Codex App: TAC(Trusted Access for Cyber) cannot be started, cybersecurity-risk block is sticky

Open
#34,236 2 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
25/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet

Research direction

Reproduce the flow in the Codex App on Microsoft Windows using the listed steps, then open https://chatgpt.com/cyber and record the verification failure. Use the provided session/work ID when tracing or reporting the issue; done means normal conversations are no longer repeatedly blocked or the TAC verification flow completes for eligible accounts.

Written by the indexing model from the issue text.

Description

app bug safety-check windows-os
What version of the Codex App are you using (From “About Codex” dialog)?

Version 26.715.31925

What subscription do you have?

ChatGPT Pro (individual)

What platform is your computer?

Microsoft Windows NT 10.0.26200.0 x64

What issue are you seeing?

Even after normal usage, the app repeatedly shows cybersecurity-risk blocking prompts.
Attempting to follow the remediation path at https://chatgpt.com/cyber fails with error messages instead of allowing verification.

Full message examples (PII redacted):

  • "Your conversations have multiple flags for possible cybersecurity risk."
  • "Could not start verification. You may not be eligible for this verification flow right now."
  • "Your identity could not be verified or your account is ineligible at this time."

This blocks normal workflow even for standard, non-offensive tasks (web/page maintenance, automation, coding, devops, server management on owned systems).

What steps can reproduce the bug?
  1. Sign in with a ChatGPT Pro account in Codex (desktop/app).
  2. Start normal development/maintenance conversation.
  3. Observe repeated cybersecurity-risk warnings and/or blocked responses.
  4. Open the Trusted Access for Cyber page link (https://chatgpt.com/cyber).
  5. Click through and attempt verification.
  6. Verification fails with one of:
    • "Could not start verification. You may not be eligible for this verification flow right now."
    • "Your identity could not be verified or your account is ineligible at this time."
  7. Repeat conversations remain blocked/flagged.
    Session id / work id: 019f7c4c-144f-75f3-890c-bbe4b07fc979
    Token/context details: Issue appears immediately; not related to token limit exhaustion.
What is the expected behavior?

Normal usage should continue with only expected safety checks, or
TAC verification flow should be available and complete successfully for eligible accounts.

Additional information

This appears to be a false-positive/eligibility dead-end loop.
Existing remediation path is effectively unreachable.
No new code execution or exploit behavior is involved; this is a workspace availability/security-classifier flow issue.
I can provide screenshots or additional IDs if needed.

Dominant language
Rust
Stars
125k
Forks
19.5k
Avg merge
1m
Merged PRs (30d)
1k

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from openai/codex

All issues in openai/codex

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.