ChatGPT Work Can Now Log Into Websites and Complete Tasks
OpenAI has expanded ChatGPT Work’s cloud browser so the AI can work with supported websites that require users to sign in, while keeping passwords hidden from the model.

OpenAI has expanded ChatGPT Work with a major new capability: its cloud browser can now operate on supported websites that require a login. Previously, the cloud browser was primarily limited to public webpages. The update allows Work to pause at a login screen, let the user authenticate, and then continue carrying out the requested task using that signed-in session.
The sign-in process is designed so that the AI does not see or store the user’s password. When a login is required, ChatGPT presents a secure form where the user enters their username, password and, when necessary, a two-factor authentication code. OpenAI says those credentials are sent directly to the remote browser rather than being exposed to the model.
Once authentication is completed, ChatGPT Work can continue interacting with the website, including reading pages, clicking buttons, entering information into forms and performing other supported actions. The authentication session can remain available for future tasks until it expires, meaning users may not need to repeat the login process every time.
The development significantly expands what an AI agent can do. OpenAI describes ChatGPT Work as an agent designed for longer, multi-step projects that can work across applications and files and produce finished documents, spreadsheets, presentations, reports and websites. Adding authenticated web access gives the agent access to a much broader range of real-world workflows.
However, the capability also introduces important security and privacy considerations. OpenAI says the system includes additional checks before presenting a sign-in request, and users can review the website address and sign-in form. The company also warns that browser-based AI agents face risks such as phishing, prompt injection and potential data exfiltration. Users should therefore carefully review what websites and permissions they allow an AI agent to access.
The update represents another step toward agentic AI, where people give an AI system an objective rather than asking it to simply generate an answer. Instead of telling users how to complete a task on a website, ChatGPT can increasingly perform the digital steps itself—while pausing when authentication, approval or other human input is required.



