Part two of: OpenAI Says Verified Defenders Get More Access. I'm Going to Test That.

Part I started because I got refused.

Not in a dramatic way. I was doing authorized defensive work, and the model wouldn't follow me into it. Twice, across two providers. The question I actually asked — the one that turned into a research lane — wasn't why did this happen to me. It was narrower and more annoying: what is the threshold? Somebody decided where the line sits. I wanted to know who, and on what basis.

Part I built an instrument to measure that, published the design, and watched it fail its first independent break before collecting a single data point.

Part I also ended with a promise: