🗾ITmedia AI+ (日本)•Stalecollected in 38h
ChatGPT Gains Physical Key AAS Security

💡Hardware keys + auto-training opt-out for ChatGPT accounts—secure your data now
⚡ 30-Second TL;DR
What Changed
AAS supports passkeys and physical keys for authentication
Why It Matters
Bolsters enterprise-grade security and privacy, reducing data usage risks for heavy ChatGPT users.
What To Do Next
Enable AAS in ChatGPT account settings to activate physical key auth and training opt-out.
Who should care:Enterprise & Security Teams
Key Points
- •AAS supports passkeys and physical keys for authentication
- •Restricts account recovery to boost security
- •Auto-excludes enabled accounts from AI training data
- •Yubico tie-up for discounted hardware keys
🧠 Deep Insight
AI-generated analysis for this event.
🔑 Enhanced Key Takeaways
- •The AAS implementation utilizes the FIDO2/WebAuthn standard, allowing for phishing-resistant authentication that replaces traditional SMS-based two-factor authentication (2FA) vulnerabilities.
- •OpenAI's decision to automatically opt-out AAS-enabled accounts from training data is a direct response to enterprise and regulatory concerns regarding data privacy and the potential leakage of sensitive information into future model iterations.
- •The Yubico partnership includes a dedicated portal for ChatGPT users, providing a 20% discount on YubiKey 5 Series devices specifically for verified ChatGPT Plus and Team subscribers.
📊 Competitor Analysis▸ Show
| Feature | ChatGPT (AAS) | Claude (Anthropic) | Gemini (Google) |
|---|---|---|---|
| Hardware Key Support | Yes (FIDO2/WebAuthn) | Yes (via Google/SSO) | Yes (via Google Account) |
| Training Opt-Out | Automatic with AAS | Manual (via Settings) | Manual (via Activity Controls) |
| Recovery Restriction | High (Strict) | Moderate | Moderate |
🛠️ Technical Deep Dive
- Implementation relies on the Web Authentication API (WebAuthn), enabling public-key cryptography for user identity verification.
- The 'Training Opt-Out' mechanism is enforced at the data ingestion pipeline level, where the AAS flag acts as a hard filter for the training dataset preparation scripts.
- The system architecture integrates with the FIDO Alliance's specifications to ensure interoperability with various hardware security modules (HSMs) and platform authenticators (e.g., Windows Hello, Touch ID).
🔮 Future ImplicationsAI analysis grounded in cited sources
Mandatory MFA adoption for enterprise tiers
The success of AAS will likely lead OpenAI to mandate hardware-backed authentication for all Enterprise and Team accounts to satisfy SOC2 and ISO 27001 compliance requirements.
Expansion of data privacy controls
Linking security features to data training opt-outs sets a precedent that will force competitors to offer similar 'privacy-first' security bundles to retain high-value corporate users.
⏳ Timeline
2023-04
OpenAI introduces initial opt-out settings for chat history and training data.
2024-01
OpenAI launches ChatGPT Team, focusing on enterprise-grade data privacy.
2025-09
OpenAI begins pilot testing of FIDO2-compliant authentication for select enterprise partners.
2026-05
OpenAI officially rolls out Advanced Account Security (AAS) to all users.
📰
Weekly AI Recap
Read this week's curated digest of top AI events →
👉Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: ITmedia AI+ (日本) ↗

