Papers, please.
In August 2026, OpenAI quietly added a country gate to cyber verification. It
now blocks 44 countries and territories where it
officially offers ChatGPT.
Its
Combined population of affected 44 markets: ~650,000,000 people. This is excluding markets where ChatGPT is officially unavailable anyway (include those and the total comes out to ~2,420,000,000 people, with population data available for 61 of the 73 entries).
The new gate appeared with OpenAI’s
August 19 “technical issue”.
By then, OpenAI had already approved my Georgian government ID and granted me
But fear not: OpenAI said affected users had been emailed a path for verification and its teams were “on standby to help.” More on that standby later.
The Persona flow then repeatedly collected my Georgian ID and face data.
The UN Human Development Index places Georgia in the “very high human development” group, 57th out of 193. It is also where I build open-source security tooling for civil society groups, independent media, and activists dealing with commercial and state-controlled spyware.
OpenAI’s Trusted Access for Cyber program is supposedly made for people doing this work.
A week later, OpenAI likely figured out they forgot to update Persona template, so now it bans you at that step. Can’t complain, at least now it stops me before I submit my biometric data for a ninth time.
If you select Georgia in the Persona widget and press Select. The transition response now contains an empty list of accepted ID classes. The screen says:
Unable to verify
We are unable to verify identities in this country. Please select another country.
73 countries without cyber
Screen recording · run openai-cyber-media3-20260827
Entry on screen
GEGeorgia
official ChatGPT marketD:1
still frameat 2:21
44 of the 73 entries are markets where OpenAI officially sells ChatGPT. 35 sit in Country Group D:1 or D:5 of the 1996 US export list.
The country gate
I quickly checked whether the US had imposed some new country-level sanctions on Georgia that I had somehow missed. Nothing.
A new US export-control rule that explained it? Nothing there either.
Maybe the documents themselves? Some IDs really are too weak to verify.
Not these. The new-generation Georgian biometric passport and ID card, in circulation since 2025, won “Best New ID Document Series” at High Security Printing EMEA 2026 in Rabat this February. Georgia has participated in the ICAO Public Key Directory, the repository border authorities use to cryptographically validate ePassport chips, since May 2016: before Italy, Croatia, Serbia, Mexico, and Saudi Arabia, and a year before the EU itself joined as an entity. Document security, biometrics included, was one of the four blocks the European Commission signed off in 2015 before proposing Schengen visa-free travel. And Persona had verified this exact ID when OpenAI approved my Trusted Access in the first place.
So I tested all 250 enabled entries in the new production country gate to see what was going on.
Seventy-three returned no accepted government ID class. Forty-four are places where OpenAI officially says ChatGPT is available.
So you can use your OpenAI subscription, but we don’t trust where your ID is from, so no more cyber defense capabilities for you.
Here’s what came back:
- Selector entries tested
- 250
- Cyber verification supported
- 177
- Cyber verification unsupported
- 73
- Entries on OpenAI's ChatGPT access list
- 208
- Listed for ChatGPT but cyber unsupported
- 44
I then ran all 250 entries against OpenSanctions. Their data is amazing. Thank you to everyone who maintains it.
Only two of the 44 official ChatGPT markets blocked by cyber verification matched an active US sanctions program under the audit’s documented filter. Sanctions were not the pattern.
I expected China to fail because OpenAI does not officially offer ChatGPT there, and many other reasons. But Georgia? Armenia? Azerbaijan? Moldova, Mongolia, and all five Central Asian states? That was weird.
Georgia
I live in Georgia, and this affects me personally, so I’m obviously biased here. I also have a pile of evidence that this is insane.
The new gate gives Georgia and the Russian Federation the same answer. Georgia is on OpenAI’s official ChatGPT access list and had no active US sanctions program matched by the audit’s documented filter. Russia is absent from that list and had three matched programs.
This gate is wrong for every name in the dropdown. But someone whose country Russia is not occupying can make that case for Russia specifically. I won’t do that work.
Russia invaded Georgia in 2008 and continues to occupy 20 percent of its territory. In October 2019, Russia’s GRU carried out large-scale disruptive cyberattacks against Georgia. The attacks hit Georgian government, court, NGO, media, and business websites and interrupted several national broadcasters. The UK called them part of Russia’s long-running campaign of hostile and destabilizing activity against Georgia.
