📰 Full Story
OpenAI has launched Advanced Account Security (AAS), an opt-in, phishing-resistant protection tier for ChatGPT and Codex accounts announced April 30–May 1, 2026.
AAS removes password and email/SMS recovery routes, requiring two passkeys, two FIDO2 hardware keys, or a combination; it shortens session lengths, issues login alerts, and automatically opts enrolled accounts out of model training.
OpenAI partnered with Yubico to offer co-branded YubiKey bundles (YubiKey C NFC and YubiKey C Nano) at a discounted two-pack price to lower adoption barriers.
The company says AAS targets high-risk users — journalists, political dissidents, researchers, elected officials — but is available to all tiers, including free users.
Members of OpenAI’s Trusted Access for Cyber program must enable AAS or demonstrate equivalent phishing-resistant auth by June 1.
AAS also carries a trade-off: if users lose registered keys and recovery material, OpenAI cannot restore account access, potentially making chat histories irretrievable.
The rollout follows broader industry and OpenAI moves toward stronger account defenses amid rising credential theft and targeted phishing campaigns.







💬 Commentary