Publication context
This reflection comes from a voice memo recorded on Sunday, July 5, 2026. The article faithfully preserves my analysis as of that date, without reworking it in light of later developments. AI platforms move fast: some features mentioned here may have been added, changed, or removed since. This text is a snapshot of a line of reasoning, not a permanent state of affairs.
Long before I ever thought about the security of my AI accounts, I had already built a habit I apply without exception to my most sensitive services: the moment a platform supports security keys, I turn them on. Google, Microsoft, Apple, LinkedIn, my banking services — this practice existed well before I ever configured my ChatGPT account. When OpenAI offered that option, I simply applied a habit that was already in place. It's this continuity, not some feature I stumbled onto, that led me, one Sunday in July 2026, to look differently at an account I use every single day.
Reducing the assumptions I make about trust
In GPG: the overlooked secret, I explained why GPG has, over several years, quietly earned a constant place in my digital routine: protecting the integrity and confidentiality of certain content, without treating it as something reserved for specialists. Security keys are, at bottom, the same practice applied at a different layer. Where GPG protects what I produce, security keys protect access to the accounts that handle what I produce.
Both reflexes answer to the same underlying logic: I'm progressively trying to reduce the assumptions of trust I make toward the systems I use. No longer assuming a password is enough. No longer assuming a service properly protects what's entrusted to it just because it's well-known or paid for. Verifying, rather than presuming.
Why I went to check Claude AI's security settings
That same logic is what led me to open, for comparison, my Claude AI account settings that Sunday, July 5, 2026. One more platform in an already well-worn routine, one more check among those I already run elsewhere. Nothing dramatic about the move — it's precisely because it had become routine for me that it let me notice, without any particular effort, the absence of something I expected to find.
What I took for granted before that day
Before this check, I had never really questioned an implicit assumption: that a professional, paid platform used in a work context would necessarily offer a level of account protection matching that use. MFA, security keys, fine-grained session management — I filed this kind of option under the same category as a website's HTTPS encryption, a prerequisite so obvious it doesn't seem worth checking.
That Sunday marks the moment this assumption stopped being a given and became a question I now actively apply to every service I bring into my work environment — AI assistants being just one example among others.
What I found
On my Claude AI account — a paid account, used in a professional context — I'm not claiming a feature doesn't exist. I'm simply noting that, during my checks on my own account this Sunday, July 5, 2026, I did not identify the level of protection I was looking for, particularly around the use of security keys and stronger authentication. I want to be deliberate about the scope of this observation: it's a finding on my own account, on this specific date, and there's no guarantee it still holds by the time you're reading this. Interfaces evolve, and features sometimes roll out progressively across accounts or regions — I'm documenting an experience, not a permanent state of the product.
On privacy and data handling, nothing I reviewed struck me as a problem. My point concerns one specific thing — strengthening authentication — not a blanket assessment of the platform. On other fronts, my experience with Claude AI remains, to this day, very positive: French voice exchanges, for instance, offer a quality I haven't found matched elsewhere. This voice memo isn't an indictment of a platform. It's the account of something my own security routine happened to surface.
Why AI assistants now belong on my usual list of requirements
What this check changed isn't my view of one particular platform, but the place I now give AI assistants in my evaluation criteria. Until then, I judged them mainly on what they let me do — model capabilities, usability, integrations, cost. Account security wasn't explicitly on that list, not out of carelessness, but because I hadn't yet mentally filed them alongside my Google, Microsoft, Apple, or banking accounts.
AI assistants are no longer simple conversation interfaces. They access documents, projects, and sometimes systems I control outside the platform itself — a topic I'll get into in a future article. An account that becomes a genuine work environment deserves the same protection I already demand from every other service where I use security keys. That shift, more than any judgment about a specific provider, is what this Sunday helped me put into words.
A philosophy that goes beyond user accounts
This requirement doesn't stop at how I use other people's tools. It directly shapes how I design software. When I build a SaaS product or a business application, I'd rather bake strong authentication mechanisms into the earliest architectural decisions than bolt them on later under pressure from a client, a security audit, or a regulatory requirement.
Security isn't a feature you add at the end of a project. It's part of the architecture.
This thinking goes well beyond my personal habits. It's now part of how I design systems: thinking about access and its protection alongside everything else, not as an afterthought, and certainly not as a reaction to outside pressure.
When security becomes a selection criterion
I'm not trying to rank AI platforms against each other on this point — such a ranking would be reductive, and likely outdated before it's even published. What I take away from that day is a broader principle: as AI assistants become genuine work environments, they join the list of services to which I already apply the same requirements as my Google, Microsoft, Apple, or banking accounts. Account security thus becomes a platform evaluation criterion on par with features — a natural consequence of a broader reflection on digital trust, not an isolated concern specific to AI.
Looking ahead
This observation is deliberately dated to July 5, 2026, and AI platforms are moving at a pace few software sectors have seen before. It's entirely possible the situation has changed by the time you read this. Technology moves fast. The principles that let us trust a system, on the other hand, stay remarkably stable — and it's on those principles, more than the state of any given feature at a given moment, that I'd rather build my choices.
That Sunday extends a reflection on digital trust that started with GPG, and it now leads me to look at other facets of the same question: security keys, trusted architectures, MCP, AI agents, and more broadly, how I design digital solutions. These are different angles on the same question, ones I plan to explore in future field reports.