OpenAI’s own threat reporting says it terminated accounts associated with Russia-affiliated Forest Blizzard after the group used its services for research into satellite communications and radar imaging, and for scripting support.
Assuming Russian security services still have access to OpenAI models, that’s a lot of vulnerable persons and organizations left without state-of-the-art defensive capabilities. If you think they don’t, you haven’t been paying attention to tokeneconomics lately. They are free to target me and other Georgians, but I can’t prompt Codex to say:
GPT-5.6-Sol Max Ultra, help, Russian GRU is using OpenAI models to attack me, find the vulnerabilities in my system
Or maybe it’s OpenAI’s own model crossing its evaluation boundary and exploiting a real website that decided to target my systems?
Because that will undoubtedly trigger an automated refusal. Ironically, it will also say that I can apply for Trusted Access.
I can’t. But I’m going to show you who can - people in nine of the world’s top fifteen cybercrime bases!
OpenAI accepts IDs from nine of the top 15 cybercrime bases
OpenAI sells ChatGPT in Georgia, Armenia, and Azerbaijan, and refuses to verify anyone in all three. It verifies people in Ukraine, Nigeria, and Romania.
Rank 1 is the highest estimated concentration of cyber offenders in the 2024 World Cybercrime Index.
OpenAI refuses these three
- #52Armenia
- #66Georgia
- #87Azerbaijan
OpenAI verifies these nine
- #2Ukraine
- #4United States
- #5Nigeria
- #6Romania
- #8United Kingdom
- #9Brazil
- #10India
- #13Ghana
- #14South Africa
Ukraine is under attack from Russia, so that makes sense. But if this chart does not raise an eyebrow about the policy, I’ve got more to come.
Apart from Georgia, Armenia receives the same “Unable to verify” response. On August 8, NVIDIA announced that Armenia had opened the CIS region’s largest AI factory, built on NVIDIA infrastructure. Firebird plans to deploy more than 70,000 NVIDIA Rubin and Blackwell GPUs and 300 megawatts of AI capacity there by the end of 2027, and NVIDIA says it intends to invest in the company.
Armenia is on the path of becoming a regional hub for tens of thousands of NVIDIA GPUs running the “dangerous models” that Armenians can not use for defensive purposes. Please make that make sense.
Reverification
I previously had TAC (Trusted Access for Cyber). I had submitted my government ID and biometric data through Persona, been approved, and continued doing defensive security work with slightly fewer classifier false positives.
And fewer is an important detail - TAC does not remove guardrails, you still have to dance with the classifiers quite a bit to make them perform defensive cybersecurity work.
And these classifiers are aggressive. OpenAI presents this message when classifier trips:
This content can’t be shown
We take extra caution with cybersecurity requests. If you’re a security professional, you may be able to apply for Trusted Access.

Claude from Anthropic will do:
API Error: Opus 4.8’s safeguards flagged this message. Our intentionally broad safeguards allow us to deliver more capabilities faster, but can sometimes flag legitimate cybersecurity work. Apply to the Cyber Verification Program to reduce these interruptions. Send feedback with /feedback or learn more: https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude

Don’t even ask about Fable.
Both companies have reasons to be careful. OpenAI and Anthropic have disclosed cases where models in badly configured cyber evaluations reached real systems outside their assigned scope. OpenAI reported incidents involving GPT-5.6 Sol and other models. Anthropic later found three incidents involving Claude.
On August 19, 2026, my access disappeared. OpenAI Developers said a “technical issue” had deactivated Daybreak Blue for a limited set of users and that they would need to verify again.

I went to chatgpt.com/cyber, submitted my documents, scanned my face, and sent
the information to Persona again. OpenAI returned this:

Different browser, same error. Different device, same error. Then the flow stopped opening. It reopened after roughly 24 hours and accepted more document and face captures. By then I had made eight attempts across three browser and device paths. Persona must be very happy.
With identifiers removed:
{
"metadata": {
"verification_status": "failed",
"finalized_at": "2026-08-20T20:12:13Z"
},
"id_verification": {
"verification_status": "failed"
},
"aas": {
"status": true
},
"individual_eligibility_status": "eligible",
"plan_type": "pro",
"plan_eligible": true
}
OpenAI marked verification as failed while reporting that the individual and plan were eligible. Support initially treated it as a technical problem. Then, on August 25, it sent the decisive answer:
The information provided indicates that you completed the verification flow. However, completing the flow does not mean that verification was approved.
