Yubico, the pioneer of phishing-resistant authentication and creator of the YubiKey, has expanded its partnership with OpenAI into Australia and nine additional countries as OpenAI begins requiring hardware-backed passkeys for members of its Trusted Access for Cyber program.
OpenAI’s Advanced Account Security (AAS) program went live on 1 September 2026, requiring hardware-backed passkeys for all members of its Trusted Access for Cyber (TAC) program.
At the same time, Yubico has expanded its partnership with OpenAI by making the custom two-pack OpenAI + YubiKey bundle available in 10 additional countries: Australia, Egypt, Japan, Malaysia, Mexico, Saudi Arabia, Singapore, South Korea, Taiwan, and the United Arab Emirates.
The expansion is designed to support wider adoption of phishing-resistant authentication as organisations and individuals increasingly use powerful AI technologies for sensitive research, software development, and business workflows.
As AI capabilities advance, protecting access to AI platforms is becoming an increasingly important cybersecurity requirement. Yubico believes trusted use of AI depends not only on model safety but also on strong identity and authenticator assurance.
Hardware-backed passkeys can help disrupt attacks that rely on stealing credentials and taking over legitimate accounts.
For members of the TAC program, the requirement raises the level of protection around access to advanced AI capabilities and makes compromised accounts significantly harder for cybercriminals to obtain and resell.
The same technology can also be used to strengthen protection for consumer ChatGPT and Codex accounts, helping secure personal projects, proprietary code, and sensitive workflows against account takeover.
OpenAI strengthens protection against phishing attacks
Under OpenAI’s AAS program, enrolling security keys disables weaker, phishable authentication methods to create a higher-assurance account environment.
Traditional multi-factor authentication methods, including SMS one-time passwords and push notifications, can be intercepted or bypassed by sophisticated phishing techniques such as Adversary-in-the-Middle attacks.
Hardware-backed security keys provide a phishing-resistant root of trust using credentials that cannot be copied or silently synced between devices.
To support OpenAI users adopting the technology, existing account holders can access custom-branded YubiKeys at preferred pricing through the OpenAI and Yubico partnership.
The bundle includes:
- YubiKey C NFC – OpenAI: Designed for tap-to-authenticate protection across compatible mobile devices, tablets, and computers.
- YubiKey C Nano – OpenAI: A low-profile security key designed to remain in a laptop’s USB-C port for convenient ongoing authentication.
Once enrolled, users can access their accounts using phishing-resistant, hardware-backed passkey authentication without relying on traditional passwords.
As Australia joins the expanded rollout, the partnership signals a tougher approach to account security for those using OpenAI’s cyber defence tools, with phishing-resistant hardware now becoming a required part of access.
For more information about securing ChatGPT and Codex accounts with YubiKeys, visit Yubico’s OpenAI and YubiKey page or OpenAI Advanced Account Security.

