OpenAI Advanced Account Security Release
OpenAI Advanced Account Security Release
OpenAI introduces Advanced Account Security for high-risk users
OpenAI has released Advanced Account Security, an opt-in security suite for ChatGPT and Codex accounts. This feature set is designed for users at increased risk of digital attacks—such as journalists, elected officials, and political dissidents—as well as security-conscious individuals who require the strongest available account protections.
Core security enhancements and technical mechanisms
Advanced Account Security implements a series of controls to strengthen authentication, restrict recovery vectors, and limit session exposure. These protections are available in the Security section of ChatGPT account settings.
Phishing-resistant authentication
Advanced Account Security mandates the use of passkeys or physical security keys. Password-based logins are disabled to ensure that phishing-resistant sign-in is the default for enrolled users.
Restricted account recovery
To prevent account takeovers resulting from compromised email or SMS channels, Advanced Account Security disables email and SMS-based recovery. Recovery is restricted to backup passkeys, security keys, and recovery keys. Consequently, OpenAI Support cannot assist with account recovery for users enrolled in this program.
Session management and visibility
To reduce the window of exposure during a device or session compromise, sign-in sessions are shortened. Users are provided with login alerts and the ability to review and manage active sessions across all signed-in devices.
Automatic training exclusion
Accounts with Advanced Account Security enabled are automatically opted out of model training. Conversations from these accounts will not be used to train OpenAI models.
Hardware partnership with Yubico
To facilitate the adoption of phishing-resistant authentication, OpenAI has partnered with Yubico to offer a customized bundle of security keys. This bundle includes the YubiKey C Nano for low-friction daily authentication on laptops and the YubiKey C NFC for backup and mobile device use. While this bundle is available to all eligible users, it is specifically launched as part of the Advanced Account Security initiative. Users may also use any FIDO-compliant security key or software-based passkeys.
Mandatory requirements for Trusted Access for Cyber
Beginning June 1, 2026, individual members of the Trusted Access for Cyber program who access the most cyber-capable and permissive models will be required to enable Advanced Account Security. Organizations with trusted access may instead attest that phishing-resistant authentication is integrated into their single sign-on (SSO) workflow.
Strategic context and future expansion
This security update is part of OpenAI's broader cybersecurity action plan to protect critical systems and national security. The company intends to extend these advanced protections to additional audiences, including enterprise environments, as AI becomes more deeply embedded in professional workflows and core infrastructure.