OpenAI · Usage Policies · View original document ↗

Cybersecurity Dual-Use Restrictions

Medium severity Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity OpenAI recorded 28 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for OpenAI Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.

This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The provision operationalizes a dual-use control framework that distinguishes between authorized and prohibited cybersecurity applications. This establishes OpenAI's policy stance that certain security-related uses are permissible while others involving unauthorized system compromise remain restricted, requiring OpenAI to evaluate requests against these categories.

Clause Stability Stable

0
Changes
3
Months Monitored
Apr 9, 2026
First Seen
Apr 10, 2026
Last Seen
This clause type exists across 560 other provisions on other platforms.

Consumer impact (what this means for users)

Users are authorized to use the models for specified security purposes (research, CTF participation, penetration testing, security tool development) but are prohibited from using models to develop cyberweapons or malicious code. The terms require users to ensure their use aligns with this authorization framework, with the determination of whether a request constitutes authorized security work or prohibited malicious activity subject to OpenAI's evaluation.

How other platforms handle this

Wise Medium

You may not use our Services for any illegal purpose or in violation of any laws or regulations. You may not use the Services to send money to sanctioned countries or individuals on government watchlists. You may not use the Services for gambling, illegal drugs, weapons, or any other prohibited acti...

TaskRabbit Medium

Subject to your compliance with the terms of the Agreement (including, without limitation, these Terms and Taskrabbit's Acceptable Use Policy), Taskrabbit grants you a limited, non-exclusive, non-transferable and revocable license to (a) access and use the Platform (in the locations and territories ...

Stripe Medium

Pharmacies and the sale of prescription drugs, as well as the sale of substances that mimic the effects of illegal drugs, sale of drug paraphernalia, and related items are among the categories restricted or prohibited from using Stripe's services.

See all platforms with this clause type →

Monitoring

OpenAI has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
We don't want our models to be used to create cyberweapons or malicious code that could cause significant damage if deployed. We want to support the security community through education about attack techniques and defenses, helping with CTFs and security research, assisting with penetration testing, and building tools that improve security. However, we need to balance this with the risk that this same assistance could be used to compromise systems, networks, and devices without appropriate authorization.

— Excerpt from OpenAI's Usage Policies

Applicable regulations

CFAA
United States Federal
DMCA
United States Federal
DSA
European Union
Trump Executive Order on AI Policy Framework
US

Provision details

Document information
Document
Usage Policies
Entity
OpenAI
Document last updated
March 5, 2026
Tracking information
First tracked
March 10, 2026
Last verified
May 12, 2026
Record ID
CA-P-002435
Document ID
CA-D-00005
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d69a24617758e5b44e4be8eedeceb598a26dc4e280f2ab1469a45b64203e7403
Analysis generated
March 10, 2026 03:28 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: OpenAI
Document: Usage Policies
Record ID: CA-P-002435
Captured: 2026-03-10 03:28:59 UTC
SHA-256: d69a24617758e5b4…
URL: https://conductatlas.com/platform/openai/usage-policies/cybersecurity-dual-use-restrictions/
Accessed: June 18, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does OpenAI's Cybersecurity Dual-Use Restrictions clause do?

The provision operationalizes a dual-use control framework that distinguishes between authorized and prohibited cybersecurity applications. This establishes OpenAI's policy stance that certain security-related uses are permissible while others involving unauthorized system compromise remain restricted, requiring OpenAI to evaluate requests against these categories.

How does this clause affect you?

Users are authorized to use the models for specified security purposes (research, CTF participation, penetration testing, security tool development) but are prohibited from using models to develop cyberweapons or malicious code. The terms require users to ensure their use aligns with this authorization framework, with the determination of whether a request constitutes authorized security work or prohibited malicious activity subject …

Is ConductAtlas affiliated with OpenAI?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.