ViqusViqus
Navigate
Company
Blog
About Us
Contact
System Status
Enter Viqus Hub

OpenAI Launches Advanced Account Security, Mandating Passkeys for High-Risk Users

Advanced Account Security passkeys phishing-resistant authentication ChatGPT Codex cybersecurity
April 30, 2026
Source: OpenAI News
Viqus Verdict Logo Viqus Verdict Logo 8
Infrastructure Shift: Security as a Gatekeeper
Media Hype 5/10
Real Impact 8/10

Article Summary

OpenAI has launched 'Advanced Account Security,' a comprehensive, opt-in protection layer for ChatGPT and Codex accounts designed for users handling high-stakes or sensitive data (e.g., journalists, researchers). This new system dramatically strengthens account security by mandating the use of passkeys or physical security keys (like YubiKeys), effectively disabling less secure methods like password logins, email, and SMS recovery. Users must now utilize backup passkeys or dedicated security keys for recovery. Furthermore, the feature shortens active sign-in sessions, provides granular session management, and automatically excludes conversations from model training for enrolled users. OpenAI is also setting a precedent by requiring all 'Trusted Access for Cyber' members to adopt this security layer by June 2026, signaling a professionalization of AI usage that prioritizes institutional-grade security.

Key Points

  • Advanced Account Security mandates phishing-resistant sign-in (passkeys/physical keys) and eliminates less secure recovery methods (email/SMS) to drastically raise the bar for account protection.
  • The feature adds corporate-grade controls, such as automatically excluding conversation data from model training, which is critical for handling sensitive professional or research information.
  • OpenAI's adoption of hardware key partnerships and the mandatory rollout for key enterprise groups solidify the platform's move into core, highly regulated infrastructure for professional use.

Why It Matters

This is not routine feature maintenance; it represents OpenAI treating its platform as critical infrastructure, similar to financial services. The requirement to use physical keys and the subsequent elimination of user-friendly but insecure recovery mechanisms fundamentally shift user responsibility and platform risk. For businesses building workflows on ChatGPT/Codex, this means integrating enterprise-grade identity management (SSO/Passkeys) is becoming a prerequisite for adoption. Professionals should care because the increased security overhead for sensitive data is becoming the industry standard, potentially raising the barrier to entry for non-compliant or less secure applications. It also positions OpenAI to capture enterprise market share by offering 'security as a feature,' not just a compliance checkbox.

You might also be interested in