OpenAI Fixes Cyber Research Access Glitch as It Tests New Privacy-Focused Safety System

Abeerah Hashim  - Security Expert
Last updated: August 22, 2026
Share
OpenAI Fixes Cyber Research Access Glitch as It Tests New Privacy-Focused Safety System
  • OpenAI says a tech error caused some researchers to lose access to its cyber program.
  • The company is testing a new safety system that can spot risk across chats without sharing user content with OpenAI staff.
  • The move comes as Anthropic keeps data for 30 days on some top models to help find misuse.

OpenAI is fixing an access glitch in its new cyber research program, Daybreak. It is also testing a new way to find misuse while keeping user data private.

Several security researchers said their Trusted Access for Cyber access vanished this week. OpenAI said a tech error caused the issue. It asked some users to apply again and repeat the check.

Researchers lose cyber access to OpenAI models

Trusted Access for Cyber helps approved security workers use OpenAI models for security work. The program cuts some model limits for vetted users. Other safety rules still apply.

OpenAI says the program supports tasks such as bug research, threat checks, and security tests. Some high-risk tasks need more approval.

On August 19, several researchers on OpenAI’s support forum said their Daybreak access had gone. Some said their accounts showed the first step of the check again. Reports said five Daybreak Blue researchers outside of the US and Europe encountered this problem.

OpenAI confirmed the issue came from its side. It said a tech problem caused some users to lose Daybreak Blue access. The firm told affected users to apply again and finish the check.

There is no sign that this event was a hack. Current reports point to an access error, not a data breach.

Daybreak gives cyber teams more freedom

OpenAI expanded Daybreak on August 10 with two separate access tiers, Daybreak Blue and Daybreak Red.

The Daybreak Blue version provides approved users with access to GPT-5.6 Sol. These guardrails are lower than those used normally by OpenAI, which claims that its regular guardrails are capable of preventing legitimate use by security professionals.

The Daybreak Red version takes things one step further. Approved users get GPT-5.6-Cyber. OpenAI specifically trained this model for more complex cyber challenges like identifying vulnerabilities and creating exploit chains.

Still, there are certain restrictions imposed by OpenAI. The user needs to have permission to test the respective system.

The recent issue with accessing the model is thus very crucial as security researchers want more freedom in testing AI technology. On the other hand, attackers could exploit the same opportunities, so OpenAI wants stricter control measures in place.

OpenAI has also extended its cybersecurity efforts to Europe. OpenAI revealed in July that it had partnered with various organizations, including cyber agencies and operators of critical infrastructure in Europe, through its Trusted Access initiative.

A new way to check for risk

OpenAI also unveiled Private Safety Processing on August 20. The system works with Zero Data Retention, or ZDR, for eligible API users. Under ZDR, OpenAI does not keep prompts or model replies after a request ends, subject to the program rules.

That creates a safety gap. One chat may look safe. A set of chats may show a clear plan to cause harm. For example, a user may ask about a software bug. Later, that user may ask how to gain access or hide an attack. The full pattern may look risky. Private Safety Processing aims to spot that pattern without giving OpenAI staff the user’s text.

OpenAI says its tools can check linked chats and flag risk. The company can then get a narrow safety signal. The firm says users can keep their data on their systems. If OpenAI stores it, the data uses keys that the customer controls.

OpenAI is now testing the system with early users. It plans to share more details as the work moves ahead.

Anthropic uses data retention

The latest move sheds light on a growing difference between Anthropic and OpenAI. Anthropic now requires 30-day data retention on traffic of some covered models. The company said this will help its safety systems to identify threats across many requests.

According to Anthropic, data deletion usually takes place after 30 days except where such data is retained by its safety systems or under legal obligation.

Thus, we have two different approaches here. Anthropic keeps the data for a brief period to identify abuse. On the other hand, OpenAI seeks to do the same without letting its employees see what the user typed in.

Such an approach will be of relevance to banks, healthcare organizations and other industries dealing with sensitive data.

Why it matters now

These changes unfold as both firms strive to attract business users as they move towards unveiling their initial public offerings.

As Reuters reported, by the end of July, the annual revenue run rate of Anthropic surpassed $65 billion. Also, OpenAI is getting ready for a possible public listing.

Meanwhile, there is much pressure on OpenAI to develop despite safety improvements. OpenAI has been assessing its security measures after the recent issues related to AI testing.

Finally, there is one more issue with the Daybreak glitch. The cyber teams require access to the tools continuously. One inappropriate system alteration can cause failure even after passing authentication.

So OpenAI needs to do two things at once. It should provide trusted researchers with enough room to test its AI. At the same time, it should ensure that the model does not become the means of abuse.

OpenAI’s data practices are also under legal scrutiny. The company is facing a class-action lawsuit in California filed in May 2026, which alleges that OpenAI embedded Meta Pixel and Google Analytics tracking tools into ChatGPT’s web interface, transmitting users’ chat queries and email addresses.

Also, other personal identifiers to Meta and Google without proper consent. The suit argues that many users treat ChatGPT as a private space for sensitive topics like health, finances, and legal issues, and had a reasonable expectation of privacy when using the service

Private Safety Processing seems to be the solution that provides OpenAI with more information without violating its zero-retention policy. It will be proven by further usage of the system. As OpenAI claims, initial users are already testing it.

Share this article

About the Author

Abeerah Hashim

Abeerah Hashim

Security Expert

Abeerah is a passionate technology blogger and cybersecurity enthusiast. She yearns to know everything about the latest technology developments. Specifically, she’s crazy about the three C’s; computing, cybersecurity, and communication. When she is not writing, she’s reading about the tech world.

More from Abeerah Hashim

Comments

No comments.