Flagged accounts - larger concerns

Resolved 💬 4 comments Opened Feb 18, 2026 by hexvy Closed Feb 20, 2026

I am aware that there is a known issue, but hear me out.

Yes, I got:

⚠ Your account was flagged for potentially high-risk cyber activity and this request was routed to gpt-5.2 as a fallback. [...]

emitted when using GPT-5.2. I am aware this is a known bug. Thread ID 019c6e33-83f7-70b1-8ea1-aa00295f07c0

But there are larger issues with the entire idea.

1. Why are Business accounts even allowed to start the Persona verification process if they are not eligible?

At first, it seemed like I am, being a contractor to a company that owns the account, being required to submit my ID to access company-owned ChatGPT, which obviously would be a terrible idea so I see why this is not allowed and makes little sense. I actually tried to do that just to test things out, and found out that the account is "ineligible" -- so the first issue is lack of clarity regarding eligibility. Is it really hard to hide a button when logged with an account that is not eligible?

2. What is the avenue for small and medium sized business to litigate?

Vagueness of "high-risk cyber activity" is the core issue here, because it is impossible to litigate when there is no definition for what it means for work to be "high-risk cyber activity". Does regularly asking "are there security issues in my code" constitutes a criteria for "high-risk cyber activity" flagging? This policy leaves no rigorous way nor documents an avenue to litigate when Codex 5.3 is not _intended_ to be used as a "hacking" tool, and users can be mistakenly locked out because they mistakenly asked a few security-related questions with no malicious intentions.

How can individuals and companies not willing to engage in hardcore cybersecurity research and hacking restore access to the frontier model?

But more importantly...

3. This policy change currently violates European laws.

As it appears right now, this policy effectively locks out users, small and medium sized companies from using Codex 5.3 under their ChatGPT subscriptions unless they explicitly do security-related work AND get lucky with the approval, even if companies or users do not directly intend to specialize in cybersecurity. Which actually matters a lot: OpenAI as of this moment is effectively engaging in false advertisement in violation of 🇪🇺 EU laws 🇪🇺 thus begging the question:

Will ChatGPT be made EU-compliant promptly by redacting all of its marketing materials, will OpenAI commit to this change and pay the fine for illegal business practices according to European law, or is OpenAI planning to leave the EU market? You must be very clear about NOT providing promised services unless criteria are met, or 🇪🇺 pay the fine to the European Union 🇪🇺 when _this_ will hit the fan. Many companies grow to depend on ChatGPT in their day-to-day work, and getting features limited like this can result in individuals and companies claiming measurable damages.

View original on GitHub ↗

This issue has 4 comments on GitHub. Read the full discussion on GitHub ↗