OpenAI Launches Advanced Account Security for High-Risk ChatGPT Users
OpenAI's opt-in Advanced Account Security kills passwords and email recovery for ChatGPT, requires passkeys or hardware keys, and auto-excludes chats from training. Cyber defenders must enroll by June 2026.

Updated
Why it matters
- Advanced Account Security requires passkeys or physical security keys, disabling password-based login, and covers Codex accounts accessed through the same login.
- Email and SMS recovery are disabled; OpenAI Support cannot assist with recovery for enrolled accounts, which must use backup passkeys, security keys, or recovery keys.
- Members of Trusted Access for Cyber must enable the mode by June 1, 2026, and a Yubico bundle (YubiKey C Nano plus YubiKey C NFC) is offered at preferred pricing.
OpenAI has launched Advanced Account Security, an opt-in setting for ChatGPT accounts that disables password-based login entirely and requires passkeys or physical security keys instead. The feature is available starting today in the Security section of users' ChatGPT accounts, and once enrolled, protection extends to Codex accounts accessed through the same login.
The company frames the new mode as protection for people at elevated risk of digital attacks: journalists, elected officials, political dissidents, researchers, and what OpenAI calls "those who are especially security-conscious." But the feature also signals something larger. As OpenAI puts it, "a ChatGPT account can hold sensitive personal and professional context, and sit at the center of connected tools and workflows." An AI account is no longer a chat window. It is a repository of professional context, a hub for connected tools, and increasingly a piece of workplace infrastructure. Account takeover in that context means the theft of intellectual property, private deliberations, and workflow access at once.
The launch is part of OpenAI's broader cybersecurity action plan, which the company describes as an effort "to broaden access to the technologies that can help protect communities, critical systems, and our national security." That framing matters for the policy conversation around consumer AI platforms: as ChatGPT's user base grows, the security of individual accounts becomes a question that extends beyond any single user's privacy.
What the mode actually changes
Advanced Account Security bundles four concrete changes into one switch.
First, sign-in. The mode requires passkeys or physical security keys and disables password-based login. For the target population, phishing-resistant authentication becomes the default rather than an option buried in settings.
Second, and most consequential, account recovery. If a user's email account or phone number is compromised, an attacker would normally attempt to use email or SMS recovery to seize the ChatGPT account. Advanced Account Security shuts that door. It disables email and SMS recovery and permits only three stronger methods: backup passkeys, security keys, and recovery keys. This hardening carries a cost the company states plainly: "Because account recovery is restricted to these more secure methods, OpenAI Support will not be able to assist with account recovery for users enrolled in Advanced Account Security." Lose your keys, and you may lose the account. OpenAI acknowledges this trade-off directly, saying it wants users "to understand that the increased protection of Advanced Account Security comes with an increased responsibility for account recovery."
Third, session management. Sign-in sessions are shortened to reduce the window of exposure if a device or an active session is compromised. Users get alerts on every login and can review and manage active sessions across the devices where they are signed in.
Fourth, training exclusion. Accounts enrolled in the mode will automatically keep their conversations out of model training. OpenAI notes that people working with especially sensitive information may already opt out of having conversations used for training; with Advanced Account Security, that preference is automatic rather than a setting users must find and enable themselves. For journalists and researchers handling sensitive material, this removes one point of uncertainty about where their data goes.
A hardware partnership with Yubico
To lower the barrier to phishing-resistant authentication, OpenAI has partnered with Yubico, which it calls "a leader in hardware-based authentication and account protection," to offer preferred pricing on a customized bundle of security keys. The bundle pairs the YubiKey C Nano, designed to stay plugged into a laptop for low-friction daily authentication, with the YubiKey C NFC, intended for backup and for use across laptops and mobile devices.
The bundle launches alongside Advanced Account Security, but OpenAI says it will be available to all eligible users through their security settings, extending hardware-key adoption beyond the high-risk population the mode targets. Users are not locked into Yubico hardware: OpenAI confirms that "any other FIDO-compliant security key, or use software-based passkeys" will work.
The partnership reflects the practical reality of FIDO-based authentication. Passkeys and security keys are the strongest widely deployed defense against phishing, but recovery and portability have always been the friction points. Bundling a daily-use key with a backup key, at preferred pricing, addresses the single most common way users lock themselves out of hardened accounts.
Mandatory for cyber defenders in 2026
The most revealing detail in the announcement is a mandate. Individual members of Trusted Access for Cyber — OpenAI's program that gives verified defenders access to more capable and permissive models — will be required to enable Advanced Account Security beginning June 1, 2026. Organizations with trusted access have an alternative path: they can attest that phishing-resistant authentication is part of their single sign-on workflow.
The mandate makes the feature's purpose explicit. OpenAI is expanding programs that put more capable and more permissive models in the hands of verified cybersecurity defenders, and those accounts are themselves high-value targets. An attacker who compromises a defender's account does not just gain chat history; they gain access to the more permissive capabilities the program provides. Requiring the strongest account protections for those users closes a loop between capability access and account security.
Why this matters beyond a settings toggle
The announcement situates itself in OpenAI's larger ambitions. The company describes itself as "becoming the core infrastructure for AI, making it possible for people around the world and businesses, big and small, to just build things." It points to the broad consumer reach of ChatGPT as "a powerful distribution channel into the workplace, where demand is rapidly shifting from basic model access to intelligent systems that reshape how businesses operate," and notes that developers build on the platform through APIs while "Codex is transforming how developers turn ideas into working software."
That infrastructure argument is the context for why account security is now a strategic concern rather than a routine product update. An account that sits at the center of connected tools, agent workflows, and professional context is a higher-value target than a chat log ever was. Account takeover protection, session hygiene, and recovery hardening are the consumer-facing layer of that security posture.
There is also a market signal here. Making training exclusion automatic for high-risk accounts, shipping a hardware-key bundle at preferred pricing, and mandating phishing-resistant authentication for cyber defenders all position OpenAI's consumer product for users — and regulators — who increasingly treat AI platforms as handling sensitive data by default.
OpenAI says privacy and security are "foundational to how we build all of our products" and that it will "continue investing in protections that give people more control and stronger safeguards over time." The company expects to extend this work to additional audiences, including enterprise environments, "where stronger account security can matter just as much." Users who want the protection now can enroll at chatgpt.com/advanced-account-security — with the caveat that once enrolled, they alone hold the keys, literally, to getting back in.
Original: cdn.openai.com
More from Rebecca Stone
Show full bio
Correspondent covering consumer brands and retail at AI In Context.
135 articles
Related articles
- OpenAI adds Lockdown Mode and risk labels to ChatGPT
- Security Researchers Used Anthropic's Claude to Hack Into OpenAI
- OpenAI Bans Korean-Language Accounts Tied to Malware Development
- OpenAI Bans Accounts Linked to DPRK Threat Actors Using AI for Intrusion Research
- OpenAI ships GPT-5.5-Cyber, tiers access for defenders