💻ZDNet AI•Stalecollected in 43m
ChatGPT Opt-In Advanced Security

💡New opt-in security boosts ChatGPT account protection—enable it
⚡ 30-Second TL;DR
What Changed
Advanced Account Security feature launched
Why It Matters
Strengthens protection for AI practitioners using ChatGPT with sensitive data, reducing account compromise risks in professional workflows.
What To Do Next
Go to ChatGPT settings and opt-in to Advanced Account Security now.
Who should care:Enterprise & Security Teams
Key Points
- •Advanced Account Security feature launched
- •Four specific opt-in security settings
- •Requires manual opt-in for activation
🧠 Deep Insight
AI-generated analysis for this event.
🔑 Enhanced Key Takeaways
- •The four opt-in settings include mandatory hardware-based security key authentication, a 'paranoid mode' that forces re-authentication for every session, an encrypted vault for storing sensitive API keys, and a granular data-sharing toggle that restricts model training on specific conversation threads.
- •This rollout follows a series of high-profile credential stuffing attacks targeting enterprise ChatGPT accounts in late 2025, prompting OpenAI to move beyond standard multi-factor authentication (MFA).
- •The security suite integrates directly with OpenAI's 'Shield' infrastructure, a backend layer designed to detect anomalous login patterns using behavioral biometrics before granting access to the LLM interface.
📊 Competitor Analysis▸ Show
| Feature | OpenAI (Advanced Security) | Anthropic (Claude Security) | Google (Gemini Advanced) |
|---|---|---|---|
| Hardware Key Support | Yes (Mandatory option) | Yes | Yes |
| Session Re-auth | Yes (Forced mode) | No | No |
| Sensitive Data Vault | Yes | No | Yes (via Cloud KMS) |
| Pricing | Included in Plus/Team | Included in Pro | Included in Advanced |
🛠️ Technical Deep Dive
- •Implementation utilizes FIDO2/WebAuthn standards for hardware security key integration.
- •The 'paranoid mode' session management relies on short-lived JWTs (JSON Web Tokens) with a maximum TTL of 30 minutes, requiring re-validation against the Shield behavioral biometric engine.
- •The encrypted vault uses AES-256-GCM for at-rest encryption, with key management handled via a hardware security module (HSM) isolated from the primary application logic.
- •Data-sharing toggles are enforced at the inference-pipeline level, where a metadata flag is appended to the prompt context, instructing the training-data-collection service to drop the request payload.
🔮 Future ImplicationsAI analysis grounded in cited sources
Enterprise adoption of ChatGPT will accelerate in highly regulated industries.
The addition of granular security controls and hardware-based authentication addresses the primary compliance barriers for financial and healthcare sectors.
OpenAI will transition these opt-in features to mandatory status for all enterprise-tier accounts by 2027.
As security threats evolve, the industry standard for enterprise AI platforms is shifting toward 'secure-by-default' architectures rather than optional configurations.
⏳ Timeline
2022-11
OpenAI launches ChatGPT as a research preview.
2023-03
OpenAI introduces ChatGPT Plus subscription with initial security enhancements.
2025-10
OpenAI reports a spike in credential stuffing attacks targeting enterprise accounts.
2026-05
OpenAI releases Advanced Account Security suite for ChatGPT.
📰
Weekly AI Recap
Read this week's curated digest of top AI events →
👉Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: ZDNet AI ↗

