Red Flag? OpenAI's Agentic ChatGPT Work Signs Into Your Accounts Without You OpenAI's ChatGPT Work browser can now sign into websites and keep working on tasks without user intervention, as detailed in the August 25 release notes. The feature allows users to enter credentials once, after which the agent can act on the account and the session may persist for future tasks. OpenAI states the model cannot see usernames or passwords, and they are not stored or used for training, but security experts warn that a persistent session poses a risk if the agent acts beyond its intended scope. In brief - ChatGPT Work's browser on web and mobile can now complete tasks on sites that require you to sign in. - You enter credentials once; the agent can keep working and the session may stay signed in for later tasks. - OpenAI says the model can't see your username or password, and they aren't stored or used for training. OpenAI added an agentic browser capability in its August 25 release notes https://help.openai.com/en/articles/6825453-chatgpt-release-notes , letting ChatGPT Work take over a task on a login-gated site and keep working while you step away. You ask it to do something on a site that needs a login. If that site allows authentication, ChatGPT surfaces the login screen so you can type your credentials or a security code. Once you're in, the agent keeps going and the session may stay signed in for future tasks, so you don't have to log in again. OpenAI says the browser supports password managers for that step, and that the model can't see your username or password; they aren't stored and aren't used for training. Where the consent questions start Authenticating once hands the agent a persistent foothold on an account you'd normally have to be present to open. OpenAI surfaces the login screen for you to enter credentials, but after sign-in the agent can act on the account and the session can carry forward. "You can hand off a task and step away while it keeps working," the release says. The design assumes you're not watching. And this is a serious tradeoff: Security over convenience. OpenAI's own models have already shown they'll act past the lane they're given. In a recent incident, roughly 1,200 OpenAI agents, including GPT-5.6 Sol https://decrypt.co/373151/openai-gpt-5-6-sol-how-compares-ai-models and a pre-release model, broke out of a test environment https://decrypt.co/374015/openai-models-escaped-test-environment-hacked-hugging-face-cheat-benchmark and breached Hugging Face's production servers to cheat a benchmark, with about 700 joining the attack. In other instances, unsupervised AI agents have done everything from spending way too much money in subscriptions and credits to formatting their owner’s PC. That said, the upside is clear: no more re-entering passwords to let an assistant file a form or pull a statement. A signed-in agent that can "continue working" on a site holds the same access you would, until you clear its browsing history. The control exists, but it's manual, not per-action. An agent that can log in and stay logged in is a useful assistant and a standing credential. The safeguards OpenAI lists cover the password. They don't cover the session the password unlocks. The feature is live in ChatGPT Work's browser on web and mobile as of the August 25 release notes; sessions can be cleared individually per site from Settings Cloud browser.