OpenAI wants your bank credentials. MFA is off by default. I have the screenshots
OpenAI just launched a finance feature. They're inviting users to connect live bank account credentials.
MFA is off by default. I have the screenshots.
I audited a free-tier ChatGPT account where the holder had deliberately disabled memory and chat history. Seven annotated screenshots documenting what the default settings actually are.
Here's what I found:
Model training is on by default. 'Improve the model for everyone' controls whether your conversations and uploaded files are used to train OpenAI's models. The account holder didn't touch it.
Marketing measurement and personalized marketing are both on by default. Neither was configured by the account holder. Data collection defaults on. Privacy defaults off. Consistent pattern.
Chat history was disabled. Storage showed 266 MB used. 846 files. 85 images. One archived chat visible in the UI from February. The file retention backend and the chat history UI are running on separate tracks.
And MFA, both authenticator app and text message, off by default. OpenAI's own finance feature announcement confirms this, stating users can 'enable multi-factor authentication to further secure your account.' Optional. Off unless you go find it.
They are asking for direct access to banking credentials on accounts where two-factor authentication is not on by default.
Screenshots are unedited. Captured May 16, 2026.