OpenAI Daybreak signals a new era for AI security and the critical role of hardware security keys OpenAI now requires individual users of its Daybreak frontier model stack for advanced cybersecurity research to enroll in Advanced Account Security and authenticate with FIDO2 hardware security keys, with existing users given until October 1, 2026 to comply or lose access. Under the policy, hardware keys must be the only registered login methods and software or synced passkeys do not qualify, a change Yubico framed as reflecting that "the more powerful the AI, the stronger the identity protection must be." The requirement makes phishing-resistant, hardware-backed authentication the access control plane for high-capability AI accounts that attackers increasingly target for access to frontier models and proprietary data. The race to build increasingly powerful AI models is accelerating. But as AI capabilities advance, so too does the value of the accounts that provide access to them. A clear example of this shift is OpenAI’s Daybreak https://openai.com/daybreak/ , its frontier model stack for advanced cybersecurity research. New individual users seeking access to Daybreak must enroll in Advanced Account Security https://chatgpt.com/advanced-account-security AAS and authenticate using stronger forms of security, such as FIDO2 hardware security keys. Existing users have until October 1, 2026 to meet these new security requirements in order to maintain access. The organizations building tomorrow’s AI platforms are setting new expectations for how users prove their identity and intent. As AI systems become more capable and autonomous, identity becomes the primary control plane. It’s an important milestone, and a recognition of a broader reality: the more powerful the AI, the stronger the identity protection must be . AI is changing what is worth protecting Attackers no longer need complex infrastructure to bypass software-based tokens; automated tools can trick users and capture session tokens in real time. At the same time, AI has become a strategic business asset. Compromised credentials no longer just expose email or internal documents – they can grant adversaries access to frontier AI models, proprietary data, autonomous workflows, and mission-critical intellectual property. Attackers understand this shift, making high-capability AI accounts primary, high-value targets. For the most sensitive AI environments, organizations recognize that phishing-resistant, hardware-backed passkeys are essential. That’s why governments, critical infrastructure providers, financial institutions and many of the world’s largest enterprises rely on hardware-backed authentication as the cornerstone of responsible access- ensuring privileged users and high-value accounts are protected at the highest standard. Why FIDO2 hardware security keys offer strong passkey protection OpenAI Daybreak gives qualified security teams and practitioners access to advanced AI capabilities to find vulnerabilities, validate findings, and strengthen the systems they protect. Protecting access to these capabilities is part of deploying them responsibly. Individual Daybreak users must enroll in Advanced Account Security and use compatible FIDO2 hardware security keys, including YubiKeys, to help protect their accounts from unauthorized access. Individual Daybreak access requires an eligible paid plan, Advanced Account Security, and at least one compatible FIDO2 hardware security key. Hardware keys must be the user’s only registered login methods, and software or synced passkeys do not qualify. The individual application flow checks these requirements before identity verification. Existing individual users must meet these requirements by Oct 1, 2026 to keep access. This decision reflects the growing need for the highest level of authenticator assurance when securing the world’s most capable AI technologies. Hardware security keys, such as YubiKeys, keep cryptographic material isolated from the host device and operating system. Trust becomes the control plane in the AI era As AI continues to reshape the security landscape and access to frontier AI models becomes increasingly valuable, trusted identity will become the foundation that enables organizations to innovate with confidence. It’s about ensuring that the right people , on trusted devices , can securely access the world’s most powerful technologies. Passwords and legacy multi-factor authentication MFA are no longer enough. For organizations protecting their most critical systems, privileged users and frontier AI, hardware-backed passkeys provide the highest level of phishing-resistant authentication available today. To learn how to secure your ChatGPT and Codex accounts with YubiKeys and get started today, visit here https://www.yubico.com/openai-and-yubico/ or chatgpt.com/advanced-account-security http://chatgpt.com/advanced-account-security .