ChatGPT's Major Change | OpenAI × Yubico Physical Security Key for ~$68 Now Available
機械翻訳 / Machine-translated

機械翻訳 / Machine-translated
@aifriends
AI Friends(https://aifriends.jp)のクロスポスト公式アカウント。AIツールの紹介・使い方・できることを、中学生でもわかるやさしい日本語で届けます。
"If your ChatGPT password is hijacked, your entire conversation history, custom instructions, and API keys are fully exposed" — that nightmare is no longer hypothetical.
On April 30, 2026, OpenAI partnered with Yubico to announce "Advanced Account Security," a way to physically protect your ChatGPT account. The co-branded two-key YubiKey bundle went on sale for approximately $68 (~¥10,000), completely eliminating password login. This is the arrival of the ultimate protection mode — secured by passkeys and physical keys alone.
This article walks through the full picture of Advanced Account Security: how passkeys and physical keys work, pricing and setup steps, the risks of losing your keys, who it's for, how it compares to competitors, and what Japanese users should do next.
Advanced Account Security (hereafter AAS) is the most powerful login protection mode in ChatGPT's history, completely replacing the conventional password-based approach. It requires two passkeys (cryptographic keys used in place of passwords) or physical security keys, and it ruthlessly eliminates email and SMS authentication entirely.
If the old ChatGPT was protected by "one key and a PIN," AAS is the equivalent of combining "a vault-grade physical key + fingerprint authentication + biometrics" — less like locking your front door and more like securing a bank safe-deposit box.
Setup is opt-in (you choose to activate it yourself), and all users including those on the free plan can enable it. However, because this is an extremely powerful mode with no way back once enabled, you must activate it carefully using the steps described below.
The partner in this deal deserves attention. Yubico is the world's leading manufacturer of physical security keys, adopted as standard by governments and large corporations worldwide — including internal use at Google, Microsoft, and Meta.
Through this partnership with OpenAI, two co-branded models — the "YubiKey C NFC" and the "YubiKey C Nano" — are being sold as a two-key bundle for $68 (~¥10,000). That's roughly half off the standard retail price of $126 — an aggressive price point, as if the world's top locksmith teamed up with a famous brand to offer a "special-edition vault key" at an accessible price.
Yubico CEO Jerrod Chow stated, "Our intent is to dramatically reduce the threat of unauthorized access to OpenAI accounts," making the commitment of both companies clear.
Let's look at why this is happening now. In 2024, security firm Group-IB discovered over 100,000 leaked ChatGPT credentials on the dark web. In 2025, a hacker group claimed to have stolen 20 million ChatGPT access codes.
Since ChatGPT's launch, phishing email volume has surged 1,265%, while AI-generated phishing content has exploded by 4,151% — an alarming situation. It's as if a wildly popular restaurant attracted a flood of pickpockets targeting its customers.
For OpenAI, the fear that "failing to take account security seriously will destroy trust" is the driving force behind Advanced Account Security.
Let's break down the key terminology. A passkey is a system that logs you in using a "cryptographic key stored inside your device" instead of a password — once you verify your identity with Face ID, Touch ID, or a PIN, sign-in happens automatically. It's based on the FIDO2 industry standard and is already supported by all OSes from Apple, Google, and Microsoft.
Think of it as upgrading your house key from "a code number you memorize and type in" to "a high-security vault that only opens with your fingerprint." Even if you accidentally land on a phishing site, the cryptographic key never leaves your device, so it can't be stolen.
This is the core technology of AAS, and it physically resolves the fundamental weakness of passwords.
Here's a breakdown of the two physical keys. The "YubiKey C Nano" is an ultra-compact key designed to stay plugged into your laptop's USB-C port — ideal for everyday desktop authentication. The "YubiKey C NFC" acts as a backup you simply tap to your smartphone's NFC reader, perfect for mobile access on the go or as a spare key.
Think of it as pairing an everyday chef's knife (the Nano) with a specialized filleting knife for special occasions (the NFC) — a two-key lineup that covers all scenarios.
What makes this remarkable is OpenAI selling this two-key bundle for $68 (¥10,000). Buying both models separately from Yubico's official store would normally cost $126+ (¥18,000), making this a significant discount — putting the ultimate account security configuration within reach for individuals.
Session management enhancements are another important feature. Once AAS is enabled, you'll receive a notification for every login from a new device, and you can view all currently active sessions (devices currently logged in) from your account settings and disconnect them instantly.
