
이미지: TechCrunch AI
Summary
- Multiple users of OpenAI's TAC program for cybersecurity researchers reported losing access on August 19
- Affected researchers were based outside the US and Europe, raising the possibility of a regional glitch
- OpenAI confirmed a technical issue left some users unable to use the service without re-verification
- 발생 시점
- 2026년 8월 19일(현지시간) 수요일
- 대상 프로그램
- Trusted Access for Cyber(TAC) 중 Daybreak Blue 티어
- 증상
- 챗GPT Cyber 페이지 접속 시 신원 확인 불가 또는 '현재 자격 없음' 메시지 표시
- 확인된 피해자
- TechCrunch가 접촉한 연구자 5명, 모두 미국·유럽 외 거주
- 오픈AI 해명
- 일부 사용자에게 영향을 준 기술적 문제, 재인증 요청
- Daybreak Blue 출시일
- 2026년 8월 10일, GPT-5.6 Sol 등 프론티어 모델 제공
- 비교 프로그램
- 앤스로픽(Anthropic)의 Cyber Verification Program(CVP)
Logging In to "Ineligible"
On Wednesday, August 19, several cybersecurity researchers logged into ChatGPT's dedicated cyber page only to find an unexpected screen — either a message saying their identity could not be verified, or one reading "ineligible at this time." These users were part of a special access program OpenAI offers to vulnerability researchers, and they posted on OpenAI's official support forum and on X that accounts they had been using normally just days earlier had suddenly been blocked.
What Is Trusted Access for Cyber?
As OpenAI describes on its official introduction page, the program is called Trusted Access for Cyber, or TAC for short. It grants security researchers who submit identity verification and pass OpenAI's review process access to the latest models with fewer restrictions than ordinary users face. The program is designed to help speed up defensive vulnerability reporting and security assessments, while also preventing the same models from falling into the hands of criminals or malicious hackers who might exploit vulnerabilities.
As METAL LAB reported on August 11 in OpenAI Unveils Cybersecurity-Dedicated Model GPT-5.6-Cyber, OpenAI split TAC into two tiers on August 10. The entry-level tier for individual researchers, Daybreak Blue, offers frontier general-purpose models including GPT-5.6 Sol fitted with safeguards tailored for defensive work, supporting vulnerability discovery, security code review, malware analysis, incident response, and patch verification. The higher tier, Daybreak Red, is paired with models trained specifically for cybersecurity research and covers authorized vulnerability research, exploit verification, and security testing. OpenAI has stated that this model was used to discover a previously unknown vulnerability in Chrome's V8 engine.
| Category | Daybreak Blue | Daybreak Red |
|---|---|---|
| Target models | Frontier general-purpose models such as GPT-5.6 Sol | Models trained specifically for cybersecurity research |
| Use cases | Vulnerability discovery, code review, malware analysis, incident response | Authorized vulnerability research, exploit verification, security testing |
| Nature | Entry-level tier for most defensive researchers | Higher tier requiring more extensive vetting |
What Happened
All five researchers TechCrunch directly contacted reported experiencing the same issue. One researcher shared an email received from OpenAI stating that "Daybreak Blue access was revoked due to a technical issue that affected some users." The email included the line: "This was an issue on our end, and not the user experience we want to deliver." OpenAI's support team, responding to a separate inquiry, also said that some users had lost Daybreak Blue access due to a "recent technical issue."
Both responses directed researchers to reapply and go through re-verification again. A notable common thread is that every researcher TechCrunch contacted resides outside the US and Europe. This suggests the error may have been confined to a particular region, though it remains unconfirmed exactly how many users were affected or why this particular region was involved.
OpenAI's Official Response
In response to TechCrunch's inquiry, OpenAI did not issue a separate statement but instead pointed to a post on X. In the post, OpenAI said that "Daybreak Blue access for a limited number of users is no longer valid, and re-verification is required to continue using it." Taken together, the company's explanation indicates this was not an intentional revocation of access but a temporary lockout caused by a system error, one that would be restored once users completed re-verification through the proper process.
The Guardrail Debate Continues
In recent months, security researchers working on both offensive and defensive research have repeatedly complained that guardrails imposed by OpenAI and Anthropic block legitimate research activity. Anthropic operates a similarly structured verification program called the Cyber Verification Program (CVP), which applies real-time cyber safeguards to its Claude Opus and Sonnet models. Both companies face the same dilemma: opening the door to trusted researchers while minimizing the potential for misuse. This TAC access disruption can be seen as a case where the system stumbled while trying to strike that balance.
Editor's Take
What's worth noting here is not the error itself but where it occurred. TAC is a vetted program that requires identity verification just to join, and Daybreak Blue is its entry-level tier. A regionally concentrated error at the entry level points to a possible failure in how the identity verification logic handles country or region codes for certain values. The fact that only researchers outside the US and Europe were affected is too consistent to be coincidental.
From an operational standpoint, this kind of authentication failure is not unusual in the cloud services industry. AWS and Google Cloud have both had incidents where region-specific permission sync errors temporarily locked accounts in certain countries. But in this case, the affected parties are not ordinary consumers but security researchers whose livelihood depends on vulnerability reporting, making the practical impact more severe. If an ongoing vulnerability analysis is interrupted, a malicious actor who discovers the same bug in the meantime could build an exploit first — meaning even a few hours of delay is far from trivial for defenders.
Researchers who are enrolled in and actively using programs like TAC or CVP domestically would do well to keep this case in mind. When an access error occurs, it's better to first check the official support forum or company announcements for reports of similar cases before immediately going through the reapplication process. If the problem stems from a system error rather than an individual account issue, it often resolves without any separate action — and resubmitting re-verification documents unnecessarily could mean getting placed back at the end of the review queue.
OpenAI has already outlined the re-verification process, and if that timeline holds, most affected accounts should be restored within a few weeks. However, if this error is confirmed to stem from an issue in how regional codes were handled, OpenAI is expected to issue a separate announcement soon detailing the cause and measures to prevent recurrence.




Comments