OpenAI on Thursday launched Advanced Account Security, an opt-in protection program for ChatGPT users, and named Yubico as its hardware partner. The two companies are shipping a pair of co-branded keys — the YubiKey C NFC and the YubiKey C Nano — that bind directly to a ChatGPT login. OpenAI is pitching the program at political dissidents, journalists, researchers, and elected officials, alongside enterprise users whose corporate data sits inside chat sessions.
The April 30, 2026 announcement is the second security-flavored move from OpenAI this week, following a new framework for digital defense the company posted days earlier. It also lands several weeks after Anthropic introduced Mythos, a dedicated cybersecurity model. The competitive subtext is hard to miss: every frontier lab now wants to be seen as the safer place to put sensitive prompts.
Security keys are small USB devices that hold a unique cryptographic identifier. Logging into a connected account requires physical possession of the key, which makes phishing — the dominant vector for account takeover — substantially harder to pull off. For high-value targets, that is the whole point.
Key facts
- 01OpenAI launched Advanced Account Security (AAS) on April 30, 2026, an opt-in protection layer for ChatGPT accounts.
- 02Yubico is shipping two co-branded keys for the program: the YubiKey C NFC and the YubiKey C Nano.
- 03OpenAI is pitching AAS at political dissidents, journalists, researchers, elected officials, and enterprise users.
- 04If a user loses their security key, OpenAI cannot recover the account — meaning chat history could be permanently lost.
- 05The launch follows Anthropic's debut of its Mythos cybersecurity model several weeks earlier.
"Ultimately, our intent is to drastically reduce the threat of unauthorized access to sensitive data in OpenAI accounts worldwide," Yubico CEO Jerrod Chong said in the announcement. The framing is notable because it implicitly acknowledges what most chatbot users already suspect: ChatGPT sessions now contain enough personal and corporate detail to be worth stealing.
“Ultimately, our intent is to drastically reduce the threat of unauthorized access to sensitive data in OpenAI accounts worldwide.”— Jaeden Schafer
There is a growing body of evidence that attackers agree. Cybercriminals have begun targeting chatbot users for extortion-grade material, and the intimate register of chatbot conversations — health questions, legal questions, draft contracts, source code — is a richer haul than a typical email inbox. Enterprise accounts compound the problem because employees routinely paste internal documents into prompts.
AAS does carry a real tradeoff. If a user loses the YubiKey, OpenAI will not be able to recover access to the account. In practice that means months or years of conversation history could be unreachable, with no support-ticket escape hatch. That is the standard hardware-key bargain, but it will be unfamiliar to consumers who have been trained to expect a password reset link.
OpenAI has not disclosed pricing for the co-branded keys or whether AAS will be free for ChatGPT Plus and Enterprise tiers. The company has also not said how the program will interact with existing single sign-on deployments inside enterprises, where IT teams typically own the identity stack rather than the end user.
The Yubico deal slots into a busier-than-usual stretch for OpenAI's security and partnership posture. The company recently moved to gate its GPT-5.5 Cyber model behind restricted access — a reversal of its earlier mockery of Anthropic for doing the same with Mythos — and closed a $50B Amazon compute deal that ended its Microsoft legal entanglement. Account security is the consumer-facing piece of the same story.
Skeptics will note that hardware keys are a partial fix. They defeat phishing and credential stuffing, but they do nothing about prompt injection, model-side data leakage, or rogue insiders at the AI provider itself. A journalist communicating with a source through ChatGPT is still trusting OpenAI's infrastructure, regardless of how the login is gated.
Still, the move sets a useful floor. Until now, the most sensitive ChatGPT account in the world — say, an elected official's — could be protected by the same SMS-code two-factor that protects a fantasy football league. Forcing a hardware step for users who want it pulls account security into rough parity with what banks and email providers already offer, and pressures Anthropic, Google, and Meta to match. For an industry that has spent two years arguing about model safety, the unglamorous question of who can log in is finally getting the attention it deserves.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




