OpenAI gates cyber defense in 44 ChatGPT markets with a 1996 US export list

A 250-country audit shows OpenAI's new cyber verification gate exactly matches US export Country Groups D:1 and D:5, rows Georgia inherited from the Soviet Union.

12 min readCybersecurityAccess policyOpenAI

Papers, please.

In August 2026, OpenAI quietly added a country gate to cyber verification. It now blocks 44 countries and territories where it officially offers ChatGPT. Its flow exposes 250 country options. Seventy-three accept no government ID class.

Combined population of affected 44 markets: ~650,000,000 people. This is excluding markets where ChatGPT is officially unavailable anyway (include those and the total comes out to ~2,420,000,000 people, with population data available for 61 of the 73 entries).

The new gate appeared with OpenAI’s August 19 “technical issue”. By then, OpenAI had already approved my Georgian government ID and granted me . The “technical issue” removed that access and sent affected users back through verification.

But fear not: OpenAI said affected users had been emailed a path for verification and its teams were “on standby to help.” More on that standby later.

The Persona flow then repeatedly collected my Georgian ID and face data.

The UN Human Development Index places Georgia in the “very high human development” group, 57th out of 193. It is also where I build open-source security tooling for civil society groups, independent media, and activists dealing with commercial and state-controlled spyware.

OpenAI’s Trusted Access for Cyber program is supposedly made for people doing this work.

A week later, OpenAI likely figured out they forgot to update Persona template, so now it bans you at that step. Can’t complain, at least now it stops me before I submit my biometric data for a ninth time.

If you select Georgia in the Persona widget and press Select. The transition response now contains an empty list of accepted ID classes. The screen says:

Unable to verify

We are unable to verify identities in this country. Please select another country.

Screen: Persona country selector, chatgpt.com/cyber

The Persona widget before and after selecting Georgia01

73 countries without cyber

Screen recording · run openai-cyber-media3-20260827

Entry on screen

GE

Georgia

official ChatGPT marketD:1

1 / 73

still frameat 2:21

44 of the 73 entries are markets where OpenAI officially sells ChatGPT. 35 sit in Country Group D:1 or D:5 of the 1996 US export list.

Screen recording of the production Persona country selector. Sources: the served recordingthe chapter indexproduction selector audit

The country gate

I quickly checked whether the US had imposed some new country-level sanctions on Georgia that I had somehow missed. Nothing.

A new US export-control rule that explained it? Nothing there either.

Maybe the documents themselves? Some IDs really are too weak to verify.

Not these. The new-generation Georgian biometric passport and ID card, in circulation since 2025, won “Best New ID Document Series” at High Security Printing EMEA 2026 in Rabat this February. Georgia has participated in the ICAO Public Key Directory, the repository border authorities use to cryptographically validate ePassport chips, since May 2016: before Italy, Croatia, Serbia, Mexico, and Saudi Arabia, and a year before the EU itself joined as an entity. Document security, biometrics included, was one of the four blocks the European Commission signed off in 2015 before proposing Schengen visa-free travel. And Persona had verified this exact ID when OpenAI approved my Trusted Access in the first place.

So I tested all 250 enabled entries in the new production country gate to see what was going on.

Seventy-three returned no accepted government ID class. Forty-four are places where OpenAI officially says ChatGPT is available.

So you can use your OpenAI subscription, but we don’t trust where your ID is from, so no more cyber defense capabilities for you.

Here’s what came back:

Selector entries tested
250
Cyber verification supported
177
Cyber verification unsupported
73
Entries on OpenAI's ChatGPT access list
208
Listed for ChatGPT but cyber unsupported
44

I then ran all 250 entries against OpenSanctions. Their data is amazing. Thank you to everyone who maintains it.

Only two of the 44 official ChatGPT markets blocked by cyber verification matched an active US sanctions program under the audit’s documented filter. Sanctions were not the pattern.

I expected China to fail because OpenAI does not officially offer ChatGPT there, and many other reasons. But Georgia? Armenia? Azerbaijan? Moldova, Mongolia, and all five Central Asian states? That was weird.

Georgia

I live in Georgia, and this affects me personally, so I’m obviously biased here. I also have a pile of evidence that this is insane.

