• Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
Monday, September 21, 2026
freevirtualsolutions.com
  • Home
  • Virtual Assistant
  • Enterprise Technology
  • Customer Support
  • Marketing Support
  • Workforce Management
No Result
View All Result
  • Home
  • Virtual Assistant
  • Enterprise Technology
  • Customer Support
  • Marketing Support
  • Workforce Management
No Result
View All Result
Free Virtual Solutions
No Result
View All Result
Home Enterprise Technology

OpenAI Makes Hardware Passkeys Mandatory For Its Highest-End Cyber Model

Ermias S. by Ermias S.
2 months ago
in Enterprise Technology
0
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


In April 2025, OpenAI announced that it will require its users to complete formal, government-issued, national ID document-based identity verification (IDV). Now OpenAI has announced that, effective September 1, 2026, Trusted Access for Cyber (TAC) accounts will be required to authenticate using hardware passkeys to access OpenAI’s most advanced cyber AI models. This capability will need to be enabled via OpenAI’s Advanced Account Security. OpenAI announced special hardware passkey pricing for Yubico YubiKeys, namely YubiKey C NFC (predominantly for mobile devices) and YubiKey C Nano (for desktops that have a mini-USB connector). OpenAI also supports other FIDO-compatible hardware keys for Advanced Account Security.

Hardware-based FIDO passkeys improve security, but they also introduce new challenges that customers should consider:

  • Using API keys for TAC services cannot be fully automated. If invocation of GPT-5.6 models via APIs requires hardware FIDO passkey-based authentication, then an authorized user must manually perform this ceremony at least once (provided that API keys can be stored on the API caller’s end). This may result in service outages. If not every API model invocation requires authenticating via FIDO passkeys, then the mechanism is vulnerable to session theft — something that is unique to the OpenAI case. This can be especially inconvenient when trying to meet DevOps CI/CD integration or emergency access requirements.
  • Hardware key usage means organizations and users must absorb new device and management costs. Hardware keys are — in a way — a return to one-time password generators (such as RSA SecurID tokens) that create higher management costs (e.g., shipping keys to users, replacing lost hardware tokens). Because Yubico does not store the seed of its hardware keys centrally, OpenAI must provide self-service that allows for recovery of hardware keys. Currently, when users enroll in Advanced Account Security, OpenAI disables all SMS and email account recovery permanently and mandates that users register a hardware security key, plus another either software or hardware FIDO passkey. Organizations should also consider that USB-C-only-based hardware keys may not be compatible with all mobile devices, which could create user experience challenges. Users with limited dexterity and vision may also encounter additional friction when trying to use hardware keys.
  • Hardware keys could hinder equal access to higher-end AI models. Given that hardware FIDO passkeys may be unavailable in certain geographies, mandating passkeys may de facto automatically exclude access to these high-end models from certain countries or regions.

Device-bound, software-only FIDO passkeys (which should be required only for researching and using high-risk security AI technologies), complemented with a secure synchronization mechanism (such as password managers including 1Password or Dashlane) and continuous, contextual authentication, could be a more convenient alternative than hardware passkeys. Organizations should understand that there are trade-offs associated with implementing hardware-based strong authentication.

Forrester clients who want to dive deeper into this topic and discuss how they should implement IAM for LLMs can schedule an inquiry or guidance session with me.



Source_link

Tags: CyberHardwareHighestEndMandatorymodelOpenAIPasskeys
Previous Post

NVIDIA’s Open Secure AI Alliance Targets the Growing Security Risks of Autonomous AI Agents

Next Post

The Rowboat | Seth’s Blog

Next Post
Hiding the ‘aha’

The Rowboat | Seth's Blog

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Customer Support (1,762)
  • Enterprise Technology (4,563)
  • Marketing Support (3,885)
  • Virtual Assistant (4,147)
  • Workforce Management (1,535)

Free Virtual Solutions

Welcome to freevirtualsolutionsThe goal of freevirtualsolutions is to give you the absolute best news sources for any topic! Our topics are carefully curated and constantly updated as we know the web moves fast so we try to as well.

Category

  • Customer Support
  • Enterprise Technology
  • Marketing Support
  • Virtual Assistant
  • Workforce Management

Recent Post

  • Top Advantages of Moving Beyond a PEO in 2026
  • Schneider says hotter coolant can make AI datacenters less thirsty
  • How WFM Software Can Positively Impact a Contact Center Culture
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Copyright © 2023 Freevirtualsolutions.com | All Rights Reserved.

No Result
View All Result
  • Home
  • Virtual Assistant
  • Enterprise Technology
  • Customer Support
  • Marketing Support
  • Workforce Management

Copyright © 2023 Freevirtualsolutions.com | All Rights Reserved.

Chat with us

Hi there! How can I help you?