OpenAI glitch locks out vetted cyber researchers – and some can't get back in
OpenAI says a technical stuff-up booted some vetted security researchers out of its Trusted Access for Cyber (TAC) program, only for its recovery process to decide some of them aren't welcome back.
The problem surfaced this week when participants reported that their previously approved status had vanished without warning.
OpenAI's cyber verification page instead invited them to "Start verification" as though they had never been cleared.
Some also found that Daybreak Blue, an access tier offering vetted cyber defenders expanded capabilities, had disappeared from Codex Desktop and the command-line interface.
OpenAI has since acknowledged the problem.
Responding to complaints on its community forum, the company said "a limited set of users" had lost Daybreak Blue access because of a technical issue and would need to complete verification again.
"This isn't the experience we want to deliver, and we're making sure the issue doesn't happen again," OpenAI said.
Affected users were told to look for an email titled "Action required: Reverify your Daybreak Blue access," containing instructions for getting back through the door.
For some, however, it appears to remain shut.
One researcher said they followed the instructions and selected "Start verification," only to be told that the process could not begin because their account was ineligible.
Another participant said they had held Daybreak Blue access for more than a month before losing it in the technical snafu.
After OpenAI support told them to reapply, the verification system reportedly said it could not verify their identity or that the account was currently ineligible.
According to their account of a subsequent exchange with support, OpenAI could neither reset the verification state nor restore or override the previous approval.
TAC gives security professionals access to advanced cyber capabilities that are more restricted for other users.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.