In April 2025, OpenAI announced that it will require formal, government issued national ID document-based identity verification (IDV) to its users. Now OpenAI announced that, effective September 1, 2026, Trusted Access Cyber (TAC) accounts will be required to authenticate using hardware passkeys to access OpenAI’s most advanced cyber AI models. This capability will need to be enabled via OpenAI’s Advanced Account Security. OpenAI announced special hardware passkey pricing for Yubico Yubikeys, namely YubiKey C NFC (predominantly for mobile devices) and YubiKey C Nano (for desktops that have a mini-USB connector). OpenAI also supports other FIDO compatible hardware keys for Advanced Account Security.

Hardware-based FIDO passkeys improve security, but they introduce new challenges that customers should consider:

  • Using API keys for TAC services cannot be fully automated. If invocation of GPT-5.6 models via APIs requires hardware FIDO Passkey based authentication, then an authorized user must manually perform this ceremony at least once (provided that API keys can be stored on the API caller’s end). This may result in service outages. If not every API model invocation requires authenticating via FIDO Passkeys, then the mechanism is vulnerable to session theft – something that is unique to the OpenAI case. This can be especially inconvenient when trying to meet DevOps CICD integration or emergency access requirements.
  • Hardware keys means organizations and users must absorb new device and management costs. Hardware keys are – in a way – a return to one time password generators (such as RSA SecurID tokens) which create higher management costs (e.g. shipping keys to users, and replacing lost hardware tokens). Since Yubico does not store the seed of its hardware keys centrally, OpenAI must provide self-services that allow for recovery of hardware keys. Currently when users enrolls in Advanced Account Security, OpenAI disables all SMS and email account recovery permanently and mandates that users register a hardware security key, plus another either software or hardware FIDO passkey. Organizations should also consider that USB-C only based hardware keys may not be compatible with all mobile devices which could create user experience challenges. Users with limited dexterity and vision may also encounter additional friction when trying to use hardware keys
  • Hardware keys could hinder equal access to higher-end AI models. Given that hardware FIDO passkeys may be unavailable in certain geographies, mandating passkeys may de facto automatically exclude access to these high-end models from certain countries or regions.

Device bound software only FIDO Passkeys (which should be required only for researching and using high-risk security AI technologies), complemented with a secure synchronization mechanism (such as password managers including 1Password or Dashlane) and continuous, contextual authentication could be more convenient alternative than hardware passkeys. Organizations should understand that there are tradeoffs associated with implementing hardware based strong authentication.

Forrester clients who want to dive deeper into this topic and discuss how they should implement IAM for LLMs schedule an inquiry or guidance session with me.

 

Share