At a glance
- What changed
- OpenAI added an opt-in Advanced Account Security mode that requires passkeys or security keys, tightens recovery, and shortens sessions.
- Why it matters
- As ChatGPT accounts store sensitive context and connect to tools, account takeovers become higher impact. Phishing-resistant sign-in can reduce risk, but stricter recovery raises the cost of losing keys.
- Who is affected
- AI users, security teams, policy watchers
- What to do next
- Watch how availability expands to workspace and enterprise setups, and how users balance stronger protection with tougher recovery.
What changed
On April 30, 2026, OpenAI announced Advanced Account Security for ChatGPT logins, requiring passkeys or security keys and tightening recovery and session protections; the setting also applies to Codex.
Why it matters
As ChatGPT accounts store sensitive context and connect to tools, account takeovers become higher impact. Phishing-resistant sign-in can reduce risk, but stricter recovery raises the cost of losing keys.
In plain English
It’s a lock-down mode for your ChatGPT account: you sign in with passkeys or hardware keys, and recovery becomes stricter.
What this means for you
Who is affected: AI users, security teams, policy watchers
Next move: Watch how availability expands to workspace and enterprise setups, and how users balance stronger protection with tougher recovery.
- Requires passkeys or security keys and disables password-based login.
- Adds recovery keys and tighter account recovery rules.
- Shortens active sessions and adds more visibility into account activity.
What remains uncertain
Watch how availability expands to workspace and enterprise setups, and how users balance stronger protection with tougher recovery.