they will need to re-verify to maintain their access." So, if you're a security researcher in, say, Singapore, you might want to check your access.

Daybreak Blue, launched on August 10, is OpenAI's latest tier for individual researchers, granting access to "frontier general-purpose models, including GPT-5.6 Sol, with safeguards tailored to authorized defensive security work." It's "the recommended starting point for most defenders," supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. Sounds great - if you can access it.

OpenAI also introduced a higher tier called Daybreak Red, which gives access to models specifically for cybersecurity research, allowing vetted users to do "authorized vulnerability research, exploit validation, and security testing." Because why not have a red team too?

In recent months, both defensive and offensive security researchers have complained about the guardrails imposed by OpenAI and Anthropic, saying they hinder legitimate work. Now, with accidental revocations, they have something new to complain about. At least the error wasn't on their end - this time.