ChatGPT can now do things on your behalf without seeing your login details

OpenAI has introduced a major update to ChatGPT Work, enabling the AI assistant to perform real-world tasks like flight cancellations, utility setups, and delivery reschedules without ever seeing your login credentials. By leveraging a secure cloud browser system, the platform can navigate signed-in websites and complete complex multi-step actions safely on mobile and desktop devices.

ChatGPT logo on a smartphone.

Managing day-to-day administrative tasks online usually requires jumping between multiple browser tabs, logging into distinct customer portals, and manually filling out web forms. OpenAI aims to streamline these routine chores by allowing its flagship chatbot to complete web actions directly on your behalf. Through its latest functional update, ChatGPT can now check your insurance, cancel plane flights, or reschedule package deliveries for you, all seemingly without seeing your login details.

Announced by OpenAI on X (formerly Twitter), the update marks a significant shift in how users interact with AI assistants. Instead of relying on the chatbot purely for writing, research, or basic text generation, users can now assign real-world errands that previously required opening a web browser and logging in manually with a username and password.

At the same time, OpenAI issued a clear safety reminder for all users. You should never drop your login details directly into AI chatbot conversations. Standard chat prompts are processed by language models and stored in conversation histories, making it unsafe to paste plain-text passwords into standard text interactions.

This Tweet is currently unavailable. It might be loading or has been removed.

What Is ChatGPT Work and Who Has Access to It?

The new automated capabilities function within ChatGPT Work, a specialized task management agent located directly inside the chatbot interface. This workspace tool is designed to pull fragmented workflows, personal errands, and professional to-do items into one central spot, eliminating the need to jump between separate applications and web services.

The feature is available across both mobile and web interfaces. However, access is restricted to paid subscription tiers, including Plus, Pro, and Business users. Subscribers on these plans can access the task management agent to initiate autonomous web browsing workflows from their smartphones or desktop computers.

The technical driving force behind this update is OpenAI's advanced GPT-5.6 engine. This underlying model powers the reasoning capabilities of ChatGPT Work, allowing it to interpret web page structures, understand form fields, and follow complex navigation paths required to execute online requests.

By integrating high-level language understanding with automated web navigation, the platform creates a seamless bridge between conversational prompts and active web execution. This centralization saves time for busy professionals and everyday users who want to consolidate their digital chores into a single interface.

What Tasks Can ChatGPT Work Complete for You?

Although workspace tools are frequently built with corporate environments in mind, this update expands well beyond traditional office boardrooms. According to OpenAI, the tool can carry out everyday consumer tasks that go far beyond standard document editing or corporate task tracking.

The upgraded system can handle a wide variety of personal and administrative tasks, including:

  • Setting up home utilities: Initiating service requests, entering address details, and submitting setup forms for home services when moving into a new residence.
  • Booking passport or medical appointments: Navigating official scheduling portals, searching for available time slots, and submitting required registration details.
  • Buying or canceling plane tickets: Searching flight availability, booking airline seats, or processing cancellations through carrier websites.
  • Rearranging package delivery schedules: Accessing shipping provider tracking portals to adjust delivery windows, update drop-off instructions, or reschedule arrival dates.
  • Checking insurance coverage: Logging into provider portals to check policy coverage details, inspect benefit limits, or review active claims.

This functionality represents a significant leap forward in capabilities. Previously, the chatbot relied on basic external integrations, such as its current in-chat booking abilities that allowed users to reserve dining tables through third-party platforms like Yelp.

The new capability moves the chatbot far beyond basic reservation tools and into deeper, more serious purchasing and account management waters. For additional context on how conversational booking features evolved, check out how ChatGPT will let you book a table mid-chat during ordinary conversational flows.

How Does the Cloud Browser Protect Your Login Details?

Allowing an automated AI assistant to interact with signed-in accounts naturally raises questions about data privacy and credential protection. How does the system navigate private user accounts without exposing sensitive usernames and passwords to the core language model?

On OpenAI's help page, updated alongside the official announcement, the company explains that the system operates through an isolated cloud browser. This remote cloud browser is designed to read web pages, click interactive buttons, enter information into web forms, and carry out sequential steps on supported public and signed-in websites.

