OpenAI Adds Advanced Account Security for High-Risk Users
The opt-in setting combines stronger sign-in and recovery protections with phishing-resistant hardware authentication from Yubico.

SAN FRANCISCO, Calif. - OpenAI has introduced Advanced Account Security, a new optional suite of protections designed for ChatGPT and Codex users who face an elevated risk of account takeover or simply require stronger administrative controls over their digital assets. The update represents a significant hardening of the platform’s security posture, grouping enhanced sign-in, recovery, and session protections into a single interface. These safeguards apply globally across the company’s ecosystem, ensuring that any product accessed through a unified OpenAI login is covered by the same rigorous standards once the feature is enabled by the user.
The launch arrives at a critical juncture for the artificial intelligence sector, as tools like ChatGPT transition from experimental curiosities into central hubs for business operations and sensitive personal data. As users increasingly utilize AI to draft confidential documents, analyze proprietary codebases, and manage integrated workflows, the value of the information stored within these accounts has skyrocketed. This shift has made AI platforms a prime target for malicious actors, necessitating a move beyond standard password-based security toward more robust, multi-layered defense mechanisms that can withstand sophisticated phishing attempts.
Central to this new security offering is a strategic partnership with Yubico, a leader in hardware-based authentication. OpenAI is collaborating with the firm to offer co-branded hardware security keys that support phishing-resistant authentication protocols. These physical keys serve as a tangible line of defense, significantly reducing the risk that a convincing fake login page could capture a reusable code or credential. By requiring a physical touch or presence of the device to authorize access, the system effectively neutralizes many common remote attack vectors used by cybercriminals today.
To accommodate different hardware preferences and workflows, OpenAI is offering these security keys in both USB-C and compact formats. This dual-track approach allows users to choose between a portable key for on-the-go use across multiple devices or a low-profile ‘nano’ version that remains semi-permanently attached to a trusted workstation. By providing versatile form factors, the company aims to reduce the friction often associated with hardware-based security, encouraging broader adoption among high-risk individuals such as developers, researchers, and corporate executives.
While the benefits of hardware authentication are clear, OpenAI’s documentation emphasizes that advanced protection introduces a fundamental tradeoff in terms of account recovery. By design, these protections make the recovery process more restrictive because traditional easy-fallback methods—such as email-based resets—often become the very paths that attackers exploit to bypass primary security. By closing these loopholes, OpenAI is prioritizing account integrity over convenience, a move that aligns with industry best practices for high-security environments.
Consequently, the company is urging users to register backup authentication methods and store them in a secure physical or digital location before enabling the new controls. The documentation explicitly explains that the added level of protection may limit OpenAI’s internal ability to restore access for a user who loses their primary credentials. This shift places a greater burden of responsibility on the user, requiring a disciplined approach to credential management to avoid permanent lockout from their data and services.
Industry analysts have noted that this move reflects a broader trend among Silicon Valley giants to migrate toward a ‘zero trust’ architecture. As AI accounts gain more connections to external tools through plugins and API integrations, a compromised account is no longer an isolated incident; it could potentially expose private conversations, sensitive source files, or even trigger authenticated actions in third-party applications. Security, therefore, must be holistic, covering not only the initial sign-in but also active sessions and the entire lifecycle of an account’s recovery flow.
The introduction of Advanced Account Security also addresses the specific needs of the developer community using Codex. For engineers integrating AI into their development pipelines, the compromise of an account could lead to the injection of malicious code or the theft of intellectual property. By implementing hardware-backed security, OpenAI is providing a toolset that mirrors the high-stakes security environments found in traditional banking and enterprise software development, acknowledging the mission-critical nature of modern AI workloads.
Beyond the hardware itself, the new settings give users a clearer, more centralized way to choose a higher level of protection without navigating disparate menus. However, experts suggest that the long-term success of the initiative will depend heavily on understandable setup and recovery guidance. If the process is perceived as too complex or if users find themselves frequently locked out of their accounts, adoption rates among the general population may remain low, leaving a large portion of the user base vulnerable to credential stuffing and phishing.
For large organizations, OpenAI recommends that these new features be paired with managed identity solutions and the principle of least-privilege connections. While a hardware key can stop the vast majority of phishing attacks, it does not serve as a replacement for careful, ongoing control over what an authenticated account is actually allowed to perform within a corporate network. Managed session reviews and strict auditing remain necessary components of a comprehensive security strategy that complements OpenAI’s new hardware-based protections.
The partnership with Yubico further solidifies the role of the FIDO2 and WebAuthn standards in the consumer AI space. By moving away from SMS-based two-factor authentication, which is susceptible to SIM-swapping and interception, OpenAI is steering its most vulnerable users toward a protocol that is widely considered the gold standard in modern cybersecurity. This effort matches similar initiatives by other major platforms like Google and Apple, who have also integrated support for physical security keys to protect high-profile targets.
Looking forward, the tech industry will be watching to see how OpenAI handles the inevitable support challenges that arise when users lose their hardware keys. The company’s ability to balance rigorous security with user accessibility will likely serve as a blueprint for other AI startups currently scaling their infrastructure. As the AI sector continues to mature, the focus is expected to stay on not just what these models can do, but how securely the data behind them is being guarded.
Ultimately, the rollout of Advanced Account Security signals OpenAI’s recognition of its role as a critical infrastructure provider. By providing the tools necessary to defend against sophisticated threat actors, the company is attempting to build the trust required for deep enterprise integration. Whether through USB-C keys or hardened session management, the goal remains the same: ensuring that the next generation of artificial intelligence is built on a foundation of robust, phishing-resistant security.
Sources
Written by
The Company Wire Staff
Reporting from The Company Wire newsroom. Staff bylines cover funding rounds, product launches and company news verified against primary sources.



