Skip to content
Chimera readability score 70 out of 100, Academic reading level.

An advanced set of protections against unauthorized access to ChatGPT accounts, Codex, and the sensitive information they can contain.
Today, we’re introducing Advanced Account Security, a new opt-in setting for ChatGPT accounts, designed for people at increased risk of digital attacks, as well as for those who want the strongest account protections available. It brings together a set of heightened security measures that help safeguard against account takeover while making those protections easier to activate in one place. Once enrolled, Advanced Account Security protects users in Codex as well.
People are turning to AI for deeply personal questions and increasingly high-stakes work. Over time, a ChatGPT account can hold sensitive personal and professional context, and sit at the center of connected tools and workflows. For some people, like journalists, elected officials, political dissidents, researchers, and those who are especially security-conscious, the stakes are even higher.
This effort is part of our broader cybersecurity action plan(opens in a new window) to broaden access to the technologies that can help protect communities, critical systems, and our national security. We want users to have the controls to make the security and privacy choices that are right for them. At the same time, we want to ensure users understand that the increased protection of Advanced Account Security comes with an increased responsibility for account recovery.
Advanced Account Security brings together a series of controls that strengthen sign-in protections, tighten account recovery, reduce exposure from compromised sessions, and give users more visibility into account activity. It’s available to opt into in the Security section of users’ ChatGPT accounts on web. Protection applies to both ChatGPT and Codex accounts that are accessed through that login.
Stronger sign-in methods. Advanced Account Security requires passkeys or physical security keys while disabling password-based login, helping make phishing-resistant sign-in the default for people who need it most.
More secure account recovery. If a user’s email account or phone number is compromised, an attacker may try to use one of them to gain access to their ChatGPT account via e-mail or SMS based recovery. To reduce this risk, Advanced Account Security disables email and SMS recovery and requires stronger recovery methods: backup passkeys, security keys, and recovery keys. Because account recovery is restricted to these more secure methods, OpenAI Support will not be able to assist with account recovery for users enrolled in Advanced Account Security.
Shorter sessions and clearer session management. Sign-in sessions are shortened to reduce the window of exposure if a device or active session is compromised. Users also receive alerts when there is a login to their account, and they can review and manage the active sessions across the various devices they’re signed into.
Automatic training exclusion. People working with especially sensitive information may opt not to have those conversations used for model training. With Advanced Account Security enabled, that preference is automatic: conversations from those accounts will not be used to train our models.
Using physical security keys, such as YubiKeys, is one of the strongest defenses against phishing. To make that level of protection easier to access, we have partnered with Yubico, a leader in hardware-based authentication and account protection, to offer our users preferred pricing on a customized bundle of best in class security keys. The YubiKey C Nano is designed to stay in your laptop for simple, low-friction daily authentication, and the YubiKey C NFC for backup, and use across laptops and mobile devices.
We’re launching this partnership as part of Advanced Account Security, but the bundle will be available to all eligible users in their security settings on web so more people can adopt stronger, phishing-resistant account protection. Users will also be able to use any other FIDO-compliant security key, or use software-based passkeys.
We continue to expand programs that give verified defenders access to more capable and permissive models, and we need to ensure that the accounts of those defenders are protected with our most advanced security protections.
Individual members of Trusted Access for Cyber accessing our most cyber capable and permissive models will be required to enable Advanced Account Security beginning June 1, 2026. Organizations with trusted access can, as an alternative, attest that they have phishing resistant authentication as part of their single sign-on workflow.
OpenAI is becoming the core infrastructure for AI, making it possible for people around the world and businesses, big and small, to just build things. The broad consumer reach of ChatGPT creates a powerful distribution channel into the workplace, where demand is rapidly shifting from basic model access to intelligent systems that reshape how businesses operate. Developers build on and expand the platform by leveraging our APIs, and Codex is transforming how developers turn ideas into working software.
As AI becomes increasingly embedded in our lives, it is more important than ever to ensure that users have the controls they need to help protect their privacy and security.
Privacy and security are foundational to how we build all of our products and we’ll continue investing in protections that give people more control and stronger safeguards over time. We expect to extend this work to additional audiences, including enterprise environments, where stronger account security can matter just as much.
OpenAI users who want additional protection can enroll in Advanced Account Security (opens in a new window)on web starting today.

Facts Only

Advanced Account Security introduced by OpenAI for increased protection against unauthorized access.
Applicable to ChatGPT and Codex accounts.
Strengthens sign-in protections, tightens account recovery, reduces exposure from compromised sessions, gives users more visibility into account activity.
Available to opt into in the Security section of users’ ChatGPT accounts on web.
Protection applies to both ChatGPT and Codex accounts that are accessed through that login.
Stronger sign-in methods require passkeys or physical security keys while disabling password-based login.
More secure account recovery disables email and SMS recovery and requires backup passkeys, security keys, and recovery keys.
Shorter sessions and clearer session management are included for better control over active sessions across devices.
Automatic training exclusion allows users to opt not to have conversations used for model training.
Partnership with Yubico offers preferred pricing on a customized bundle of best in class security keys for users.
Trusted Access for Cyber program members will be required to enable Advanced Account Security starting June 1, 2026.

Executive Summary

OpenAI, the company behind the popular AI model ChatGPT, has introduced Advanced Account Security, an opt-in feature designed to enhance protection against unauthorized access to user accounts and sensitive information stored within. The new security measures include stronger sign-in methods, more secure account recovery, shorter sessions, clearer session management, automatic training exclusion, and a partnership with Yubico for preferred pricing on security keys. This initiative is aimed at individuals and organizations at increased risk of digital attacks, including journalists, elected officials, political dissidents, researchers, and cyber-conscious users.
Starting June 1, 2026, individual members of OpenAI's Trusted Access for Cyber program will be required to enable Advanced Account Security. Organizations with trusted access can alternatively attest that they have phishing-resistant authentication as part of their single sign-on workflow. The enhanced security measures apply to both ChatGPT and Codex accounts accessed through the login.

Full Take

OpenAI's introduction of Advanced Account Security emphasizes the need for stronger security measures as AI models like ChatGPT and Codex become more deeply integrated into personal and professional lives. By offering enhanced protections against unauthorized access, OpenAI aims to address concerns about privacy, security, and account takeover for users who store sensitive information within their accounts. The partnership with Yubico provides a cost-effective solution for users seeking to implement stronger, phishing-resistant authentication methods.
The requirement for Advanced Account Security for members of the Trusted Access for Cyber program highlights the increased importance of cybersecurity for individuals and organizations working with sensitive information. As AI continues to evolve, it is likely that additional security measures will be developed and implemented to address emerging threats and ensure user privacy and protection.

Sentinel — Human

Confidence

This text reads as a carefully crafted corporate announcement, effectively blending technical security details with broader privacy and societal arguments, consistent with human strategic communication.

Signals Detected
low severity: Slightly varied sentence structure and deliberate pacing; avoids the overly uniform rhythm typical of pure LLM output.
low severity: The text maintains a clear, persuasive flow linking a technical feature (security) to a moral/political imperative (privacy/control).
low severity: The structure follows a typical corporate/policy announcement template, which is common in human communication, rather than perfect, mechanical rotation.
low severity: All claims (features, partnerships, rollout dates) are presented in a manner consistent with an official announcement, suggesting internal grounding, though external verification is required.
Human Indicators
The voice balances technical exposition with appeals to societal responsibility, indicating a goal beyond simple informational delivery.
The introduction of specific, actionable policies (e.g., disabling email recovery, requiring passkeys) grounded in a specific timeline suggests human strategic intent rather than pure pattern replication.