Introducing Advanced Account Security
Key Points
- Phishing-resistant authentication with passkeys and security keys
- Restricted recovery methods with no OpenAI Support assistance
- Yubico partnership for affordable hardware security keys
Summary
OpenAI has launched Advanced Account Security, an opt-in feature designed to protect ChatGPT and Codex accounts against unauthorized access. This new security tier combines multiple hardened protections and is particularly valuable for high-risk users such as journalists, elected officials, researchers, and security-conscious individuals.
Key Points
- Phishing-resistant sign-in: Requires passkeys or physical security keys; disables password-based login
- Restricted account recovery: Eliminates email and SMS recovery methods; requires backup passkeys, security keys, or recovery keys. OpenAI Support cannot assist with recovery for enrolled users
- Session management: Shortened sign-in sessions with login alerts and active session visibility across devices
- Automatic training exclusion: Conversations are automatically excluded from model training for enhanced privacy
- Yubico partnership: Preferred pricing on YubiKey security keys (C Nano and C NFC) for accessible phishing-resistant authentication
- Trusted Access for Cyber requirement: Individual members must enable Advanced Account Security by June 1, 2026; organizations can alternatively attest to phishing-resistant SSO
- Availability: Available now on web in the Security section of ChatGPT accounts; protection extends to both ChatGPT and Codex
Future Plans
OpenAI plans to extend Advanced Account Security to enterprise environments and additional user audiences.