What Changed: A New Opt-In Security Layer for ChatGPT
On April 30, 2026, OpenAI introduced Advanced Account Security, an opt-in setting for ChatGPT accounts designed for people at increased risk of digital attacks—journalists, elected officials, political dissidents, researchers, and security-conscious users. The feature consolidates several heightened security measures into one place, and once enabled, it also protects Codex accounts accessed through the same login.
This is part of OpenAI’s broader cybersecurity action plan to broaden access to protective technologies. The company explicitly notes that the increased protection comes with increased responsibility for account recovery—a trade-off you should understand before enabling it.
How It Works: Four Core Controls
When you opt in via the Security section of your ChatGPT account, Advanced Account Security applies four categories of controls:
- Stronger sign-in methods: Requires passkeys or physical security keys, and disables password-based login. This makes phishing-resistant sign-in the default.
- More secure account recovery: Disables email and SMS recovery, which are common attack vectors if your email or phone is compromised. Instead, recovery relies on backup passkeys, security keys, or recovery keys. Because of this restriction, OpenAI Support cannot assist with account recovery for enrolled users.
- Shorter sessions and clearer session management: Sign-in sessions are shortened to reduce exposure if a device or session is compromised. You also get login alerts and can review/manage active sessions across devices.
- Automatic training exclusion: Conversations from your account will not be used to train OpenAI’s models—no need to manually opt out each time.
These controls are designed to work together. For example, disabling password login reduces phishing risk, while stricter recovery prevents attackers from using a compromised email or phone number to reset your password.
Practical Implementation: Getting Started with Passkeys and Security Keys
To enable Advanced Account Security, go to your ChatGPT account’s Security settings. You’ll need at least one passkey or security key set up before you can enable the feature, because password login will be disabled.
Here’s a typical workflow for a developer or power user:
- Create a passkey on your primary device (laptop or phone). This can be a software-based passkey (e.g., iCloud Keychain, Google Password Manager, or Windows Hello) or a hardware security key.
- Set up a backup passkey or recovery key on a separate device. This is critical because if you lose your only passkey, you’ll be locked out permanently—OpenAI Support won’t help.
- Enable Advanced Account Security in the Security settings.
- Test the recovery flow by signing out and signing back in using your backup method.
For hardware keys, OpenAI has partnered with Yubico to offer preferred pricing on a bundle of two YubiKeys: the YubiKey C Nano (designed to stay in your laptop) and the YubiKey C NFC (for backup and cross-device use). The bundle is available to all eligible users in their security settings, not just those enrolled in Advanced Account Security. You can also use any FIDO-compliant security key or software passkey.
Who Should Use It: High-Risk Users and Trusted Access for Cyber
OpenAI positions Advanced Account Security for individuals who face elevated digital threats. If you’re a journalist covering sensitive topics, an activist, a researcher handling confidential data, or simply someone who wants maximum protection for a ChatGPT account that stores years of personal and professional context, this feature is worth enabling.
A concrete trigger: Starting June 1, 2026, individual members of Trusted Access for Cyber—a program giving verified defenders access to OpenAI’s most capable and permissive models—will be required to enable Advanced Account Security. Organizations with trusted access can instead attest that their single sign-on workflow already includes phishing-resistant authentication. This signals that OpenAI is moving from voluntary to mandatory security for high-risk roles.
For product builders, this is a reminder: as AI tools become central to sensitive work, account security can’t be an afterthought. If you’re building on OpenAI’s platform, consider how your own authentication and recovery flows handle phishing resistance and session management.
Limitations and Trade-offs: The Recovery Responsibility Is on You
The biggest trade-off is account recovery. With email and SMS recovery disabled, you must securely store backup passkeys, security keys, or recovery keys. If you lose all of them, your account is unrecoverable—OpenAI Support explicitly cannot help. This is a deliberate design choice to prevent social engineering attacks, but it places a heavy burden on the user.
Other limitations to keep in mind:
- Not for everyone: If you’re not at high risk, the inconvenience of managing hardware keys or multiple passkeys may outweigh the benefits.
- Session management: Shorter sessions mean you’ll need to re-authenticate more often, which can be annoying on shared or multiple devices.
- Training exclusion is automatic: While this is a privacy win, it means your conversations won’t contribute to model improvements—a trade-off if you value that.
- Enterprise rollout is future: OpenAI says it expects to extend this work to additional audiences, including enterprise environments, but no timeline is given.
Key Takeaway for Builders and Users
Advanced Account Security is a strong, well-designed option for high-risk users, but it’s not a set-and-forget feature. Before enabling it, plan your recovery strategy: create at least two passkeys or security keys, store recovery keys in a safe place, and test the flow. For product builders, the lesson is clear: when AI tools handle sensitive data, security features like phishing-resistant login and strict recovery should be part of the product’s core design, not an optional add-on. OpenAI is leading by example, and the June 1 requirement for Trusted Access for Cyber shows that stronger security is becoming the baseline for high-stakes use cases.
Sources
AI-assisted summary compiled from the sources above, reviewed by a human before publishing.