The new gate gives Georgia and the Russian Federation the same answer. Georgia is on OpenAI’s official ChatGPT access list and had no active US sanctions program matched by the audit’s documented filter. Russia is absent from that list and had three matched programs.

This gate is wrong for every name in the dropdown. But someone whose country Russia is not occupying can make that case for Russia specifically. I won’t do that work.

Russia invaded Georgia in 2008 and continues to occupy 20 percent of its territory. In October 2019, Russia’s GRU carried out large-scale disruptive cyberattacks against Georgia. The attacks hit Georgian government, court, NGO, media, and business websites and interrupted several national broadcasters. The UK called them part of Russia’s long-running campaign of hostile and destabilizing activity against Georgia.

OpenAI’s own threat reporting says it terminated accounts associated with Russia-affiliated Forest Blizzard after the group used its services for research into satellite communications and radar imaging, and for scripting support.

Assuming Russian security services still have access to OpenAI models, that’s a lot of vulnerable persons and organizations left without state-of-the-art defensive capabilities. If you think they don’t, you haven’t been paying attention to tokeneconomics lately. They are free to target me and other Georgians, but I can’t prompt Codex to say:

GPT-5.6-Sol Max Ultra, help, Russian GRU is using OpenAI models to attack me, find the vulnerabilities in my system

Or maybe it’s OpenAI’s own model crossing its evaluation boundary and exploiting a real website that decided to target my systems?

Because that will undoubtedly trigger an automated refusal. Ironically, it will also say that I can apply for Trusted Access.

I can’t. But I’m going to show you who can - people in nine of the world’s top fifteen cybercrime bases!

OpenAI accepts IDs from nine of the top 15 cybercrime bases

OpenAI sells ChatGPT in Georgia, Armenia, and Azerbaijan, and refuses to verify anyone in all three. It verifies people in Ukraine, Nigeria, and Romania.

Rank 1 is the highest estimated concentration of cyber offenders in the 2024 World Cybercrime Index.

OpenAI refuses these three

OpenAI verifies these nine

  1. #2Ukraine
  2. #4United States
  3. #5Nigeria
  4. #6Romania
  5. #8United Kingdom
  6. #9Brazil
  7. #10India
  8. #13Ghana
  9. #14South Africa
Source: World Cybercrime Index, production selector audit.

Ukraine is under attack from Russia, so that makes sense. But if this chart does not raise an eyebrow about the policy, I’ve got more to come.

Apart from Georgia, Armenia receives the same “Unable to verify” response. On August 8, NVIDIA announced that Armenia had opened the CIS region’s largest AI factory, built on NVIDIA infrastructure. Firebird plans to deploy more than 70,000 NVIDIA Rubin and Blackwell GPUs and 300 megawatts of AI capacity there by the end of 2027, and NVIDIA says it intends to invest in the company.

Armenia is on the path of becoming a regional hub for tens of thousands of NVIDIA GPUs running the “dangerous models” that Armenians can not use for defensive purposes. Please make that make sense.

Reverification

I previously had TAC (Trusted Access for Cyber). I had submitted my government ID and biometric data through Persona, been approved, and continued doing defensive security work with slightly fewer classifier false positives.

And fewer is an important detail - TAC does not remove guardrails, you still have to dance with the classifiers quite a bit to make them perform defensive cybersecurity work.

And these classifiers are aggressive. OpenAI presents this message when classifier trips:

This content can’t be shown

We take extra caution with cybersecurity requests. If you’re a security professional, you may be able to apply for Trusted Access.

Screen: Codex refusal message, GitHub issue 35829

The Codex app refusal banner with the Trusted Access link

Claude from Anthropic will do:

API Error: Opus 4.8’s safeguards flagged this message. Our intentionally broad safeguards allow us to deliver more capabilities faster, but can sometimes flag legitimate cybersecurity work. Apply to the Cyber Verification Program to reduce these interruptions. Send feedback with /feedback or learn more: https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude

Screen: Claude Code refusal message, GitHub issue 86050

The Claude Code refusal in a terminal, pointing at the Cyber Verification Program

Don’t even ask about Fable.

Both companies have reasons to be careful. OpenAI and Anthropic have disclosed cases where models in badly configured cyber evaluations reached real systems outside their assigned scope. OpenAI reported incidents involving GPT-5.6 Sol and other models. Anthropic later found three incidents involving Claude.

