OpenAI has launched its Advanced Account Security program, effective September 1, 2026, to strengthen protections for security researchers and defenders working with artificial intelligence. The initiative makes hardware-backed passkeys mandatory for all members of the Trusted Access for Cyber community. This move reflects a growing effort to keep powerful AI capabilities in trusted hands as adoption accelerates.
Responding to a Changing Threat Landscape
The rapid advancement of AI continues to transform the global cybersecurity environment, making secure access to these technologies increasingly critical. Yubico and OpenAI argue that the trusted use of AI depends on identity and authenticator assurance as much as on model safety. Hardware-backed passkeys are intended to serve as a foundational control in this evolving landscape.
A Mandate for Cyber Defenders
OpenAI’s Advanced Account Security program now requires all Trusted Access for Cyber members to transition from conventional authentication to hardware-backed passkeys. This policy is specifically designed to reduce the risk of credential theft among the security researchers and defenders who protect AI systems. The launch marks a major milestone in applying phishing-resistant requirements to high-value and high-risk accounts.
Expanded Availability Across Ten Markets
To support global adoption of phishing-resistant authentication, Yubico has expanded its partnership with OpenAI by offering a custom two-pack OpenAI and YubiKey bundle in ten new countries. The newly added markets include Australia, Egypt, Japan, Malaysia, Mexico, Saudi Arabia, Singapore, South Korea, Taiwan, and the United Arab Emirates. This expansion brings hardware-backed security to more individual and professional users worldwide.
Disrupting the Economics of Account Takeover
Requiring hardware-backed passkeys for Trusted Access for Cyber members changes the economics for threat actors who rely on stolen accounts. Criminals create, validate, and resell compromised credentials for downstream abuse, but stronger authentication disrupts that pipeline. Extending similar protection to consumer ChatGPT and Codex accounts helps secure personal projects, proprietary code, and sensitive workflows.
Phishing-Resistant by Design
Under the Advanced Account Security program, enrolling dedicated security keys disables weaker and phishable authentication methods such as SMS one-time passwords and standard push notifications. These legacy controls are often intercepted or bypassed by modern adversary-in-the-middle attacks targeting sensitive AI-related accounts. A hardware-backed root of trust provides credentials that cannot be copied or silently synced across devices, creating a high-assurance environment.
Two YubiKey Options for Users
Existing OpenAI account holders can access custom-branded YubiKeys at preferred pricing during the transition to phishing-resistant authentication. The YubiKey C NFC is designed for simple tap-to-authenticate protection on mobile devices and tablets. The YubiKey C Nano is a low-profile key built to remain in a laptop USB-C port for frictionless and continuous protection.
A Passwordless Login Experience
Once enrolled, users experience the gold standard of phishing-resistant passkey security through a fast and entirely passwordless login flow that reduces friction. Unauthorized login attempts are stopped at the front door before they can compromise an account, even as AI-driven social engineering becomes more advanced. Enterprise-grade protection is extended to everyday users securing personal projects, proprietary code, and sensitive workflows against account takeover.
OpenAI and Yubico are positioning hardware-backed authentication as essential for the trusted use of artificial intelligence across professional and personal environments. The new program combines strict identity assurance with accessible security keys to protect researchers, defenders, and everyday users from credential-based attacks. As AI systems become more powerful and widely deployed, strong phishing-resistant authentication is set to play an increasingly central role in preventing account compromise.