Session lifetimes are also set shorter, so even if a session token (a temporary pass that maintains your logged-in state) is stolen, the window for misuse is minimized by design. It's like installing security cameras at your shop's entrance, checking the face of every person who walks in, and immediately removing anyone suspicious.
You go from "logged in and unaware" to "monitoring all access with instant cutoff capability."
Let's break down the cost. The OpenAI × Yubico co-branded YubiKey two-key bundle (C NFC + C Nano) is $68, approximately ¥10,000 at current exchange rates. Buying both models individually from Yubico's official site would normally run $126+ (~¥18,000+), making this a roughly 46% discount — an extraordinary deal, like a popular manufacturer offering their latest model at half price through an official store.
For a security product, this is an exceptionally aggressive price point. Anyone with an OpenAI account can order directly from the official site, though shipping costs (~$20) and import duties apply separately since it ships from the US.
Japanese users can also substitute with the standard YubiKey C NFC (approx. ¥12,000) available on Amazon Japan or through domestic resellers — if you don't need the co-branded version, domestic sourcing is a faster option.
Here's the activation process in order. To enable AAS: ① Select "Advanced Account Security" in your ChatGPT account settings, ② Register two passkeys (primary device + backup device), ③ Register two YubiKeys, ④ Generate a recovery key (write it down and store it). That's four steps.
Once complete, password login is permanently disabled and cannot be restored. Think of it like buying a top-grade safe, making three keys (everyday, spare, and last resort), and storing the last one somewhere other than your home — that level of care is required.
After setup, you can't go back even if you forget your password, so writing your recovery key on paper and storing it in a home safe or safety deposit box is essential.
Here's the risk you most need to understand. After enabling AAS, if you lose all registered passkeys, YubiKeys, and your recovery key, OpenAI support cannot restore your account — it is permanently gone.
Your entire conversation history, custom instructions, API keys, and billing history are gone forever, which is why having multiple backup methods is not optional. It's like buying the ultimate safe to protect your home, then losing all the keys — and losing the house along with them.
Practically speaking, multiple backup layers are effectively mandatory: "Keep a spare YubiKey in a safe at your parents' home," "Store the recovery key on paper in a fireproof safe," "Give a trusted family member a backup YubiKey." Understand that this mode is designed to prioritize absolute security over convenience.
Here's who OpenAI is primarily targeting. OpenAI officially recommends AAS for "politically active dissidents, journalists, researchers, election workers, and others at high risk of cyberattack."
There have been multiple real-world incidents where nation-state hacker groups targeted the accounts of journalists and human rights activists, and concern about ChatGPT conversation histories becoming targets has materialized. Think of it as applying head-of-state-level protection to your personal ChatGPT account — that framing makes the significance clear.
In Japan as well, executives and legal staff handling corporate secrets, investigative journalists, and researchers at academic institutions stand to benefit significantly from AAS.
There's a clear enterprise use case too. Administrators on ChatGPT Business, Enterprise, and Edu plans can recommend AAS to all employees, and can even mandate it as an organizational security requirement.
In high-confidentiality industries like finance, healthcare, defense, and law, a compromised employee ChatGPT account could directly trigger a major incident — leaked strategic plans, customer data, or contract drafts. It's similar to triple-locking employee access cards with a physical IC chip, fingerprint authentication, and a PIN.
For Japanese companies, combining AAS with SSO (Single Sign-On) enables a configuration that maintains administrator-level governance while maximizing individual-level protection. At roughly ¥20,000 per employee for two YubiKeys, it's a realistic investment as a form of corporate insurance.
There is a specific category for which AAS becomes mandatory. OpenAI is requiring Advanced Account Security for participants in its "Trusted Access for Cyber" program — verified security researchers and defenders — starting June 1, 2026.
This program grants access to OpenAI's most powerful cybersecurity models (sensitive AI capable of both offensive and defensive use) to a select group of specialists. It's like requiring a buyer of top-tier professional knives to agree to strict security conditions before lending them out.
This doesn't affect general users, but it has major implications for specialists at the frontier of AI security research — and it symbolically establishes OpenAI's principle that "powerful AI requires powerful protection."
Here's where the competition stands. Anthropic's Claude has supported passkey login since 2025, enabling biometric sign-in. However, as of May 2026, no partnership with Yubico or co-branded hardware key offering has been announced.
