ChatGPT Work adds browser sign-in without exposing passwords to ChatGPT

ChatGPT Work adds browser sign-in without exposing passwords to ChatGPT
News

OpenAI says ChatGPT Work can now use its computer and browser to sign in to websites on the web and on mobile without ChatGPT seeing a user's username or password. The company shared the update through the official ChatGPT account on X on August 25, 2026. It gave three examples: setting up utilities for a new apartment, booking a DMV or passport appointment, and checking a reimbursement.

The announcement describes a change in the handoff between an AI agent and a person. ChatGPT Work can navigate to a service and do the surrounding work, but the user enters sensitive credentials in the browser. OpenAI's wording does not mean that the agent can access every website or complete every transaction automatically. A site may still require a user takeover, a second factor, a CAPTCHA, a payment confirmation or another permission step. The relevant safety boundary is that the secret itself should stay in the browser interaction rather than in the chat.

That distinction matters because many useful tasks are blocked by account sign-in. An assistant may be able to find an appointment or prepare a form, yet the final workflow traditionally stops when a password is needed. If ChatGPT Work can handle the page around that step while keeping the credential out of the model's visible context, more administrative tasks become possible without asking users to paste secrets into a conversation.

For individuals, the benefit is convenience with a clear responsibility: inspect the active website, account and requested action before allowing the agent to continue. A sign-in that does not reveal a password still grants access to personal information and may enable consequential actions. Users should therefore review confirmations and permissions just as they would when operating the site themselves.

For companies, the feature raises a practical governance question. Browser agents can reduce repetitive work, but organisations still need approved websites, least-privilege accounts, audit trails and rules for actions involving money, identity or regulated data. Developers building agent workflows will also need reliable pause-and-resume behaviour around authentication. OpenAI's post announces the capability and examples, but does not publish a technical security assessment or a complete list of supported sites. The immediate news is therefore a new interaction pattern, not a guarantee that every login-driven process is safe or fully autonomous.

Source x.com