At this time, Trusted Access for Cyber verification does not support retries or appeals.
I replied that their system had prevented the flow from completing. Support clarified that my “verification information was submitted.” It could not explain the outcome, reset the process, or offer an appeal.
That was the team OpenAI said was “on standby to help.”
The complete redacted correspondence is public.
As of August 27, 2026, the OpenAI Community thread about disappearing access had 60 posts. Other previously approved users reported the same eligibility discrepancy and lockout.
I opened the verification flow from a fresh account. The new gate failed immediately after I selected Georgia. That led to the 250-entry audit.
For every country entry, the recorder selected the option, pressed Select, captured the exact Persona transition request and response, saved the before-and-after screenshots, and returned back.
The complete audit repository contains the sanitized transition evidence, all 1,250 screenshots, the country map, population and sanctions enrichment, comparison with OpenAI’s public ChatGPT access list.
1996 to the rescue
After a few hours of digging (and a lot of AI-assisted research & automation, of course), I found the pattern.
It’s in a document written 30 years ago. What is there not to love about a table row that can predict that LLMs will be hacking machines autonomously!
The
US Bureau of Industry and Security
places 24 destinations in
Where OpenAI sells ChatGPT and refuses to verify a cyber defender
44 countries and territories where OpenAI offers ChatGPT and accepts no ID for cyber verification.
Arrow keys move between the countries in the view on screen. Home and End jump to the first and last.
Forty-two selector entries are outside OpenAI’s official ChatGPT list. The map draws them as places ChatGPT is not sold and the comparison leaves them out. Fourteen blocked markets have no polygon in this 110m geometry. Macao, one of the export-list entries, has none either. They keep their records and their place in the counts, and no shape lights up for them. Population is the UN estimate for 2023, matched to 237 of the 250 selector entries.
Perfect match - all 35 unsupported with zero supported entries belonging in either group.
D:1 contains the countries that had looked particularly strange in the audit: Georgia, Armenia, Azerbaijan, Moldova, Mongolia, all five Central Asian states, Vietnam, China, and Russia, the state occupying Georgia’s territories.
There are also other pecularities in there - eleven French-associated entries fail while France works. Aruba fails while Curaçao works. Perhaps someone else can explain these anomalies, I’m going to focus on the D-flags.
Some of you are probably already thinking: “D:1? National Security? Of course that country should be banned.” But that D:1 row was never really written for independent Georgia - it was inherited from Soviet Union.02
OpenAI’s or in between D:1, D:5 puts Georgia in the group of Iran and North Korea.
Cyber-capable models are dangerous. That part is true. BIS created ACE because these tools can be used for surveillance, espionage, and actions that disrupt, deny, or degrade networks and devices. So I can understand the intent.
The problem is who this gate actually stops, and it’s not the adversaries. Adversaries already use these models and route around access gates. The attackers I defend against do not queue politely at Persona with their real government IDs, turning their heads slowly to the left and right.
I did (8 times).
Now let’s look at the rule.
15 CFR § 742.4 says the general policy for D:1 applications is to approve them case by case when the items are for civilian use or would not significantly contribute to the destination’s military potential. The same section gives Kazakhstan and Mongolia “enhanced favorable consideration licensing treatment.”
OpenAI blocks Georgia, Kazakhstan, and Mongolia at the country selector.
In 1996, Georgia had reclaimed its independence five years earlier after seven decades of Soviet rule. It was emerging from overlapping conflicts: a civil war over control of the central government and wars in the Georgian regions of Abkhazia and South Ossetia. The World Bank describes the period after independence as one of economic crisis, a sharp and protracted fall in output, and hyperinflation.
But Georgia for which the rule was made for does not exist anymore.
Thirty years later, Georgia has moved from state and economic collapse to 57th place on UNDP’s Human Development Index. NATO lists it as one of four Enhanced Opportunity Partners, alongside Australia, Jordan, and Ukraine.
Georgian citizens have had visa-free travel to the Schengen area since 2017, and the EU granted Georgia candidate status in 2023. That relationship has since deteriorated. The EU says the accession process is now effectively halted after serious democratic backsliding.