On August 19, 2026, my access disappeared. OpenAI Developers said a “technical issue” had deactivated Daybreak Blue for a limited set of users and that they would need to verify again.

OpenAI Developers’ August 19 technical-issue announcement

I went to chatgpt.com/cyber, submitted my documents, scanned my face, and sent the information to Persona again. OpenAI returned this:

Trusted Access for Cyber reporting that identity could not be verified or the account was ineligible

Different browser, same error. Different device, same error. Then the flow stopped opening. It reopened after roughly 24 hours and accepted more document and face captures. By then I had made eight attempts across three browser and device paths. Persona must be very happy.

With identifiers removed:

{
  "metadata": {
    "verification_status": "failed",
    "finalized_at": "2026-08-20T20:12:13Z"
  },
  "id_verification": {
    "verification_status": "failed"
  },
  "aas": {
    "status": true
  },
  "individual_eligibility_status": "eligible",
  "plan_type": "pro",
  "plan_eligible": true
}

OpenAI marked verification as failed while reporting that the individual and plan were eligible. Support initially treated it as a technical problem. Then, on August 25, it sent the decisive answer:

I replied that their system had prevented the flow from completing. Support clarified that my “verification information was submitted.” It could not explain the outcome, reset the process, or offer an appeal.

That was the team OpenAI said was “on standby to help.”

The complete redacted correspondence is public.

As of August 27, 2026, the OpenAI Community thread about disappearing access had 60 posts. Other previously approved users reported the same eligibility discrepancy and lockout.

I opened the verification flow from a fresh account. The new gate failed immediately after I selected Georgia. That led to the 250-entry audit.

For every country entry, the recorder selected the option, pressed Select, captured the exact Persona transition request and response, saved the before-and-after screenshots, and returned back.

The complete audit repository contains the sanitized transition evidence, all 1,250 screenshots, the country map, population and sanctions enrichment, comparison with OpenAI’s public ChatGPT access list.

1996 to the rescue

After a few hours of digging (and a lot of AI-assisted research & automation, of course), I found the pattern.

It’s in a document written 30 years ago. What is there not to love about a table row that can predict that LLMs will be hacking machines autonomously!

The US Bureau of Industry and Security places 24 destinations in and 20 in . There are 35 distinct entries between them. OpenAI’s selector contained all 35.

Where OpenAI sells ChatGPT and refuses to verify a cyber defender

44 countries and territories where OpenAI offers ChatGPT and accepts no ID for cyber verification.

