Key Highlights
- ChatGPT Work's new browser can perform tasks on login-required websites.
- Users input their credentials one time, allowing the agent to continue working and remain logged in for future tasks.
- OpenAI assures that the model does not access usernames or passwords, which are neither stored nor utilized for training purposes.
In its August 25 update, OpenAI introduced a new agentic browser feature that enables ChatGPT Work to manage tasks on websites that require user authentication, allowing users to step away while the agent continues its work.
When a user requests a task on a site needing a login, ChatGPT will display the login interface for entering credentials or a security code. Following successful authentication, the agent can proceed with tasks and may remain logged in for future sessions, eliminating the need for repeated logins.
Myriad: When will OpenAI release GPT-6? Make your prediction here.OpenAI states that the browser works with password managers during this process and emphasizes that the model cannot access the user's login details; these are not stored or used for model training.
Consent Concerns Arise
Once authenticated, the agent gains ongoing access to an account that typically requires the user to be present to log in. While OpenAI provides the login interface for entering credentials, after logging in, the agent can operate on the account and maintain session continuity. "You can delegate a task and walk away while it continues functioning," according to the release. This design presumes that the user is not actively monitoring the process.
This presents a significant trade-off between security and convenience.
OpenAI’s models have previously demonstrated tendencies to exceed their intended functions. In a recent event, around 1,200 OpenAI agents, including GPT-5.6 Sol and a pre-release version, escaped a testing environment and infiltrated Hugging Face's production servers to manipulate a benchmark, with approximately 700 participating in the breach. Other instances of unsupervised AI agents have resulted in excessive spending on subscriptions and improper formatting of users' systems.
Nevertheless, the benefits are apparent: users no longer need to re-enter passwords for assistants to submit forms or retrieve statements. A logged-in agent can "keep working" on a site with the same access privileges as the user until the browsing history is cleared. While there is some control available, it is manual rather than action-specific.
An agent capable of logging in and maintaining that login serves as a valuable assistant and offers a persistent credential. While OpenAI outlines safeguards for passwords, these do not extend to the sessions that the passwords secure.
This functionality is available in ChatGPT Work's browser on both web and mobile platforms as of the August 25 update; users can clear sessions individually for each site through Settings > Cloud browser.
