Introducing Advanced Account Security
Key Points
- Passkeys or security keys required; passwords disabled
- Email/SMS recovery disabled; recovery via passkeys/security/recovery keys only
- Enrolled accounts are automatically excluded from model training
Summary
OpenAI is introducing Advanced Account Security, an opt-in security tier for ChatGPT (and Codex) accounts that enforces phishing-resistant sign-in, stricter recovery, shorter sessions, explicit session management, and automatic exclusion from model training. It's intended for high-risk users (journalists, officials, security-conscious users) and will be required for individual members of Trusted Access for Cyber starting June 1, 2026.
Key Points
- Stronger sign-in: password-based login is disabled; users must use passkeys or physical security keys (FIDO-compliant) for phishing-resistant authentication.
- Recovery changes: email and SMS recovery are disabled. Recovery is limited to backup passkeys, security keys, and recovery keys; OpenAI Support cannot assist with recovery for enrolled accounts.
- Sessions and visibility: session lifetimes are shortened; users receive login alerts and can review/manage active sessions across devices.
- Training exclusion: conversations from enrolled accounts are automatically excluded from model training.
- Yubico partnership: OpenAI offers a preferred YubiKey bundle (YubiKey C Nano + C NFC) in security settings, but any FIDO-compliant key or software passkeys are supported.
- Enforcement for defenders: Trusted Access for Cyber individuals must enable Advanced Account Security by 2026-06-01; organizations can alternatively attest to phishing-resistant SSO.
Actionable next steps for engineers
- If you manage accounts: update onboarding docs to require or recommend passkeys/security keys and document backup/recovery key procedures.
- If you integrate SSO: provide or verify phishing-resistant SSO flows to support organizational attestation.
- If you depend on support workflows: account recovery assistance will be unavailable for enrolled users—plan self-service recovery tooling and user education.
- If you use APIs/Codex: note that protections apply to accounts used to access Codex via the same login.
Where to enable
- Users can opt into Advanced Account Security in the Security section of ChatGPT on web. Enrollment applies to both ChatGPT and Codex access for that login.