FB pixel

OpenAI requires hardware-backed passkeys for trusted cyber access

Categories Access Control  |  Biometrics News
OpenAI requires hardware-backed passkeys for trusted cyber access
 

OpenAI is requiring stronger account protection for users who access some of its most sensitive AI capabilities.

Starting September 1, 2026, individual members of its Trusted Access for Cyber (TAC) program will be required to activate Advanced Account Security and authenticate with a hardware-backed passkey to retain access to frontier models.

OpenAI says members who do not meet the requirement will still be able to use ChatGPT, but their accounts will return to the standard level of model access. TAC is designed for high-level security researchers who may require access to capabilities that OpenAI restricts to ordinary accounts.

Individuals wanting trusted access must complete an identity verification process. OpenAI says this includes a government ID check, know-your-customer (KYC) identity checks, and additional trust signals such as device health.

The verification process is conducted via Persona to help OpenAI determine whether an account belongs to a real user engaged in legitimate cybersecurity work.

OpenAI’s trust and access decision determines the level of cyber capability that a person or organization may use. Verification provides OpenAI with additional context to differentiate authorized work from anonymous or potentially abusive use.

This verification has two identity controls at different stages. Identity proofing connects a real-world person to the ChatGPT account and supports the decision to give trusted access. A hardware-backed passkey protects that verified account during subsequent logins by a cryptographic credential stored on a physical authenticator.

The hardware key stores the private authentication credential on a physical device to make it substantially harder for attackers to capture through phishing, copy between devices, or reuse after compromising a password.

Yubico introduced a custom 2-pack of YubiKeys.  The package includes a YubiKey C NFC that can authenticate through USB-C or an NFC tap on a compatible mobile device, and a low-profile YubiKey C Nano designed to remain connected to a laptop’s USB-C port.

However, OpenAI does not require TAC members to purchase those particular YubiKeys. The Advanced Account Security page says users can enroll with any compatible FIDO security key.

Related Posts

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Biometrics consolidation reflects shift to continuous identity

AI-driven fraud is reshaping the biometrics industry. This week’s acquisitions, product launches and market developments all point toward the same…

 

Australia’s national face matching system expands with NSW participation

New South Wales (NSW) is joining Australia’s national face matching network, allowing driver licence and photo card images to be…

 

From behavior to payment: Visa builds trust across the customer lifecycle

Visa’s agreement to acquire BioCatch for $2.4 billion raises an important strategic question: Why would a global payments network invest…

 

Why deepfake detection is becoming trust infrastructure

For many, the word “deepfake” still has a twinge of novelty about it – a hint of science fiction. But…

 

Brazil age assurance challenge overlooks privacy-preserving options

Where there are online safety laws, there is litigation aiming to curb them. So it goes in Brazil, where the…

 

Post-quantum identity expands beyond cryptography

As governments and enterprises prepare for practical quantum computing, the focus has largely been on post-quantum cryptography. IBM is targeting…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events