In terms of security feature depth, OpenAI currently holds a lead, while Anthropic aligns with general industry standards. The distinction is: Claude takes the approach of a reliable conventional lock, while OpenAI has opted for vault-level security.
Companies using Claude for business purposes should anticipate similar enhancements in the near future, as a wave of security strengthening is expected to sweep the AI industry.
Here's how the major platforms compare. Google and Microsoft have supported passkey login and YubiKey integration for several years, and Microsoft also offers multi-factor authentication as standard through its Authenticator app.
However, an AI company partnering with Yubico to sell co-branded physical keys at a discount to its subscriber base is an industry first. It's like an electronics retailer collaborating with a manufacturer to offer a "bundled move-in package" — bringing a one-stop solution model to the AI industry.
OpenAI's move could be a pioneer in a new business model where "AI subscription services include security hardware as part of the offering."
Here's an objective security comparison. With traditional password + SMS two-factor authentication, if you're lured to a phishing site, your password and one-time SMS code can be stolen and your account instantly taken over.
AAS's passkey + physical key approach means the cryptographic key never leaves your device, so authentication on a phishing site cannot succeed in principle — attacks are physically blocked. If the old system was "a test where you memorize and enter a password and PIN," AAS is the equivalent of a safe that "absolutely cannot be opened without your fingerprint."
In an era when SlashNext reports AI-generated phishing has surged 4,151%, password-based systems have exceeded their limits. Migration to passkeys and physical keys is an industry trend that will arrive sooner or later.
Here are the purchase options for Japanese users. The OpenAI × Yubico co-branded YubiKey two-key bundle ($68) is available to order from the OpenAI official site, but since it ships from the US, expect approximately $20 in shipping plus import duties.
If you're not in a hurry, buying the standard YubiKey C NFC (approx. ¥12,000) and standard C Nano (approx. ¥8,000) separately from Amazon Japan or a domestic reseller will arrive faster. It's simply a choice between importing a US-exclusive package or buying the equivalent domestically.
For Japanese IT administrators and privacy-conscious users, passkeys alone are sufficient in many cases. A staged approach — starting with free passkeys on your existing iPhone, MacBook, or Android device, and adding physical keys as needed — is the most practical path.
Here's a look at how Japanese companies are likely to respond. Within 2026, major megabanks, large insurance companies, and top law firms are expected to begin mandating AAS for employees on ChatGPT Enterprise contracts.
The backdrop is a tripling of Japanese corporate ChatGPT usage in 2025 compared to the previous year, with more situations involving confidential information. It's similar to a corporate cafeteria where everyone has switched to mobile payments, prompting the company to issue dedicated IC card readers to all staff — a broad security upgrade driven by changing usage patterns.
Japan's Information-technology Promotion Agency (IPA) also warned in its 2025 report that "a robust authentication infrastructure is essential for enterprise use of generative AI," making AAS adoption a rational choice from a regulatory compliance perspective as well.
Let's also confirm the language situation. OpenAI's passkey setup guide is already available in full Japanese on the official Help Center, covering setup steps, troubleshooting, and FAQs entirely in Japanese.
The YubiKey's packaging and included manual are in English, but Yubico's official Japanese distributors provide Japanese-language support, making it accessible even for first-time users. It's like buying a premium foreign kitchen appliance that comes with a Japanese instruction manual and a domestic support hotline — a reassuring setup.
Even users who aren't confident in English can get through setup without issue by combining the OpenAI Help Center in Japanese with Yubico's Japanese distributor support. It works without issue in a Japanese keyboard environment and is fully usable in Japanese UI across Mac, Windows, iOS, and Android.
Nakamura-san is an investigative journalist in Tokyo covering financial crimes. In May 2026, as she found herself entering sources' names into ChatGPT more frequently, she grew concerned that a compromised account could put her sources in danger.
She purchased the OpenAI × Yubico YubiKey two-key bundle for $68, registered passkeys on her home main device and her work iPhone, and stored her recovery key in a fireproof safe. "It feels like I put my reporter's notebook in a digital vault — I can finally sleep soundly at night," she reflects.
It's the peace of mind that comes with locking a safe containing a restaurant's secret recipes with the strongest possible lock. For an investigative journalist, AAS offers an exceptional return on investment — "the ultimate insurance for protecting sources" at a cost of just a few thousand yen per month in expenses.
