ChatGPT Adds Account Security History
OpenAI added ChatGPT security history, letting users review sign-ins, sign-outs, MFA, passkey, device, location, and security-setting changes.
The News
OpenAI’s ChatGPT release notes for September 25, 2026 introduced security history for OpenAI accounts. The affected surface is ChatGPT on the web under Settings, Security and login. Users can review recent sign-ins, sign-outs, changes to multi-factor authentication, passkeys, and other security settings, with event time, location, and device details. OpenAI notes some event details may be approximate or unavailable.
The OPTYX Analysis
This is an AI answer platform signal because account integrity is becoming part of the assistant operating layer. The mechanism is user-visible security telemetry, shifting identity events from opaque backend logs into a self-service review surface. Strategically, OpenAI is hardening ChatGPT for higher-value workflows where connected apps, memory, files, agents, and business actions raise the cost of account compromise. The change matters because assistants increasingly hold both knowledge access and execution authority, making login history a practical trust control rather than a commodity account feature.
Enterprise Impact
The exposed operator is the security administrator, workspace owner, privacy counsel, or AI governance lead responsible for employee ChatGPT use. The vulnerability is unmanaged account takeover across connected apps, saved context, and delegated workflows. The opportunity is to fold security history review into incident triage, offboarding checks, and suspicious activity playbooks. Required next move is an assistant access control procedure that covers MFA enforcement, passkey adoption, connected-app review, shared-device guidance, and escalation when location or device events do not match expected workforce patterns.
Locked Recommendations
This signal has triggered a material consequence alert. Strategic recommendations are locked pending analyst clearance.