Because the actions occur inside a separate remote browser instance, you are not putting your credentials directly into the Large Language Model (LLM) powering the chatbot. The secure login process works through a structured workflow:

  1. Start a task with a prompt: You initiate the process by typing your request as a standard text prompt inside the chat interface.
  2. Conversation pauses: Upon identifying that a signed-in website action is required, the chatbot pauses the active chat session.
  3. Secure form generation: The system generates a dedicated "secure form" for logging into the target website through the remote cloud browser.
  4. Authentication and 2FA: You enter your login credentials into the secure form and complete any necessary two-factor authentication (2FA) steps or site approvals.
  5. Credential isolation: According to OpenAI, the username and password entered in the secure form are not visible to the model, and ChatGPT does not store those sign-in credentials.

This structural separation guarantees that your sensitive authentication details never become part of the chatbot's training data or prompt history. The AI model only receives the contextual information necessary to complete your requested task after authentication is successfully handled by the remote browser environment.

In addition to credential isolation, OpenAI has implemented security monitoring to prevent automated abuse. The company notes that all sign-in requests are reviewed by an additional secondary model specifically designed to scan for signs of phishing or deception before sign-in forms are submitted.

Featured Video: Is ChatGPT Changing the Way We Write?

How to Manage Cloud Browser Permissions and Settings

To give users full control over how autonomous the AI assistant is when interacting with third-party websites, OpenAI provides granular security settings. Users can decide how often the remote cloud browser asks for approval before navigating to external web pages or interacting with site forms.

You can manage these access controls by navigating to Settings > Cloud browser within the platform. The menu offers three distinct operational options:

  • Always ask: The system requires manual user approval every single time the remote browser attempts to visit a web page or perform a new step.
  • Auto approve: The system automatically approves routine navigation steps across recognized sites, providing a faster experience while maintaining standard safeguards.
  • Always allow: The system is given open permission to run browsing tasks continuously without pausing for intermediate navigational approvals.

Despite these flexible permission settings, user availability can vary depending on the destination website. Some websites maintain strict anti-bot policies and restrict access from AI agents and automated remote browsers. If a website actively blocks automated agent traffic, the cloud browser will be unable to complete the task on that specific domain.

Why Confirmation Is Required Before High-Stakes Actions

Once you complete the secure login process and grant the necessary site approvals, the system unpauses your chat conversation and resumes task execution. The remote browser carries out the steps outlined in your original prompt until it reaches the final stage of the request.

However, to prevent accidental purchases, unwanted cancellations, or unauthorized account modifications, OpenAI built strict safeguard checkpoints into the workflow. Notably, ChatGPT will ask you for explicit confirmation in the chat before executing actions that could be hard to reverse or that create financial, legal, account, or other real-world commitments, such as confirming a booking or making a payment.

Key examples of real-world commitment actions that trigger a mandatory confirmation prompt include:

  • Finalizing non-refundable airline ticket purchases
  • Processing credit card or bank account payments
  • Submitting binding legal or medical registration documents
  • Confirming account terminations or service plan cancellations

If you ask the chatbot to buy a plane ticket, it will locate the flight, select preferred seating, enter passenger details, and navigate to the final checkout screen. However, it will pause and present a clear confirmation summary inside the chat window, requiring your explicit green light before charging your payment method or finalizing the booking.

The Shift Toward Full AI Task Automation

The introduction of autonomous web browsing tools within ChatGPT Work reflects a broader trend of giving AI assistants greater operational responsibility across personal and professional digital environments. Instead of functioning solely as conversational search engines, modern AI agents are rapidly transforming into active digital representatives.

This update builds directly upon previous features introduced to the platform. ChatGPT users can already connect their bank accounts for real-time financial tracking and link their medical records to receive customized health insights. Expanding into remote browser automation feels like another natural step in handing over the digital keys to AI.

By delegating time-consuming online chores to an automated agent, users can save hours of manual browsing while maintaining control over privacy options, setting permissions, and financial confirmations.

Disclosure: Ziff Davis, Mashable's parent company, in April 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.

With isolated credential forms, phishing detection models, and mandatory real-world commitment checks, ChatGPT Work offers a secure framework for managing complex web tasks through simple AI task automation.



from Mashable
-via DynaSage