Sato-san oversees IT at a large Tokyo law firm where 200 attorneys routinely draft contracts using ChatGPT Enterprise. A single account breach could directly cause a catastrophic leak of confidential client agreements.
In May 2026, he revised the firm's internal guidelines and mandated AAS activation and two YubiKeys for every attorney, allocating an annual budget of approximately ¥4 million (200 people × ¥20,000). "It gives us the strongest possible compliance story — we can tell clients, 'Not a single attorney at our firm uses a password,'" he emphasizes.
The firm has unified every office's security to the highest standard and can now confidently tell clients, "Your information will never be leaked." This is on track to become standard equipment across the legal industry.
Suzuki-san is a freelance engineer based in Yokohama running multiple personal projects using the OpenAI API. After witnessing industry peers hit with fraudulent charges of hundreds of thousands of yen per month due to leaked API keys, he decided to implement AAS.
"A ¥10,000 two-key YubiKey bundle is cheap as an investment in protecting API keys," he concluded, and enabled it on his ChatGPT Plus account. "A passkey alone is already quite strong, but adding the physical key gives me absolute confidence I won't be taken over," he says.
It's the kind of decision that feels like installing a professional-grade high-security safe in your home kitchen — we're now in an era where even individuals can buy "absolute peace of mind." For freelancers and independent developers, AAS is not overkill; it's a realistic security investment.
A. If you handle sensitive information or want thorough security, yes — it's worth it.
Passkeys alone are free to set up and dramatically increase phishing resistance. The additional $68 investment in a two-key YubiKey bundle is for people who absolutely cannot afford to be compromised. For general use, it isn't mandatory — if you don't enter sensitive information and mostly use the free plan for casual conversation, traditional passwords plus multi-factor authentication is still adequate.
Whether you need vault-grade security for your home depends on what's inside. If what's inside is valuable, get the vault; for everyday living, a regular lock is enough. Same logic applies here.
A. The standard approach is to register two passkeys first, then add a YubiKey.
Since passkeys are free and work on all Apple, Google, and Microsoft devices, the first step is setting them up on your main device plus a backup device. A YubiKey then serves as a last resort in case of physical damage or device loss, giving you the ultimate configuration. AAS requires both and cannot be activated with a passkey alone.
Think of it as getting your everyday chef's knife (passkey) first, then buying the specialized filleting knife (YubiKey) for special needs — no need to acquire everything at once. Strengthening security in stages keeps the process manageable.
A. The recovery key is only the last resort if you've lost all your passkeys and YubiKeys.
Even if you lose your recovery key, you can still log in as long as you have at least one registered passkey or YubiKey remaining. However, losing all three — passkeys, YubiKeys, and the recovery key — creates a critical risk of permanent, unrecoverable account loss. Since even OpenAI support cannot restore it, writing your recovery key on paper and storing it in a fireproof safe or safety deposit box is strongly recommended.
The very fact that you have the ultimate safe means you must make three copies of the key and store the third in a separate location. Understand that this mode presupposes a willingness to choose thorough security over convenience.
A. The AAS feature itself is free — there are no additional charges whatsoever.
It can be enabled on all plans including ChatGPT Plus, Pro, Team, Enterprise, and Edu, as well as the free plan. The only additional cost is if you purchase a YubiKey — the co-branded bundle is $68 (~¥10,000), and it is optional, not required. Since passkeys are free and work on Apple, Google, and Microsoft devices, you can start with zero upfront cost.
Think of it like a restaurant offering the "special section" service for free, but charging extra if you want to order the premium wine (YubiKey) that goes with it. OpenAI is providing security upgrade options equally to all users without differentiating by price tier — that's worth acknowledging.
"If your ChatGPT account gets taken over, your life could change" — that fear can now be left in the past.
Advanced Account Security, announced by OpenAI on April 30, 2026, is the ultimate weapon to physically protect your ChatGPT account: a co-branded Yubico two-key YubiKey bundle at $68, the complete elimination of password login, and the strongest phishing resistance available. For journalists, researchers, and enterprise users, it is effectively a must-have; even general users can start for free with just a passkey setup.
Three steps you can take today: ① Register two passkeys in your ChatGPT settings (primary device + backup), ② Order a two-key YubiKey bundle if you handle sensitive information, ③ Write your recovery key on paper and store it in a fireproof safe. Account protection in the AI era is evolving to a new standard.
This article is a cross-post from AI Friends.