On 26 August, OpenAI said ChatGPT Work can use its computer and browser to sign in. The username and password still do not go to the model.
Until now, an agent could tell you what to do. The actual work sat behind a login: calendar, insurance, accounting, a permit portal. If the agent cannot get in, it stays a helper that writes a tidy set of instructions.
The job starts after the door opens
OpenAI’s own examples are ordinary. Book an appointment. File a reimbursement. Pull invoices out of email and put them in accounting software. Fill out a small-business permit. Schedule a vet visit. Arrange a package pickup.
No manifesto. Just the dull fields somebody still has to click.
The useful part is the wall
Login is not the story. The story is that the model does not see the credentials.
An agent needs access to tools. Otherwise it talks about work instead of doing it. The model itself still should not see passwords. If it can, the risk stops being theoretical.
That is the kind of agent we want to build at AI Generation. A request becomes a checked result. A person stays in charge. Sensitive credentials stay separate.
This does not make an agent safe by default
Browser use is still browser use. A company still has to decide where the agent may go, what it may send, and where the work has to stop as a draft.
ChatGPT Work moves AI from answering questions toward doing the job. The job description changes quietly. Draw the line now, not after something has already been submitted.
