OpenAI Partners with Yubico to Bolster GPT-5.6 Security via Hardware Passkeys
![]()
Jerrod Chong, CEO of Yubico | Image Credit: Yubico
OpenAI’s upcoming GPT-5.6 will mandate hardware-backed passkeys starting in September, a move that Yubico CEO Jerrod Chong says confirms their product as the premier defense against account compromise.
OpenAI has launched the GPT-5.6 family of models, claiming they deliver frontier-level AI performance while consuming fewer tokens during operation.
The announcement introduces a new security requirement for individual members enrolled in OpenAI's Trusted Access for Cyber (TAC) program.
These users must now implement hardware-backed passkeys to retain access to the company's most powerful models.
Individual members of the program have until September 1, 2026, to enable Advanced Account Security using hardware-backed passkeys. Failure to comply will result in the loss of access to frontier models, reverting users to default access levels.

This security enhancement coincides with OpenAI’s release of its latest flagship model, GPT-5.6 Sol, which demonstrates significant improvements across cybersecurity benchmarks and expands defensive capabilities for verified users within the TAC program.
Model performance across cyber benchmarks
According to OpenAI, GPT-5.6 Sol achieves a score of 73.5% on ExploitBench, which measures a model's ability to progress from identifying vulnerable code to arbitrary code execution, compared to 47.9% for GPT-5.5. The company states this represents its strongest model performance to date.
ExploitGym is a benchmark that challenges agents to convert real-world vulnerabilities into working exploits. GPT-5.6's performance on ExploitGym rose from 15.1% for its predecessor to 24.9% within a two-hour operational limit.
On SEC-Bench Pro, which tests proof-of-concept generation, the score improved from 45.8% to 71.2% with GPT-5.6.
The company notes that token consumption decreased while these performance gains were achieved.
Cybersecurity performance matrix | Image Credit: OpenAI
GPT-5.6 supports tasks including secure code review, patching, threat modeling, and blue teaming. These functions are available to users with the appropriate access levels.
Through the Trusted Access for Cyber program, qualified members can access enhanced capabilities for vulnerability triage and validation. The model also supports malware analysis, detection engineering, and patch validation within authorized environments.
Hardware authentication becomes mandatory
OpenAI now requires individual Trusted Access for Cyber members to secure their accounts using hardware-backed passkeys.
The company previously partnered with Yubico to integrate hardware-backed security keys for ChatGPT users.
For users without existing hardware-backed passkeys, OpenAI has introduced preferred pricing for Yubico security keys.
“By requiring hardware-backed passkeys rather than sync passkeys or software-based alternatives, OpenAI is validating that our product is the best defence for account takeover.” Jerrod Chong, CEO of Yubico
The company states it is implementing additional restrictions for what it describes as high-risk entities and jurisdictions.
Yubico already provides security keys for OpenAI employees and infrastructure. This new requirement extends that relationship to users seeking access to the company's most advanced models.
"This directive represents a strategic and commercial validation for Yubico," says Jerrod Chong, CEO of Yubico.
"By requiring hardware-backed passkeys rather than sync passkeys or software-based alternatives, OpenAI is validating that our product is the best defence for account takeover."

Authentication as access control
Jerrod suggests this requirement could drive the adoption of OpenAI YubiKey bundles across the Trusted Access for Cyber ecosystem.
"This milestone deepens our partnership with OpenAI – which already relies on YubiKeys for protecting its own employees and infrastructure – and further strengthens our leadership in providing the highest level of authentication as state-of-the-art models scale," says Jerrod.
OpenAI's decision to mandate hardware-backed passkeys for access to its most capable models is a measured security move designed to limit unauthorized access to advanced capabilities.
Hardware-backed passkeys are considered more resistant to phishing attacks than software-based alternatives.
Related article
AI Guardrails Stifle Offensive Cybersecurity Researchers
For months, AI leaders have implemented strict vetting protocols and safety guardrails to prevent malicious actors from exploiting their models. However, these restrictions are now obstructing legitimate network defenders and offensive cybersecurity
OpenAI Leads 100-Signatory Push for Cyber Defence
OpenAI’s letter begins stating "we have a limited window to strengthen cyber defences". Credit: Getty ImagesMajor tech firms – including AWS, Google and Microsoft – urge governments to fund defensive tools, while critics call the manifesto self-servi
Anthropic Unleashes AI Agents on Shared Task, Sparking Internal Rivalry
What occurs when AI agents are pitted against one another? Anthropic’s recent tests reveal that the results can quickly become chaotic.On Thursday, Anthropic’s Frontier Red Team released new research analyzing how groups of AI agents interact when th
Related Special Topic Recommendations
Comments (0)
0/500
Jerrod Chong, CEO of Yubico | Image Credit: Yubico
OpenAI’s upcoming GPT-5.6 will mandate hardware-backed passkeys starting in September, a move that Yubico CEO Jerrod Chong says confirms their product as the premier defense against account compromise.
OpenAI has launched the GPT-5.6 family of models, claiming they deliver frontier-level AI performance while consuming fewer tokens during operation.
The announcement introduces a new security requirement for individual members enrolled in OpenAI's Trusted Access for Cyber (TAC) program.
These users must now implement hardware-backed passkeys to retain access to the company's most powerful models.
Individual members of the program have until September 1, 2026, to enable Advanced Account Security using hardware-backed passkeys. Failure to comply will result in the loss of access to frontier models, reverting users to default access levels.

