Researchers say OpenAI revoked their access to limited cyber program
TechCrunch
β’Wed, 19 Aug 2026 18:46:14 +0000
π° What Happened
Several cybersecurity researchers reported on 19 August 2026 that OpenAI had suddenly revoked their access to the Trusted Access for Cyber (TAC) program, which gives vetted researchers access to more advanced AI models with fewer cybersecurity guardrails. When they opened ChatGPT's Cyber page they saw messages saying their identity could not be verified or that their account was ineligible. OpenAI confirmed the issue was caused by an error, and TechCrunch spoke to five affected researchers though the full scope is unclear.
π The Backstory
TAC is OpenAI's vetting program for trusted security defenders to use advanced models for finding and reporting bugs, similar to Anthropic's Cyber Verification Program (CVP); its aim is to help defenders patch flaws faster while keeping malicious hackers from abusing the models.
π― Why It Matters
The abrupt revocations disrupted legitimate security researchers' ability to use AI for defensive work, and the incident raises questions about the reliability and transparency of restricted-access AI programs amid growing cybersecurity reliance on them.
Several cybersecurity researchers reported on 19 August 2026 that OpenAI had suddenly revoked their access to the Trusted Access for Cyber (TAC) program, which gives vetted researchers access to more advanced AI models with fewer cybersecurity guardrails. When they opened ChatGPT's Cyber page they saw messages saying their identity could not be verified or that their account was ineligible. OpenAI confirmed the issue was caused by an error, and TechCrunch spoke to five affected researchers though the full scope is unclear.
TAC is OpenAI's vetting program for trusted security defenders to use advanced models for finding and reporting bugs, similar to Anthropic's Cyber Verification Program (CVP); its aim is to help defenders patch flaws faster while keeping malicious hackers from abusing the models.
The abrupt revocations disrupted legitimate security researchers' ability to use AI for defensive work, and the incident raises questions about the reliability and transparency of restricted-access AI programs amid growing cybersecurity reliance on them.