In everyday words
It’s a lock-down mode for your ChatGPT account: you sign in with passkeys or hardware keys, and recovery becomes stricter.
Need a meaning?
A phishing-resistant sign-in method based on public-key cryptography, often stored in a device’s secure hardware.When an attacker gains control of an account through phishing, credential theft, or session hijacking.
Quick Sip
What you need to know
- Who is affected
- AI users, security teams, policy watchers
- What changed
- On April 30, 2026, OpenAI announced Advanced Account Security for ChatGPT logins, requiring passkeys or security keys and tightening recovery and session protections; the setting also applies to Codex.
- Why it matters
- As ChatGPT accounts store sensitive context and connect to tools, account takeovers become higher impact. Phishing-resistant sign-in can reduce risk, but stricter recovery raises the cost of losing keys.
- What to watch next
- Watch how availability expands to workspace and enterprise setups, and how users balance stronger protection with tougher recovery.
Four useful details
- Requires passkeys or security keys and disables password-based login.
- Adds recovery keys and tighter account recovery rules.
- Shortens active sessions and adds more visibility into account activity.
OpenAI · Official AnnouncementOffering Zero Data Retention for frontier models ↗
Adds source-backed context on ai safety from OpenAI.
OpenAI · Official UpdateAdvancing content provenance for a safer, more transparent AI ecosystem ↗Adds source-backed context on ai news from OpenAI.
Notion · Official AnnouncementIntroducing Notion’s Developer Platform ↗Adds source-backed context on ai tools from Notion.
Your next sip
All latest briefings →