OpenAI and Yubico have announced a partnership on phishing-resistant authentication. OpenAI users can now buy a custom two-pack of YubiKeys as part of the Advanced Account Security programme, protecting their account with hardware-backed passkeys.
Regular readers will recognise the trajectory. In Issue #001 we covered OpenAI requiring hardware keys for its Trusted Access for Cyber programme, a control applied to a small population with access to dangerous capability. This announcement takes the same control and offers it to everyone with an account and the price of a two-pack.
Why identity teams should care
Hardware-backed passkeys are crossing from a privileged-user control to a consumer product, sold at checkout by one of the most mainstream software brands in the world. That shift changes the conversation inside your organisation in a specific way: the "our users will never carry a hardware key" objection gets weaker every time a consumer platform normalises exactly that.
It also sharpens the question we asked in August, which transfers directly: if OpenAI thinks a chatbot account justifies a hardware key, which of your internal systems still protects more capability with less credential?