This security enhancement coincides with OpenAI’s release of its latest flagship model, GPT-5.6 Sol, which demonstrates significant improvements across cybersecurity benchmarks and expands defensive capabilities for verified users within the TAC program.
Model performance across cyber benchmarks
According to OpenAI, GPT-5.6 Sol achieves a score of 73.5% on ExploitBench, which measures a model's ability to progress from identifying vulnerable code to arbitrary code execution, compared to 47.9% for GPT-5.5. The company states this represents its strongest model performance to date.
ExploitGym is a benchmark that challenges agents to convert real-world vulnerabilities into working exploits. GPT-5.6's performance on ExploitGym rose from 15.1% for its predecessor to 24.9% within a two-hour operational limit.
On SEC-Bench Pro, which tests proof-of-concept generation, the score improved from 45.8% to 71.2% with GPT-5.6.
The company notes that token consumption decreased while these performance gains were achieved.
Cybersecurity performance matrix | Image Credit: OpenAI
GPT-5.6 supports tasks including secure code review, patching, threat modeling, and blue teaming. These functions are available to users with the appropriate access levels.
Through the Trusted Access for Cyber program, qualified members can access enhanced capabilities for vulnerability triage and validation. The model also supports malware analysis, detection engineering, and patch validation within authorized environments.
Hardware authentication becomes mandatory
OpenAI now requires individual Trusted Access for Cyber members to secure their accounts using hardware-backed passkeys.
The company previously partnered with Yubico to integrate hardware-backed security keys for ChatGPT users.
For users without existing hardware-backed passkeys, OpenAI has introduced preferred pricing for Yubico security keys.
“By requiring hardware-backed passkeys rather than sync passkeys or software-based alternatives, OpenAI is validating that our product is the best defence for account takeover.” Jerrod Chong, CEO of Yubico
The company states it is implementing additional restrictions for what it describes as high-risk entities and jurisdictions.
Yubico already provides security keys for OpenAI employees and infrastructure. This new requirement extends that relationship to users seeking access to the company's most advanced models.
"This directive represents a strategic and commercial validation for Yubico," says Jerrod Chong, CEO of Yubico.
"By requiring hardware-backed passkeys rather than sync passkeys or software-based alternatives, OpenAI is validating that our product is the best defence for account takeover."

Authentication as access control
Jerrod suggests this requirement could drive the adoption of OpenAI YubiKey bundles across the Trusted Access for Cyber ecosystem.
"This milestone deepens our partnership with OpenAI – which already relies on YubiKeys for protecting its own employees and infrastructure – and further strengthens our leadership in providing the highest level of authentication as state-of-the-art models scale," says Jerrod.
OpenAI's decision to mandate hardware-backed passkeys for access to its most capable models is a measured security move designed to limit unauthorized access to advanced capabilities.
Hardware-backed passkeys are considered more resistant to phishing attacks than software-based alternatives.
AI Guardrails Stifle Offensive Cybersecurity Researchers
For months, AI leaders have implemented strict vetting protocols and safety guardrails to prevent malicious actors from exploiting their models. However, these restrictions are now obstructing legitimate network defenders and offensive cybersecurity
OpenAI Leads 100-Signatory Push for Cyber Defence
OpenAI’s letter begins stating "we have a limited window to strengthen cyber defences". Credit: Getty ImagesMajor tech firms – including AWS, Google and Microsoft – urge governments to fund defensive tools, while critics call the manifesto self-servi
Anthropic Unleashes AI Agents on Shared Task, Sparking Internal Rivalry
What occurs when AI agents are pitted against one another? Anthropic’s recent tests reveal that the results can quickly become chaotic.On Thursday, Anthropic’s Frontier Red Team released new research analyzing how groups of AI agents interact when th





Home






