Key Takeaways
- A ChatGPT agent is an AI that completes multi-step tasks on your behalf inside a sandboxed virtual computer, browsing sites, filling forms and producing finished files rather than answering a question.
- OpenAI retired agent mode in early August 2026. The help centre now states it is no longer available and directs users to ChatGPT Work for multi-step tasks and to the cloud browser for browser workflows.
- ChatGPT Work launched on 9 July 2026, taking a goal instead of a prompt and returning finished spreadsheets, slides, documents and web apps after working independently for hours.
- The current engine behind ChatGPT is GPT-6 Astra, which scores 72.6 percent on OSWorld 2.0 computer use at roughly 47 percent less time per task than its predecessor.
- Agent tasks carry real privacy risk, chiefly prompt injection, where malicious page content tricks the agent into actions you never asked for.
- Takeover mode exists so you enter passwords yourself without the agent capturing screenshots, and cookies persist across sessions like a normal browser.
- The useful mental model: regular chat is a collaborator you steer continuously, an agent is a delegate you brief once and review at checkpoints.
A ChatGPT agent is an AI that does things rather than describing them. Given a goal — book a table, compare forty suppliers, clean up a messy export and chart the result — it works inside a sandboxed virtual computer, clicking, scrolling, typing, running code and handling files, then returns the finished output. You can watch it work, interrupt it, and take the controls yourself at any point.
One important correction before going further, because most guides online have not caught up: OpenAI removed agent mode from ChatGPT in early August 2026, with no advance deprecation notice. The help centre now opens with a plain statement — “ChatGPT agent is no longer available. Use ChatGPT Work for longer, multi-step tasks and finished deliverables. For supported browser workflows, see Using cloud browser in ChatGPT.” Confusingly, the old instructions still sit beneath that notice, because the warning was added to the top of the existing article without removing the body. If the option vanished from your tools menu, that is why.
How the Agent Idea Developed
The lineage explains why the terminology is such a mess. OpenAI released Operator as a limited research preview for Pro subscribers in the United States in early 2025, giving an AI control of a remote browser. Operator was folded into ChatGPT agent in mid-2025 and its standalone site shut down on 31 August 2025. Agent mode then absorbed both Operator’s browser control and Deep Research’s investigative capability, becoming a standard feature on paid plans through 2026 — until it too was retired in August 2026.
| Product | Period | Status |
|---|---|---|
| Operator | Early 2025 – August 2025 | Retired; folded into ChatGPT agent |
| ChatGPT agent (agent mode) | Mid 2025 – early August 2026 | Retired without advance notice |
| ChatGPT Work | Launched 9 July 2026 | Current, for multi-step tasks and deliverables |
| Cloud browser in ChatGPT | Current | For supported browser workflows |
| Codex | Current | Specialised software development agent |
ChatGPT Atlas, the standalone browser, shut down on 9 August 2026, with its functionality moving into a built-in browser inside the merged desktop application. The Codex app folded into that same desktop app, which now carries Chat, Work and Codex together.
How an Agent Actually Works
The mechanism is simpler than it sounds. The agent operates a virtual browser and takes screenshots of it to see the page, which is how it decides where to click, what to type and how to react when a site behaves unexpectedly. It breaks a goal into smaller steps, works through them, and pauses to ask for clarification or confirmation when a decision could change the outcome.
Under agent mode, tasks typically ran five to thirty minutes. ChatGPT Work extends that considerably — OpenAI describes it staying with complex projects for hours, gathering context across connected apps and files, and returning finished materials rather than chat text. It connects to a large library of applications, with Slack, Microsoft Teams, Google Drive, SharePoint and GitHub among them, and can schedule recurring work.
The current model underneath matters for what is now realistic. GPT-6 Astra scores 72.6 percent on OSWorld 2.0 computer use at roughly 47 percent less time per task than GPT-5.6 Sol, 92.7 percent on ScreenSpot-Pro without tools, and 59.3 percent on Agents’ Last Exam. OpenAI describes concrete applications: filling out online forms, updating customer records in a CRM, organising a calendar, running frontend quality checks on a site it has just built, and installing and testing software. It also handles ambiguity better than earlier models, asking focused questions when an answer would change the outcome and proceeding with sensible assumptions when it would not.
| Regular chat | Agent-style work | |
|---|---|---|
| What you give it | A prompt, refined turn by turn | An outcome |
| Context | What you paste or attach | Connected apps and files |
| Duration | Seconds per reply | Minutes to hours per task |
| Output | Text in the chat | Finished spreadsheets, slides, documents, web apps |
| Your role | Steer every step | Approve the plan, answer check-ins, review |
What Agents Are Genuinely Good At
Web workflows are the clearest fit: price comparisons, availability checks, form filling and gathering structured information across many pages. The rule of thumb is anything a diligent assistant could do with a browser and a checklist. Data work is the second strength — upload a messy export and get back a cleaned, structured version with analysis attached.
