

OpenAI YubiKey Australia Partnership Expands as Hardware-Backed Passkey Mandate Begins
Custom OpenAI and YubiKey bundle reaches Australia and nine additional countries as OpenAI strengthens phishing-resistant account security.
The OpenAI YubiKey Australia partnership has expanded as OpenAI introduces stronger security requirements for users with access to advanced cyber capabilities.
Yubico, the creator of the YubiKey, has expanded its OpenAI partnership into Australia and nine other countries. The expansion comes as OpenAI starts requiring hardware-backed passkeys for members of its Trusted Access for Cyber program.
OpenAI launched its Advanced Account Security (AAS) program on September 1, 2026. The program requires hardware-backed passkeys for all members of Trusted Access for Cyber (TAC).
At the same time, Yubico has expanded its partnership with OpenAI. Its custom two-pack OpenAI + YubiKey bundle is now available in 10 additional countries.
Those countries are Australia, Egypt, Japan, Malaysia, Mexico, Saudi Arabia, Singapore, South Korea, Taiwan, and the United Arab Emirates.
OpenAI YubiKey Australia Expansion Targets Phishing-Resistant Access
The OpenAI YubiKey Australia expansion aims to support wider use of phishing-resistant authentication. The change comes as organisations and individuals increasingly use powerful AI systems for sensitive research, software development, and business workflows.
As AI capabilities grow, attackers have more incentive to target the accounts that control access to those systems. Protecting the login can therefore become just as important as protecting the underlying AI model.
Yubico argues that trusted AI use depends on more than model safety. Strong identity controls and authenticator assurance also play a critical role.
Hardware-backed passkeys can disrupt attacks that depend on stolen credentials and account takeover. For TAC members, the requirement adds stronger protection around access to advanced AI capabilities. It can also make compromised accounts significantly harder for cybercriminals to obtain and resell.
The technology can also strengthen consumer ChatGPT and Codex accounts. Users can add hardware-backed authentication to help protect personal projects, proprietary code, and sensitive workflows against account takeover.
OpenAI Strengthens Protection Against Phishing Attacks
Under OpenAI’s AAS program, users who enroll security keys disable weaker, phishable authentication methods. That approach creates a higher-assurance account environment.
Traditional multi-factor authentication can still leave users exposed to sophisticated phishing. SMS one-time passwords and some push-based authentication methods, for example, can face interception or bypass through techniques such as Adversary-in-the-Middle attacks.
Hardware-backed security keys take a different approach. They provide a phishing-resistant root of trust through credentials that attackers cannot simply copy or silently sync between devices.
This distinction matters because modern phishing increasingly targets authenticated sessions rather than passwords alone. Preventing an attacker from successfully presenting a credential to the wrong service can remove a major part of that attack chain.
OpenAI YubiKey Bundle Expands to Australia
Existing OpenAI account holders can access custom-branded YubiKeys at preferred pricing through the OpenAI and Yubico partnership.
The bundle contains two different security keys:
YubiKey C NFC – OpenAI
The YubiKey C NFC – OpenAI supports tap-to-authenticate protection across compatible mobile devices, tablets, and computers.
YubiKey C Nano – OpenAI
The YubiKey C Nano – OpenAI uses a low-profile design that allows users to keep the security key in a laptop’s USB-C port for convenient ongoing authentication.
After enrollment, users can access their accounts with phishing-resistant, hardware-backed passkey authentication instead of relying on traditional passwords.
The two-key approach also gives users an important practical advantage. A second hardware key can provide another authentication option if the primary key becomes unavailable.
Securing ChatGPT and Codex With Hardware-Backed Passkeys
The OpenAI YubiKey Australia expansion comes as identity becomes an increasingly important part of AI security.
Attackers who compromise an AI account may gain access to far more than a chatbot history. Depending on how an organisation uses the account, exposed information could include proprietary code, research, business data, prompts, connected workflows, or other sensitive material.
Phishing-resistant authentication does not eliminate every account security risk. However, hardware-backed passkeys can remove several common paths attackers use to steal reusable credentials.
For more information about securing ChatGPT and Codex accounts with YubiKeys, visit Yubico’s OpenAI and YubiKey page or OpenAI Advanced Account Security.
About Yubico
Yubico (Nasdaq Stockholm: YUBICO), the inventor of the YubiKey, offers the gold standard for phishing-resistant multi-factor authentication (MFA), stopping account takeovers in their tracks and making secure login easy and available for everyone. Since the company was founded in 2007, it has been a leader in setting global standards for secure access to computers, mobile devices, servers, browsers, and internet accounts. Yubico is a creator and core contributor to the FIDO2, WebAuthn, and FIDO Universal 2nd Factor (U2F) open authentication standards, and is a pioneer in delivering hardware-based passwordless authentication using the highest assurance passkeys to customers in 160+ countries.
Yubico’s solutions enable passwordless logins using the most secure form of passkey technology. YubiKeys work out-of-the-box across hundreds of consumer and enterprise applications and services, delivering strong security with a fast and easy experience.
The company is headquartered in Stockholm and Santa Clara, CA. For more information on Yubico, visit www.yubico.com.