United Arab Emirates · AEAfghanistan · AFAlbania · ALArmenia · AMAngola · AOAntarctica · AQArgentina · ARAustria · ATAustralia · AUAzerbaijan · AZBosnia and Herzegovina · BABangladesh · BDBelgium · BEBurkina Faso · BFBulgaria · BGBurundi · BIBenin · BJBrunei Darussalam · BNBolivia · BOBrazil · BRBahamas · BSBhutan · BTBotswana · BWBelarus · BYBelize · BZCanada · CACongo, The Democratic Republic of the · CDCentral African Republic · CFCongo · CGSwitzerland · CHCôte d'Ivoire · CIChile · CLCameroon · CMChina · CNColombia · COCosta Rica · CRCuba · CUCyprus · CYCzechia · CZGermany · DEDjibouti · DJDenmark · DKDominican Republic · DOAlgeria · DZEcuador · ECEstonia · EEEgypt · EGWestern Sahara · EHEritrea · ERSpain · ESEthiopia · ETFinland · FIFiji · FJFalkland Islands (Malvinas) · FKFrance · FRGabon · GAUnited Kingdom · GBGeorgia · GEGhana · GHGreenland · GLGambia · GMGuinea · GNEquatorial Guinea · GQGreece · GRGuatemala · GTGuinea-Bissau · GWGuyana · GYHonduras · HNCroatia · HRHaiti · HTHungary · HUIndonesia · IDIreland · IEIsrael · ILIndia · INIraq · IQIran · IRIceland · ISItaly · ITJamaica · JMJordan · JOJapan · JPKenya · KEKyrgyzstan · KGCambodia · KHNorth Korea · KPSouth Korea · KRKuwait · KWKazakhstan · KZLao People's Democratic Republic · LALebanon · LBSri Lanka · LKLiberia · LRLesotho · LSLithuania · LTLuxembourg · LULatvia · LVLibya · LYMorocco · MAMoldova · MDMontenegro · MEMadagascar · MGNorth Macedonia · MKMali · MLMyanmar · MMMongolia · MNMauritania · MRMalawi · MWMexico · MXMalaysia · MYMozambique · MZNamibia · NANew Caledonia · NCNiger · NENigeria · NGNicaragua · NINetherlands · NLNorway · NONepal · NPNew Zealand · NZOman · OMPanama · PAPeru · PEPapua New Guinea · PGPhilippines · PHPakistan · PKPoland · PLPuerto Rico · PRPalestine, State of · PSPortugal · PTParaguay · PYQatar · QARomania · ROSerbia · RSRussian Federation · RURwanda · RWSaudi Arabia · SASolomon Islands · SBSudan · SDSweden · SESlovenia · SISlovakia · SKSierra Leone · SLSenegal · SNSomalia · SOSuriname · SRSouth Sudan · SSEl Salvador · SVSyrian Arab Republic · SYEswatini · SZChad · TDFrench Southern Territories · TFTogo · TGThailand · THTajikistan · TJTimor-Leste · TLTurkmenistan · TMTunisia · TNTürkiye · TRTrinidad and Tobago · TTTaiwan · TWTanzania · TZUkraine · UAUganda · UGUnited States · USUruguay · UYUzbekistan · UZVenezuela · VEVietnam · VNVanuatu · VUKosovo · XKYemen · YESouth Africa · ZAZambia · ZMZimbabwe · ZW

Arrow keys move between the countries in the view on screen. Home and End jump to the first and last.

Forty-two selector entries are outside OpenAI’s official ChatGPT list. The map draws them as places ChatGPT is not sold and the comparison leaves them out. Fourteen blocked markets have no polygon in this 110m geometry. Macao, one of the export-list entries, has none either. They keep their records and their place in the counts, and no shape lights up for them. Population is the UN estimate for 2023, matched to 237 of the 250 selector entries.

Sources: BIS country groupsproduction selector auditUN population estimates

Perfect match - all 35 unsupported with zero supported entries belonging in either group.

D:1 contains the countries that had looked particularly strange in the audit: Georgia, Armenia, Azerbaijan, Moldova, Mongolia, all five Central Asian states, Vietnam, China, and Russia, the state occupying Georgia’s territories.

There are also other pecularities in there - eleven French-associated entries fail while France works. Aruba fails while Curaçao works. Perhaps someone else can explain these anomalies, I’m going to focus on the D-flags.

Some of you are probably already thinking: “D:1? National Security? Of course that country should be banned.” But that D:1 row was never really written for independent Georgia - it was inherited from Soviet Union.02

OpenAI’s or in between D:1, D:5 puts Georgia in the group of Iran and North Korea.

Cyber-capable models are dangerous. That part is true. BIS created ACE because these tools can be used for surveillance, espionage, and actions that disrupt, deny, or degrade networks and devices. So I can understand the intent.

The problem is who this gate actually stops, and it’s not the adversaries. Adversaries already use these models and route around access gates. The attackers I defend against do not queue politely at Persona with their real government IDs, turning their heads slowly to the left and right.

I did (8 times).

Now let’s look at the rule.

15 CFR § 742.4 says the general policy for D:1 applications is to approve them case by case when the items are for civilian use or would not significantly contribute to the destination’s military potential. The same section gives Kazakhstan and Mongolia “enhanced favorable consideration licensing treatment.”

OpenAI blocks Georgia, Kazakhstan, and Mongolia at the country selector.

In 1996, Georgia had reclaimed its independence five years earlier after seven decades of Soviet rule. It was emerging from overlapping conflicts: a civil war over control of the central government and wars in the Georgian regions of Abkhazia and South Ossetia. The World Bank describes the period after independence as one of economic crisis, a sharp and protracted fall in output, and hyperinflation.

But Georgia for which the rule was made for does not exist anymore.

Thirty years later, Georgia has moved from state and economic collapse to 57th place on UNDP’s Human Development Index. NATO lists it as one of four Enhanced Opportunity Partners, alongside Australia, Jordan, and Ukraine.