The limits are equally practical. Agents cannot post directly to social platforms because of authentication barriers, so scheduled content still needs a human to move it into the publishing tool. Anything requiring judgment about consequences should stop for confirmation, and OpenAI designed it to do so. Vague instructions produce poor results, which is why “check my email and handle everything” is explicitly listed as a prompt to avoid.
The Safety Part Nobody Should Skip
When you sign an agent into websites or enable app connections, it can reach sensitive data — emails, files, account settings — and act on your behalf. The main risk is prompt injection, and the official example is worth reading carefully because it is not hypothetical.
You ask the agent to find a restaurant for a group dinner by checking your calendar and recent emails. While researching, it encounters a malicious comment on a web page — content written specifically to trick an agent — instructing it to retrieve a password reset code from Gmail and send it to an attacker’s site. The agent has legitimate access to both. Nothing about the request was suspicious.
OpenAI built several layers against this: user confirmations before high-impact actions, refusal patterns for disallowed tasks, prompt injection monitoring, and a watch mode requiring supervision on certain sites. The company is candid that these reduce risk without eliminating it.
The practical habits that follow are short. Never type passwords into messages — use takeover mode, where you control the browser directly and screenshots are not captured. Enable only the apps a task actually needs. Consider how sensitive each site you log into is. Stop a task immediately if something looks wrong. Clear browser data after sensitive sessions, since cookies persist across sessions exactly as in a normal browser. And review app permissions periodically.
These risks are not unique to one vendor. They apply to any agent with tool access, which is why they feature in our overview of the core AI agent concepts worth knowing and in our review of real agentic workflows companies run in production, where authentication across vendor APIs is a recurring integration problem.
Controls for Organisations
Workspace owners on business tiers had meaningful controls under agent mode, and similar governance applies to the current products. Agent capability defaulted to off for enterprise workspaces, with role-based access controls determining who could use it. Administrators controlled which app connections were available, and could request blocklists for specific domains or entire domain trees. Conversations involving agent tasks appeared in Compliance API logs, though individual actions such as virtual computer usage and chain of thought did not. Data residency and custom retention policies were respected.
Getting Started Today
Since agent mode is gone, the routes are these. For multi-step research, file work and finished deliverables, use ChatGPT Work. For workflows that require driving a site you must log into, use the cloud browser where supported. For code-shaped automation, use Codex. For a recurring job that should start on its own, you need a scheduling mechanism rather than an agent invocation.
Availability sits on paid plans — Plus, Pro, Business and Enterprise — with nothing on the Free or Go tiers. Under the old agent mode, monthly caps ran at 40 messages for Plus, 400 for Pro and 40 for Business and Enterprise, with 30 credits per message on flexible enterprise pricing; ChatGPT Work is metered against plan allowances instead, with consumption varying by task. Reporting suggests Plus subscribers reach the newest model through Work and Codex rather than regular chat, which is worth verifying against your own account. Current subscription tiers across the major assistants are compared in our breakdown of Gemini, ChatGPT, Claude and Grok pricing.
Why This Matters Beyond One Product
The naming churn obscures a real change in how people use these systems. ChatGPT reached 900 million weekly users by early 2026, and the shift from asking to delegating changes what that scale means — a trajectory covered in our pieces on ChatGPT’s development from text generator to platform and when it might cross a billion weekly users.
Agentic delegation is becoming the default way people work with AI rather than a specialist feature, and every major vendor now ships a version of it. The skill worth building is not memorising one product’s menu, which clearly changes faster than documentation can track. It is learning to write a good brief, define what “done” looks like, and check the work at the points where a mistake would be expensive.
If you are interested in this topic, we suggest you check our articles:
- AI Agent Concepts: 15 Critical Principles
- Agentic AI Real Use Cases: Beyond Hype to Working Solutions
- ChatGPT’s Evolution: From Text Generator to AI Powerhouse
- When Will ChatGPT Reach 1 Billion Weekly Users?
- 2026 AI Subscription Prices: Gemini vs ChatGPT vs Claude
Sources: OpenAI Help Center, OpenAI, OpenAI (GPT-6 Astra), VentureBeat, The Next Web, Wikipedia
Written by Alius Noreika

