FutureFive Australia - Consumer technology news from the future
Yubico expands OpenAI passkey partnership to Australia

Yubico expands OpenAI passkey partnership to Australia

Thu, 3rd Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Yubico has expanded its partnership with OpenAI to Australia and nine other countries, coinciding with OpenAI's requirement for hardware-backed passkeys in its Trusted Access for Cyber program.

The expansion makes a co-branded two-pack of YubiKey devices available in Australia, Egypt, Japan, Malaysia, Mexico, Saudi Arabia, Singapore, South Korea, Taiwan and the United Arab Emirates. OpenAI's Advanced Account Security program now requires members of its Trusted Access for Cyber group to use hardware-backed passkeys.

The move combines a broader commercial rollout with a stricter security standard for a group of OpenAI users whose accounts may be higher-value targets for attackers. It also extends a partnership previously limited to fewer markets.

Access controls

Under OpenAI's Advanced Account Security program, users who enroll security keys have weaker sign-in methods disabled. That means traditional multi-factor authentication tools such as SMS one-time passwords and push notifications can no longer be used for those accounts.

Those older methods remain widely used across consumer and business services, but security specialists have long warned they can be intercepted or bypassed through phishing, including adversary-in-the-middle attacks. Hardware-backed passkeys aim to reduce that risk by tying authentication to a physical device rather than a code that can be captured and replayed.

The bundle available to OpenAI users includes two USB-C security keys: the YubiKey C NFC - OpenAI, which supports tap-based authentication across compatible mobile devices, tablets and computers, and the YubiKey C Nano - OpenAI, a low-profile key designed to remain inserted in a laptop USB-C port.

Once enrolled, users can sign in with hardware-backed passkey authentication instead of relying on conventional passwords. Existing account holders can obtain the co-branded keys at preferred pricing through the partnership.

Wider use

The rollout comes as AI systems are increasingly used for software development, research and internal business tasks involving sensitive information. That raises the stakes for account security for both companies and individual users, especially where access includes proprietary code, internal workflows or personal projects.

The same hardware-backed authentication can also be used to protect consumer ChatGPT and Codex accounts, broadening the partnership's relevance beyond the Trusted Access for Cyber cohort to a wider base of OpenAI users.

Yubico argues that secure use of AI systems depends not only on model safety but also on stronger identity checks and assurance that the person signing in is the legitimate account holder. In practical terms, physical security keys are intended to make compromised accounts harder to obtain and resell.

Standards push

Founded in 2007, Yubico is known for the YubiKey line and has been involved in developing authentication standards including FIDO2, WebAuthn and U2F. It says it serves customers in more than 160 countries and has focused on passwordless login tools based on physical authenticators.

The latest OpenAI tie-up gives Yubico a visible role as AI developers and users face growing pressure to strengthen account protection. Security around access to AI tools has become more prominent as those services become embedded in business operations and software workflows.

For OpenAI, the Trusted Access for Cyber requirement marks a more prescriptive approach to account security for selected users. Rather than offering stronger login options as an upgrade, it has made hardware-backed passkeys mandatory within the program.

That distinction matters because it removes a range of login methods that are easier for attackers to exploit. By requiring a physical key, OpenAI is narrowing the path to account access at a time when compromised credentials remain a common route into online services.

The ten-country expansion means Australian users are now part of the wider push toward physical authentication for AI-related accounts, alongside markets across Asia, the Middle East, Latin America and North Africa.

Yubico says hardware-backed security keys provide a phishing-resistant root of trust using credentials that cannot be copied or silently synced between devices.