Fez – OpenAI has introduced a new security feature designed to strengthen account protection on ChatGPT, as concerns grow over data privacy and cyber threats in professional environments.
The feature, called “Advanced Account Security,” is an optional setting that users can activate from their account security menu.
It aims to provide a higher level of protection against phishing attacks, account takeovers, and unauthorized access, risks that have become more serious as AI tools are increasingly used in sensitive work.
At the core of the update is a shift away from traditional passwords.
Instead, the system relies on passkeys or physical security keys, such as YubiKey.
This approach removes one of the most common vulnerabilities in digital security: stolen or compromised passwords.
The feature also disables weaker recovery methods, including email and SMS-based verification.
These methods have long been criticized by cybersecurity experts as easy targets for attacks such as SIM swapping or interception.
In their place, account recovery depends entirely on user-held recovery keys, which must be stored securely.
In addition, the system introduces tighter session management and real-time alerts for login attempts, reducing the window of opportunity for potential breaches.
Users who enable the feature will also benefit from enhanced data privacy, as their conversations are automatically excluded from model training processes.
OpenAI said the feature is primarily intended for high-risk users, including journalists, researchers, political figures, and organizations handling sensitive data.
It is also relevant for companies using advanced AI tools such as OpenAI Codex in critical work environments.
However, the company has issued a clear warning: activating the feature transfers full responsibility to the user.
If access keys and recovery keys are lost, the account cannot be restored, even by customer support.
This strict approach reflects a growing trend in cybersecurity, where eliminating backdoor access is essential to achieving strong protection.
Cybersecurity experts have largely welcomed the move, viewing it as part of a broader shift toward phishing-resistant authentication.
The decision to move away from SMS and email verification aligns with long-standing recommendations from security authorities, which have repeatedly flagged these methods as weak points.
Some analysts compare the feature to advanced protection models introduced by major technology firms, such as Google, suggesting that OpenAI is aligning its platform with the security standards required in government and financial sectors.
Still, concerns remain about usability. While effective from a security standpoint, the “no-recovery” policy places a significant burden on users.
Losing physical security keys without a backup could result in permanent loss of access, raising questions about how accessible such systems are for the broader public.
The launch positions OpenAI platforms as secure tools not only for individuals, but also for institutions that demand strict compliance and data protection standards.








