Paper No. 01 · 4 September 2026

The allowlist and the register

Every capability market eventually gates access on trust. The question is never whether someone will vouch. It is whether anyone else can check.

1. What prompted this

In September 2026 OpenAI announced Daybreak, a cybersecurity programme granting bounded access to a specialised model to vetted organisations, who embed it in defensive security products. More than twenty of the largest security vendors in the world are named partners. Access runs through a mechanism called Trusted Access, which evaluates applicants on “identity and trust verification, risk considerations, the intended use case,” sorts approved parties into two tiers, and states plainly that “approval is not automatic.”

We think this is a reasonable thing for a model provider to build, and from what is published, a carefully built one. Bounding a dangerous capability to parties who have been looked at is better than not doing so. Nothing in this paper argues that Daybreak is badly designed.

This paper argues that it is a different instrument from the one this Registry exists to be, that the difference is structural rather than a matter of quality, and that both will be needed.

2. The shape of a private allowlist

Strip away the specifics and the mechanism is old and well understood. One party holds something valuable. It decides, case by case, whom to give it to. It records that decision in its own systems. The decision can be revised at any time, for any reason, and the revision is announced to nobody.

That instrument is good at things a register is bad at. It is fast: an approval takes as long as the approver wants it to take. It is precise: the grantor can see exactly how its own capability is being used, because the telemetry is its own. And it is immediately enforceable: a provider can withdraw access in seconds, which no third-party body can do to anyone.

Those are real advantages and they are not available to us.

3. What the shape cannot do

Four limits follow from the structure itself, not from any failing of the people running it.

The vetted unit is not the acting unit. A programme of this kind approves an organisation. But organisations do not send payments, delete tables, or message customers — agents do. Approving a company says something true and useful about that company’s people, processes, and intentions. It says nothing about the particular agent that ran in a particular customer’s environment on a particular Tuesday, which is the unit that acts and the unit an auditor asks about.

The status does not travel. If a vendor is approved, that vendor’s customer cannot verify it. There is no reference to cite, no record to read, no way to distinguish a current approval from a lapsed one. The customer takes the vendor’s word, or the provider’s. A trust claim that its own beneficiary is the only practical source of is not doing the work trust claims are for.

Nobody outside can check it, so nobody outside can rely on it. There is no published criteria threshold, no register of who currently holds the status, no stated revocation process, and no independent audit. That is not a criticism of the vetting, which may well be rigorous. It is an observation that rigour nobody can inspect is indistinguishable, from outside, from rigour nobody performed.

It stops at the edge of one provider. This is the limit that will matter most, soonest. Real fleets are already multi-model: a firm runs one provider’s model for reasoning, another’s for code, a third for cost, and switches between them by the quarter. Per-provider trust produces a fleet holding several partial statuses and no whole one, each issued by a party that can only speak about its own share. The agent is the thing that acted. No provider is positioned to describe it.

4. There is a precedent, and it is exact

Marine insurance solved this problem, badly at first and then well, over about seventy years.

The bad version was the private book. Every underwriter at Edward Lloyd’s coffee house kept his own notes on which vessels he would cover. Each assessment was made from scratch by each underwriter; none of it was portable; a shipowner’s good standing with one party bought nothing with the next. The information existed. It simply could not move.

In 1760 the customers of that coffee house formed a society to keep a shared register, employing retired sea captains to survey vessels at sixteen ports. The first surviving Register dates from 1764. The innovation was not better judgement than the individual underwriters had been exercising. The innovation was publication.

Then it broke, in the most instructive way available. In 1799 a dispute over classification method split the enterprise in two: shipowners published their own register, bound in red, and underwriters kept the green one. Each book was produced by a party with a direct interest in what it said. Shipowners believed the underwriters’ book graded their vessels harshly; underwriters believed the shipowners’ book flattered them. Both were probably right, and it did not matter which, because neither book could be believed by the side that had not written it.

The two registers ran in competition for thirty-five years. The resolution, in 1834, was not that one side won. It was a single society reconstituted so that no one interest owned it — the arrangement that has governed ship classification ever since.

The lesson is narrow and worth stating exactly: the thing that made classification useful was never the surveying. It was that the surveyor was structurally incapable of being leaned on by the party being surveyed.

5. What this Registry has done about itself

An argument of this kind is worth very little from a party that has not accepted its own constraint. So on the day this paper was written we added a clause to our own Rules, in force on publication:

G3.1 — The Registry accepts no discretionary, revocable or unpublished benefit from any party in the supply chain of the subjects it classifies — model providers, infrastructure providers, and tooling vendors alike. This includes preferential access programmes, trusted-partner status, and any standing granted at another party’s sole discretion. A registry whose own standing can be withdrawn by a party it rates cannot publish an adverse finding that a reader has any reason to believe.

Two things about it matter more than the sentiment.

The first is that the line is discretion, not money. G3.2 says so explicitly: we buy models, hosting and services at published market terms like any other customer, and being a paying customer is not a relationship this restricts. A price anyone can pay is a transaction. A status only some are granted is a favour, and only one of the two can be quietly taken away.

The second is that G3.3 binds it for every provider without exception, including the ones we presently run on and depend on. This Registry is built with tooling from companies whose customers’ agents it may one day classify. A rule of this kind is worth publishing only where it costs something; applied to a competitor and not to a dependency, it would be marketing, and a reader would spot that faster than we could write it.

It is published with a number, in the same rulebook that binds our members, and if we ever breach it that is a correction we owe the public record under G1.3 — which is a materially different thing from quietly changing our minds.

6. What this paper is not

It is not a finding about Daybreak or any other programme. We have surveyed nothing and observed nothing, and the Rules do not permit us to characterise what we have not examined.

It is not a claim that provider programmes should not exist. Instant revocation of a dangerous capability is something only a provider can do, and we would rather providers did it.

And it is not a track record. This Registry is young. It classifies a small number of agents, its demonstration fleet is larger than its membership, and every figure it publishes about itself is designed to make that obvious rather than to obscure it. The argument here is structural, and structural arguments are cheap until somebody has operated under them for a while. We have published the rule we will be held to. That is the beginning of the case, not the end of it.

7. The one-sentence version

A provider can tell you it trusts a company. Only an independent register can tell a third party what an agent did, in terms that party can check without asking either of us.

Sources: OpenAI, Daybreak programme and partner listing, and the Trusted Access overview, September 2026. Lloyd’s Register Foundation, Our history, for the 1760 society, the 1764 Register, the 1799 division into the shipowners’ and underwriters’ registers, and the 1834 reconstitution. The clauses cited are published in full at Rules Part G and in rules.json.