OpenAI、サイバー研究プログラムへのアクセスを誤って停止し謝罪
本文の状態
日本語全文を表示中
詳細モードで約4分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
TechCrunch AI
セキュリティ研究者らが OpenAI の高度な AI モデルへのアクセス権限を突然剥奪された件について、同社が技術的な誤りによるものだと認めた。
AI深層分析を開く2026年8月20日 04:35
AI深層分析
キーポイント
アクセス権限の突然の剥奪
複数のセキュリティ研究者が OpenAI の公式フォーラムや X で、Trusted Access for Cyber (TAC) プログラムへのアクセス権限が突然取り消されたと報告した。
OpenAI の誤りによる事象
OpenAI はこの問題が技術的なエラーに起因するものであり、ユーザー側の不備ではないと公式に認めた。
TAC プログラムの目的と仕組み
TAC は信頼されたセキュリティ研究者に対し、通常のモデルよりも防御策が緩やかな高度な AI モデルへのアクセスを提供し、脆弱性の早期報告を促すプログラムである。
影響範囲と原因の不明確さ
現時点ではこの問題が発生した研究者の正確な人数や、技術エラーが具体的にどの部分で発生したかは完全には明らかになっていない。
アクセス停止の理由と対応
OpenAI は「直近の技術的問題」を理由に一部のユーザーのアクセスを停止し、再申請と検証プロセスの完了を求めている。
重要な引用
"due to a technical issue affecting a limited number of users."
"This was an issue on our end, and not the user experience we want to deliver."
"a recent technical issue that caused some users to lose access"
"limited set of users' access to Daybreak Blue is no longer active and they will need to re-verify"
編集コメントを表示
編集コメント
セキュリティ研究を支援する重要なプログラムにおける技術的エラーは、信頼関係の維持において重大な課題を示している。同社の迅速な対応と再検証プロセスの透明性が今後の信頼回復の鍵となるだろう。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
セキュリティ研究者数名が、OpenAI がサイバーセキュリティ研究のために AI ツールの利用制限を一部緩和した限定プログラムへのアクセスを突然取り消したと報告しています。OpenAI はこの事象は誤りによるものだと確認しました。
水曜日、OpenAI の公式フォーラムや X(旧 Twitter)上で複数の研究者が、「Trusted Access for Cyber(TAC)」プログラムへのアクセス権限を取り消されたと報じました。彼らは ChatGPT のサイバー関連ページを開いた際、本人確認ができないか、アカウントが「現時点で対象外」というメッセージが表示されたと言います。
TAC は、OpenAI が審査済みの研究者に対し、一般ユーザーが利用可能なモデルよりもセキュリティ対策の制限が少ない、同社最上位の AI モデルへのアクセスを認める特別プログラムです。Anthropic も同様の「Cyber Verification Program(CVP)」を提供しています。
TAC と CVP の構想は、信頼できる防御者により優れたモデルを提供し、バグや脆弱性を企業へ報告できるようにすることで、欠陥の修正を迅速化することにあります。同時に、サイバー犯罪者や悪意のあるハッカーがこれらのモデルにアクセスしてバグを見つけ、攻撃用のエクスプロイトを開発するのを防ぐことも目的の一つです。
TAC にアクセスするには、セキュリティ研究者は ID を提出し、OpenAI による審査を受ける必要があります。
現時点では、なぜこれらの研究者の TAC アクセスが取り消されたのか、また対象者がどれほどいるのかについては、まだ明確ではありません。
TechCrunch はこの問題に直面したと語る 5 人の研究者に取材しました。そのうち一人は、OpenAI から「限られた数のユーザーに影響を与える技術的な問題」により、TAC の最新審査済みティアである Daybreak Blue へのアクセスが取り消されたとするメールを受け取ったと語っています。
この研究者が TechCrunch に共有したメッセージには、「これは弊社の側の問題であり、私たちが提供したいユーザー体験とは異なるものです」と記載されていました。
OpenAI のフォーラムでのスレッドでは、ある研究者 が公式サポートへ問い合わせた後、同社も一部のユーザーが Daybreak Blue へのアクセスを失った原因として「直近の技術的な問題」を挙げていたと記述しています。
両方のメッセージにおいて、OpenAI は研究者に対し、再申請して検証プロセスを完了するよう求めています。
TechCrunch が取材したすべての研究者は、米国および欧州外に住んでいると回答しており、このアクセス停止が特定の地域に限定されている可能性を示唆しています。
OpenAI は TechCrunch に対し、同社が「Daybreak Blue の限られたユーザーのアクセスが無効化され、アクセスを維持するには再検証が必要になる」と発表したツイート こちら を紹介しました。
Daybreak Blue は、8 月 10 日に導入された個人研究者向けの最新ティアで、「許可された防御セキュリティ作業向けに設計されたセーフガードを備えた GPT‑5.6 Sol など、最先端の汎用モデルへのアクセス」を付与します OpenAI の発表によると。これは「脆弱性発見、コードレビューの安全化、マルウェア分析、インシデント対応、パッチ検証をサポートする、多くの防御者にとって推奨される最初のステップ」です。
同時に、同社はサイバーセキュリティ研究専用のモデルへのアクセスを付与する、より上位のティア「Daybreak Red」も導入しました。これにより、審査済みのユーザーは「許可された脆弱性調査、エクスプロイト検証、セキュリティテスト」を行うことが可能になります。
ここ数ヶ月、防御側と攻撃側のセキュリティ研究者双方が、Anthropic や OpenAI が設けたガバナンス(ガードレール)に苦言を呈しています。彼らはこれらの制限が、正当な研究活動の妨げになっていると主張しているのです。
※OpenAI からのコメントを追加しました。
当記事内のリンクを通じて購入が行われた場合、私たちは少額のコミッションを受け取る可能性があります。ただし、これは当社の編集の独立性には影響しません。
ローレンツォ・フランチェスキ=ビッチエライは TechCrunch のシニアライターです。ハッキング、サイバーセキュリティ、監視、プライバシーに関する報道を担当しています。
ローレンツォへの連絡や、彼からの outreach(接触)の真偽確認は、以下の方法で行えます:lorenzo@techcrunch.com へメールを送るか、Signal で +1 917 257 1382 に暗号化メッセージを送る、Keybase/Telegram の @lorenzofb に連絡してください。
原文を表示
Several security researchers say OpenAI suddenly revoked their access to a limited-access program that removes some restrictions on using its AI tools for cybersecurity research. OpenAI confirmed that the issue was caused by an error.