Georgian citizens have had visa-free travel to the Schengen area since 2017, and the EU granted Georgia candidate status in 2023. That relationship has since deteriorated. The EU says the accession process is now effectively halted after serious democratic backsliding.

Georgia’s democracy is sliding, that’s undeniable. I’ve lost nearly every friend I had because they fled the country since we started riding that slide ~3 years ago. Yes, it’s not good.

But denying defensive cybersecurity capabilities to civil society, independent media, and security researchers does not reverse that. On contrary, they become the first in the line of fire.

Besides, 1996 rule gives no Georgia-specific rationale. OpenAI’s gate treats the row it inherited from that moment as a current judgment about every Georgian.

Georgia was already in D:1 when the State Department approved a possible Javelin sale worth up to $75 million in 2017. Georgia bought the system. Its defense minister later confirmed that it had been fully delivered.

Washington looked at D:1 Georgia in 2017, ran the case-by-case review the rule actually prescribes, and approved the missiles. OpenAI looked at the same row and that was all that it needed to know about me.

And I’m not saying that Javelins or tanks are more dangerous than cyber-capable models. In fact, I believe quite the opposite. But the D table gets worse:

D:2 is Nuclear. D:3 is Chemical and Biological. D:4 is Missile Technology. Israel and Pakistan are in all three and both pass OpenAI’s gate.

The relevant cyber rule is 15 CFR § 740.22, License Exception Authorized Cybersecurity Exports. For non-government users in D:1 and D:5, its restrictions have exceptions for vulnerability disclosure, cyber incident response, deemed exports, and specified favorable-treatment users. The rule also says other license exceptions may remain available.

Those exceptions cover the kind of work Trusted Access supposedly exists for. OpenAI says the program supports security education, defensive programming, and responsible vulnerability research.

The country gate asks about none of them. In fact, I sent OpenAI Support my credentials and explained the work:

OpenAI Support replied:

The full redacted transcript is public.

I think I clearly remember OpenAI’s public stance sounded quite different from this.

OpenAI’s policy

Fouad Matin of OpenAI’s cyber preparedness team wrote:

Trusted access isn’t limited to US/EU.

We believe cyber capabilities should be broadly available with appropriate safeguards.

Statement: Fouad Matin, OpenAI cyber preparedness team, post on X

The statement that Trusted Access is not limited to the US and EU

OpenAI’s published policy says the same thing. It says access should use clear, objective criteria such as kyc and identity verification, and should depend on the user, trust signals, intended use, and access level. OpenAI’s Daybreak overview says individual eligibility is evaluated using identity and trust verification, risk considerations, intended use, and the applicant’s ability to strengthen the cybersecurity ecosystem. I may not be well known to people outside Georgia, but I may know a person or two who will attest that I’ve put a block or two in strengthening Georgian cybersecurity ecosystem.

In practice, the new country gate controls eligibility before any of those criteria. It knows the issuing country of the applicant’s government ID and that’s enough. It does not evaluate their work, authorization, intended use, or trust signals - even when you proactively provide them.

Georgia’s defenders protect civil society from the state occupying their country and attacking its digital infrastructure.

OpenAI’s D:1 gate gets the final word before any individual trust assessment.

Questions to OpenAI

  1. Why did OpenAI turn D:1 or D:5 membership into a categorical individual access rule that ACE does not require?
  2. Why is the supported-country list hidden inside a biometric verification flow?
  3. Why did OpenAI tell users affected by its own technical issue to verify again, collect repeated document and face captures, call the failures technical, and only later move the block to Persona’s country selector?
  4. Why is there no correction, retry, or appeal path? And why is government-ID the only information OpenAI takes into account?

Gates like this have a track record. OpenAI has never officially served mainland China, yet the models are still in heavy use there. What the restriction produced was a grey market, with brokered tokens by people who not once submitted any ID anywhere. They remove capabilities from hands of defenders, and move access of adversaries to a place where nobody is watching.

AI gates keep honest people out.

I don’t believe verified access works either, but I can live with that compromise. At the very least, OpenAI must publicly declare why these rules were introduced, and where exactly are users supposed to supply information so that they are “evaluated using identity”.