CYBERSECURITY AI SECURITY

Yubico and OpenAI Partner on Hardware Security for GPT-5.6

TM
Techmediaglobal
| 4 min read
73.5%
EXPLOITBENCH SCORE
24.9%
EXPLOITGYM (2HR)
71.2%
SEC-BENCH PRO
SEPT 1
2026 DEADLINE

OpenAI's launch of its GPT-5.6 model family brings more than raw performance gains. The company is now mandating hardware-backed passkey authentication for individual members of its Trusted Access for Cyber (TAC) programme, and Yubico CEO Jerrod Chong calls it a major validation of hardware security keys as the strongest defence against account takeover.

A New Security Mandate for High-Risk AI Access

From 1 September 2026, individual TAC members must enable Advanced Account Security using a hardware-backed passkey to retain access to OpenAI's most cyber-capable frontier models. Members who fail to meet the requirement will revert to default access levels.

The mandate accompanies the release of GPT-5.6 Sol, OpenAI's latest model, which delivers significant gains across cybersecurity benchmarks while expanding the defensive tasks available to verified users through the TAC programme.

Model Performance and Security Benchmarks

OpenAI describes GPT-5.6 Sol as its strongest cybersecurity model to date, delivering major improvements across software security benchmarks while using significantly fewer tokens than its predecessor.

The model achieved 73.5% on ExploitBench, up from GPT-5.5's 47.9%. It nearly doubled peak performance on ExploitGym, rising from 15.1% to 24.9% within a two-hour limit, and improved its SEC-Bench Pro score from 45.8% to 71.2%, showing stronger capability in proof-of-concept generation for complex software.

Beyond benchmarks, OpenAI says GPT-5.6 supports defensive security tasks including secure code review, patching, threat modelling and blue teaming. Qualified TAC members can also access enhanced capabilities for vulnerability triage and validation, malware analysis, detection engineering and patch validation within authorised environments.

Hardware-Backed Authentication as Access Control

The capabilities delivered by GPT-5.6 require authentication mechanisms that can withstand sophisticated account takeover attempts. To strengthen the defences around these higher-risk capabilities, OpenAI is requiring individual TAC members to secure their accounts with hardware-backed passkeys.

OpenAI had previously partnered with Yubico to bring hardware-backed security keys directly to ChatGPT users, and has now introduced preferred pricing on Yubico security keys for members who don't already have one.

"By requiring hardware-backed passkeys rather than sync passkeys or software-based alternatives, OpenAI is validating that our product is the best defence for account takeover."

Jerrod Chong, CEO, Yubico

Deepening the Yubico-OpenAI Relationship

Yubico already supplies security keys to protect OpenAI employees and infrastructure. The new requirement extends that relationship to users seeking access to OpenAI's most advanced cybersecurity models, and OpenAI says it is also implementing additional restrictions for high-risk entities and jurisdictions.

Chong called the directive "a significant strategic and commercial validation for Yubico", adding that it will help drive adoption of the companies' OpenAI YubiKey bundles across the TAC ecosystem and deepen a partnership built on protecting OpenAI's own employees and infrastructure.

Authentication Architecture for Frontier Models

By making hardware-backed passkeys a condition of access for its most capable cybersecurity models, OpenAI could be signalling that phishing-resistant authentication is becoming a core architectural safeguard rather than an optional security feature.

The mandate effectively treats authentication strength as a control plane for capability access, linking account security posture directly to the risk profile of available model features. For organisations deploying TAC programme access, this could mean reassessing authentication infrastructure and key management workflows to ensure hardware-backed credentials are provisioned and enforced at the identity layer.

The approach suggests that as model capabilities continue to advance, authentication requirements may become increasingly differentiated based on the security risk associated with specific model features or deployment contexts.

Key Takeaways

  • From 1 September 2026, individual TAC members must enable hardware-backed passkey security to keep access to OpenAI's most cyber-capable models.
  • GPT-5.6 Sol scored 73.5% on ExploitBench, 24.9% on ExploitGym, and 71.2% on SEC-Bench Pro, all major jumps over GPT-5.5.
  • OpenAI is offering preferred pricing on Yubico security keys for TAC members without hardware-backed passkeys.
  • Yubico CEO Jerrod Chong calls the mandate a major strategic and commercial validation of hardware-backed authentication.
  • OpenAI is also adding extra restrictions for high-risk entities and jurisdictions accessing GPT-5.6's cybersecurity capabilities.
  • The move signals that phishing-resistant authentication is becoming a core architectural safeguard for frontier AI access, not just an optional add-on.
Tags: Cybersecurity Hardware Passkeys GPT-5.6 AI Security TAC Programme Yubico OpenAI Account Security