On Wednesday, multiple researchers on OpenAI’s official support forums and on X reported having their access to the Trusted Access for Cyber (TAC) program revoked. The people said that when they opened ChatGPT’s Cyber page, a message appeared saying their identity could not be verified or that their account “is ineligible at this time.”
TAC is a special program through which OpenAI offers vetted researchers access to the company’s most advanced AI models with fewer cybersecurity guardrails than the models that regular users can access. Anthropic offers a similar program called the Cyber Verification Program, or CVP.
The idea behind TAC and CVP is to give trusted defenders better models so they can report bugs and vulnerabilities to companies, with the aim of getting flaws patched faster. The goal is also to prevent cybercriminals and malicious hackers from accessing those models and use them to find bugs and develop exploits to hack companies.
To get access to TAC, cybersecurity researchers have to submit an ID and be vetted by OpenAI.
At this point, it’s not entirely clear why these researchers are getting their access to TAC revoked, nor how many people have had this issue.
TechCrunch spoke to five researchers who said they have had this problem. One researcher said OpenAI sent an email saying that their access to Daybreak Blue, the latest vetted tier of TAC, was revoked “due to a technical issue affecting a limited number of users.”
“This was an issue on our end, and not the user experience we want to deliver,” read the message, which the researcher shared with TechCrunch.
In a thread on OpenAI’s forums, a researcher wrote that after they reached out to the official support, the company also cited a “recent technical issue” that caused some users to lose access to Daybreak Blue.
In both messages, OpenAI asked the researchers to reapply and complete the verification process.
All the researchers TechCrunch spoke to said they live outside of the U.S. and Europe, suggesting the revocations may be limited to certain regions.
OpenAI referred TechCrunch to a tweet in which the company said a “limited set of users’ access to Daybreak Blue is no longer active and they will need to re-verify to maintain their access.”
Daybreak Blue is the latest tier for individual researchers that grants access to “frontier general-purpose models, including GPT‑5.6 Sol, with safeguards tailored to authorized defensive security work,” according to OpenAI, which launched it on August 10. “It is the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation.”
At the same time, the company also introduced a higher tier called Daybreak Red that gives access to models made specifically for cybersecurity research, which allow vetted users to do “authorized vulnerability research, exploit validation, and security testing.”
In recent months, both defensive and offensive security researchers have complained about the guardrails imposed by Anthropic and OpenAI, arguing that the guardrails prevent them from doing legitimate work.
*Updated with comment from OpenAI.*
*When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.*
Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy.
You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com, via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み