OpenAI Launches Advanced Account Security with Keys

SkimNews Take
OpenAI's focus on physical security keys for high-risk accounts signals a recognition that software-based authentication alone is insufficient against state-level or sophisticated attackers when AI access becomes a critical target.
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- OpenAI launched Advanced Account Security, a new optional tier that bans passwords and requires two physical security keys or passkeys for login.
- Yubico partnered with OpenAI to provide discounted YubiKey bundles for users who enable the Advanced Account Security feature.
- Trusted Access for Cyber participants must activate Advanced Account Security by June 1 or submit an alternative attestation proving phishing‑resistant enterprise SSO.
- Advanced Account Security shortens sign‑in windows, logs every login attempt, and removes email/SMS recovery, forcing users to rely on recovery keys or physical keys.
- Google continues to roll out its Gemini AI across products like Chrome, contrasting OpenAI’s focus on tightening account protection rather than expanding functionality.
Why it matters: Journalists, elected officials, and security‑concerned users gain phishing‑resistant login, while attackers lose a common vector; OpenAI’s June 1 deadline forces rapid adoption, reducing breach risk and potentially lowering liability costs for the firm.



