OpenAI’s August 25, 2026 update lets ChatGPT Work continue tasks on supported signed in websites on web and mobile; users enter credentials through the surfaced login screen, while OpenAI says ChatGPT does not see the... The update expands Work to account based tasks such as utility setup, appointments, insurance ch...
Research answer

Create a landscape editorial hero image for this Studio Global article: What did OpenAI’s August 25, 2026 update to ChatGPT Work’s cloud browser introduce regarding secure website authentication—including how use. Article summary: OpenAI’s August 25 update let ChatGPT Work’s cloud browser sign in to supported websites on web and mobile so it can carry out longer, authenticated tasks while the user is away. OpenAI said ChatGPT itself does not see t. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
OpenAI’s August 25, 2026 update moves ChatGPT Work’s cloud browser beyond public websites: on supported sites, it can now continue working after authentication instead of stopping at a login page. The login screen is surfaced to the user, who enters the required credentials and any security code, then hands the task back to Work. OpenAI says ChatGPT does not see the username or password. 2
Before this update, cloud-browser workflows were limited by login walls. The new flow allows Work to continue tasks inside supported accounts on the web and mobile versions of ChatGPT Work. OpenAI’s examples include setting up utilities, booking a DMV or passport appointment, checking an insurance reimbursement, and handling other tasks that normally require a user to open a browser and sign in. 31
The key privacy boundary is that credentials are entered into the browser’s login screen rather than into the ChatGPT conversation. OpenAI’s release note says users may also need to enter a security code before Work resumes the task. 2 Reporting on the rollout says existing password managers can be used during the login step, but the supplied OpenAI release note does not specify which password managers are supported or document a complete compatibility list. 19
After sign-in, the session may remain authenticated for future tasks, meaning users may not need to log in every time Work returns to the same site. 2 That convenience also changes the security model: the important asset is no longer only the password. A still-valid browser session can provide access until the website expires or revokes it.
Users should therefore review which sites remain signed in and revoke or clear remote browser sessions when they no longer want Work to retain access. The provided documentation confirms that sessions may persist, but it does not establish a precise site-data-clearing menu path or explain the retention period for every site.
OpenAI says the model does not see the username or password, and the login screen may require a separate security code. 2 Website operators can also verify that cloud-browser requests originate from ChatGPT Work through Web Bot Auth. The system uses HTTP Message Signatures, including Signature, Signature-Input, and Signature-Agent headers, so organizations can allowlist legitimate cloud-browser traffic while keeping their existing CDN or firewall controls. 5
That request-authentication system helps a website identify traffic from ChatGPT Work. It does not, by itself, prove that every destination is safe or guarantee protection from a malicious look-alike site. The supplied official documentation also does not provide enough detail to verify claims about a separate anti-phishing review model, screenshot handling during credential entry, or comprehensive prompt-injection prevention.
Cloud Browser pauses when it needs additional information or confirmation. OpenAI’s guidance specifically describes confirmation before consequential actions, such as completing a reservation or payment. 7 Users should expect to review high-impact steps involving money, legal commitments, account changes, or other real-world consequences rather than assuming that authentication gives Work unlimited authority.
Confirmation gates reduce accidental actions, but they are not a complete defense against hostile instructions embedded in a webpage, email, document, or other content. A user should still check the destination, the requested action, and the final details before approving a consequential step. The supplied sources do not quantify how reliably the system detects phishing or prompt injection, so stronger claims would go beyond the evidence.
OpenAI’s cloud-browser documentation says the feature is available in ChatGPT Work on paid ChatGPT plans in supported regions, excluding Free and Go, with availability potentially varying during rollout and by workspace permissions. 7 The release note announcing signed-in websites does not provide a complete plan-by-plan matrix for the authentication feature, so users should check their account and workspace settings rather than assume universal access.
The same August 25 update expanded Scheduled Tasks beyond fixed schedules. Tasks can now respond to supported activity in Gmail, Slack, or GitHub—for example, triaging a new email, summarizing Slack activity, or responding to pull-request feedback without repeatedly polling on a timer. 32
For supported workspaces, administrators can enable event-triggered tasks for approved apps. OpenAI’s workspace documentation lists Gmail messages, Slack channel messages, and GitHub pull-request activity as supported webhook sources; in Enterprise, Edu, and Healthcare workspaces, the relevant permission is off by default until an administrator enables it. 4
Scheduled tasks can also be shared. A recipient can review and customize an eligible task, connect their own apps, and schedule an independent copy rather than inheriting the original user’s connected accounts. 10
Free users began receiving scheduled-task access as well. OpenAI’s August 25 announcement says Free users can create up to three active tasks, while the official task documentation confirms that Free and Go accounts cannot create event-triggered tasks. 4437
ChatGPT Work’s cloud browser now crosses the login barrier through a user-controlled authentication step: Work can operate inside supported accounts, but the credentials are kept out of the ChatGPT model’s view. The trade-off is that persistent remote sessions and agent-driven actions deserve the same care as any other signed-in browser. Use the feature for bounded tasks, inspect the destination and final action, approve consequential steps deliberately, and remove remote access when a site should no longer remain connected.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
OpenAI’s August 25, 2026 update lets ChatGPT Work continue tasks on supported signed in websites on web and mobile; users enter credentials through the surfaced login screen, while OpenAI says ChatGPT does not see the...
OpenAI’s August 25, 2026 update lets ChatGPT Work continue tasks on supported signed in websites on web and mobile; users enter credentials through the surfaced login screen, while OpenAI says ChatGPT does not see the... The update expands Work to account based tasks such as utility setup, appointments, insurance checks, and delivery changes, but consequential actions still require user confirmation.