Georgia’s democracy is sliding, that’s undeniable. I’ve lost nearly every friend I had because they fled the country since we started riding that slide ~3 years ago. Yes, it’s not good.
But denying defensive cybersecurity capabilities to civil society, independent media, and security researchers does not reverse that. On contrary, they become the first in the line of fire.
Besides, 1996 rule gives no Georgia-specific rationale. OpenAI’s gate treats the row it inherited from that moment as a current judgment about every Georgian.
Georgia was already in D:1 when the State Department approved a possible Javelin sale worth up to $75 million in 2017. Georgia bought the system. Its defense minister later confirmed that it had been fully delivered.
Washington looked at D:1 Georgia in 2017, ran the case-by-case review the rule actually prescribes, and approved the missiles. OpenAI looked at the same row and that was all that it needed to know about me.
And I’m not saying that Javelins or tanks are more dangerous than cyber-capable models. In fact, I believe quite the opposite. But the D table gets worse:
D:2 is Nuclear. D:3 is Chemical and Biological. D:4 is Missile Technology. Israel and Pakistan are in all three and both pass OpenAI’s gate.
The relevant cyber rule is 15 CFR § 740.22, License Exception Authorized Cybersecurity Exports. For non-government users in D:1 and D:5, its restrictions have exceptions for vulnerability disclosure, cyber incident response, deemed exports, and specified favorable-treatment users. The rule also says other license exceptions may remain available.
Those exceptions cover the kind of work Trusted Access supposedly exists for. OpenAI says the program supports security education, defensive programming, and responsible vulnerability research.
The country gate asks about none of them. In fact, I sent OpenAI Support my credentials and explained the work:
I’m George Lubaretsi - a cybersecurity specialist and founder of FOI Security […] My open source guides and tools help thousands of Georgian citizens to defend their digital life from adversaries. […] FOI Security received the Democracy Tech Entrepreneur Award at the Copenhagen Democracy Summit 2026 [2]. I previously built open data and accountability infrastructure at Transparency International Georgia.
OpenAI Support replied:
This review is focused on the technical behavior of the verification flow. Support cannot provide additional details about an individual verification decision or manually override its outcome.
No further verification attempts or professional credentials are needed from you at this stage.
The full redacted transcript is public.
I think I clearly remember OpenAI’s public stance sounded quite different from this.
OpenAI’s policy
Fouad Matin of OpenAI’s cyber preparedness team wrote:
Trusted access isn’t limited to US/EU.
We believe cyber capabilities should be broadly available with appropriate safeguards.

OpenAI’s published policy says the same thing. It says access should use clear, objective criteria such as kyc and identity verification, and should depend on the user, trust signals, intended use, and access level. OpenAI’s Daybreak overview says individual eligibility is evaluated using identity and trust verification, risk considerations, intended use, and the applicant’s ability to strengthen the cybersecurity ecosystem. I may not be well known to people outside Georgia, but I may know a person or two who will attest that I’ve put a block or two in strengthening Georgian cybersecurity ecosystem.
In practice, the new country gate controls eligibility before any of those criteria. It knows the issuing country of the applicant’s government ID and that’s enough. It does not evaluate their work, authorization, intended use, or trust signals - even when you proactively provide them.
Georgia’s defenders protect civil society from the state occupying their country and attacking its digital infrastructure.
OpenAI’s D:1 gate gets the final word before any individual trust assessment.
Questions to OpenAI
- Why did OpenAI turn D:1 or D:5 membership into a categorical individual access rule that ACE does not require?
- Why is the supported-country list hidden inside a biometric verification flow?
- Why did OpenAI tell users affected by its own technical issue to verify again, collect repeated document and face captures, call the failures technical, and only later move the block to Persona’s country selector?
- Why is there no correction, retry, or appeal path? And why is government-ID the only information OpenAI takes into account?
Gates like this have a track record. OpenAI has never officially served mainland China, yet the models are still in heavy use there. What the restriction produced was a grey market, with brokered tokens by people who not once submitted any ID anywhere. They remove capabilities from hands of defenders, and move access of adversaries to a place where nobody is watching.
AI gates keep honest people out.
I don’t believe verified access works either, but I can live with that compromise. At the very least, OpenAI must publicly declare why these rules were introduced, and where exactly are users supposed to supply information so that they are “evaluated using identity”.
