Identity & AccessPress Release

Yubico Expands OpenAI Partnership as Hardware-Backed Passkey Mandate Begins for Trusted Access for Cyber Programme

Enrolling Security Keys Disables Weaker, Phishable Authentication Methods—Creating a High-Assurance Environment

Protecting the security researchers and defenders on the frontlines of AI requires phishing-resistant account protection that keeps powerful capabilities in trusted hands. Marking a major milestone in this effort, OpenAI’s Advanced Account Security (AAS) programme has gone live as of 1 September 2026—requiring hardware-backed passkeys for all Trusted Access for Cyber (TAC) members.

To further scale phishing-resistant authentication globally, Yubico has expanded its partnership with OpenAI by bringing the custom 2-pack OpenAI + YubiKey bundle to 10 new countries: Australia, Egypt, Japan, Malaysia, Mexico, Saudi Arabia, Singapore, South Korea, Taiwan, and United Arab Emirates.

The rapid advancement of AI continues changing the global cybersecurity landscape. As these technologies become increasingly powerful, safeguarding access to them is critical. Yubico believes the trusted use of AI depends as much on identity and authenticator assurance as it does on model safety.

Protecting TAC members with hardware-backed passkeys fundamentally changes the economics for threat actors by disrupting the criminal ecosystem that relies on creating, validating, and reselling compromised accounts for downstream abuse. Bringing this same enterprise-grade protection to consumer ChatGPT and Codex accounts accelerates the global adoption of phishing-resistant authentication, securing everyday personal projects, proprietary code, and sensitive workflows against account takeover.

Securing Your OpenAI Accounts with Yubico’s YubiKeys

Under OpenAI’s AAS program, enrolling security keys disables weaker, phishable authentication methods—creating a high-assurance environment. Software-based controls and legacy multi-factor authentication (MFA) – such as SMS OTPs and push notifications—are easily intercepted or bypassed by modern Adversary-in-the-Middle (AiTM) attacks. True cyber resilience requires a phishing-resistant, hardware-backed root of trust built on credentials that cannot be copied or silently synced.

To support this transition, existing account holders can access a custom set of custom-branded YubiKeys at preferred pricing:

  • YubiKey C NFC – OpenAI: Designed for simple tap-to-authenticate protection on mobile devices and tablets.
  • YubiKey C Nano – OpenAI: A low-profile key designed to remain in a laptop’s USB-C port for frictionless, continuous protection.

Once enrolled, users experience the gold standard of phishing-resistant, hardware-backed passkey security through a fast, entirely passwordless login. YubiKeys ensure that no matter how sophisticated AI-driven social engineering becomes, unauthorised login attempts are stopped at the front door.

To learn how to secure your ChatGPT and Codex accounts with Yubico’s YubiKeys and get started today, visit here or chatgpt.com/advanced-account-security.

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *