Explainer

ChatGPT agent mode, explained: what it was, why it's gone, and what ChatGPT Work does instead

OpenAI's help center says ChatGPT agent is no longer available. ChatGPT Work, a cloud browser and dots now do its job. Here's how they work.

By ShajanthanUpdated 7 min read
ByShajanthanFounder & Editor
Published
Reading7 MIN
Timeline showing OpenAI's agent products from Operator to ChatGPT agent to ChatGPT Work and dots
In 20 seconds
  1. ChatGPT agent launched on July 17, 2025. OpenAI's help center now says it is "no longer available" and sends users to ChatGPT Work, which launched on July 9, 2026.
  2. Work runs multi-step tasks in OpenAI-hosted sandboxes, or on your own computer in the desktop app. It has a cloud browser with sign-in pauses, takeover and confirmations.
  3. OpenAI says prompt injection is "unlikely to ever be fully 'solved'", so keep tasks narrow and stay signed out where you can.
Contents

If you search for "ChatGPT agent mode," most results still explain how to type /agent and let ChatGPT run tasks on its own. That advice is out of date. As of October 8, 2026, OpenAI's own help article for the feature opens with: "ChatGPT agent is no longer available." It sends users to ChatGPT Work for "longer, multi-step tasks" and to a separate cloud browser for supported web workflows. This explainer covers what agent mode was, what replaced it, what each plan includes and how the safety controls work. For how Work compares with Anthropic's equivalent, see our ChatGPT vs Claude comparison.

What ChatGPT agent was

OpenAI launched ChatGPT agent on July 17, 2025. It described the product as "a natural evolution of Operator and deep research": it merged the web-browsing Operator agent with the deep research tool. The agent worked on "its own virtual computer" and used a visual browser that it controlled through screenshots, a text-based browser, a terminal, direct API access and ChatGPT connectors such as Gmail and GitHub.

It was limited from the start. At launch, Pro users got 400 agent messages per month and other paid users got 40. The help page later listed the same 40 per month for Plus, Business and Enterprise. Only requests you started counted: clarifications and login steps did not, but each scheduled run counted as a new request. Free users never had access.

OpenAI also put tighter safety controls on agent mode than on ordinary chat:

  • Confirmations before "high-impact" actions such as purchases.
  • Watch mode, which required you to keep the tab active on certain sites. OpenAI's launch post said "certain critical tasks, like sending emails, require your active oversight."
  • Takeover mode, where you took control of the remote browser to type a password. ChatGPT did not capture screenshots while you were in control.
  • Prompt-injection monitoring and a site blocklist.

OpenAI also treated the agent as having "High Biological and Chemical capabilities" under its Preparedness Framework. It said it lacked definitive evidence of that risk and was taking the step as a precaution.

When and why it went away

OpenAI has published a replacement but no dated retirement notice for agent mode. Its official record shows three steps:

  • July 9, 2026: The ChatGPT release notes introduce ChatGPT Work as "an agent for longer, more involved tasks." The same day, OpenAI said it would retire its standalone Atlas browser, because "browser-based agentic capabilities" were moving into ChatGPT and Codex. Atlas stopped working on August 9, 2026.
  • July 16, 2026: The desktop app gets a switch: "choose Chat for quick questions and conversational help, or Work to complete tasks end to end."
  • By October 8, 2026: The agent help article carries the "no longer available" notice.

The exact date is not confirmed. User reports, which are anecdotal, place the removal in early August 2026. One vendor blog cites OpenAI developer-forum threads from August 8 in which users said there was no advance notice and no migration guide. One user noticed only because a scheduled agent task stopped running. OpenAI has not confirmed these accounts, so treat them as user reports.

In short, OpenAI did not drop agentic features. It moved them into a broader product, as it did when Operator was folded into ChatGPT agent in 2025.

What ChatGPT Work does now

OpenAI's help center separates three modes. Chat is for "fast, conversational assistance and everyday questions." Codex is "dedicated to software development and technical work." Work is for research, analysis and finished deliverables such as documents, spreadsheets, presentations, reports or hosted Sites.

Work runs in two places:

  • In the cloud. On web and mobile, tasks run in what OpenAI's security documentation calls "VM-backed sandboxes" on OpenAI-managed infrastructure. The cloud environment does not inherit your local files, apps or browser sessions.
  • On your computer. In the macOS and Windows desktop apps, Work can use local folders and desktop apps if your plan and workspace allow it. OpenAI notes that "messages and task context may be stored in the cloud, even when work runs locally."

Work connects to other services through plugins. OpenAI's product page cites "more than 1,400." A Plan mode gathers context and proposes a step-by-step plan, which you can edit or approve before Work starts. Scheduled tasks can repeat work, and since August 25, 2026, webhooks from supported apps can trigger tasks. Webhook triggers are not available on Free or Go.

The cloud browser

The agent's remote browser has been rebuilt as Work's cloud browser: "its own browser on a remote computer" that can "read web pages, click buttons, enter information into forms." According to OpenAI's help article:

  • It is available "in ChatGPT Work on paid ChatGPT plans in supported regions, excluding Free and Go."
  • At a supported sign-in page, it pauses so you can log in. "The username and password entered there are not visible to the model," and ChatGPT "does not store those sign-in credentials." Sessions persist for later tasks until they expire.
  • If it gets stuck, it asks you to take over and gives you a link to control the cloud browser directly.
  • It "is designed to request confirmation before actions that could be hard to reverse," such as bookings and payments.
  • Cookies and sessions are kept separately from your own browser. You can clear them under Settings > Cloud browser > Browser data.

The current documentation no longer mentions "watch mode." On web and mobile, you approve or decline actions with on-screen controls, and "spoken approval is not supported."

Dots: always-on agents

On September 29, 2026, OpenAI added dots: "always-on agents" that keep working on a goal between conversations. Each dot runs on GPT-6 Astra and has its own cloud computer. You choose which apps it can use and what it can do without asking. Dots are rolling out gradually to eligible Pro and Business Premium users aged 18 and over. Pro access excludes the EEA, Switzerland and the UK at launch. For Enterprise, dots are a beta that is off by default.

Plans, prices and limits

Last verified: October 8, 2026

PlanUS priceWork access (per OpenAI)Notes
Free$0Limited, desktop app onlyNo cloud browser; no webhook-triggered tasks
Go$8/monthLimited, desktop app onlyNo cloud browser; may include ads
Plus$20/monthDesktop, web, mobileLimited GPT-6 Astra use plus optional credits
Pro$100, $200 or $500/monthDesktop, web, mobilePro 500 adds Astra "Ultrafast"; dots rolling out
Business$25/user/month monthly, $20 annual (Standard seat)Desktop, web, mobilePremium seat $125 monthly / $100 annual
Enterprise / EduContact salesAdmin-controlledWork requires Enterprise Key Management

OpenAI does not publish fixed message caps for Work. It says Work "uses the same usage structure as Codex." Its pricing documentation gives estimates for Plus and Business Standard of 5–45 local messages per five hours on GPT-6 Astra and 15–160 on GPT-6.1 Sol, and says Pro "currently has no five-hour limit." Extra usage is bought as credits. The heaviest model draws on credits several times faster than the lighter ones.

The new GPT-6 models for Chat, announced on October 7, 2026 with a feature OpenAI calls "Intelligent UI", do not change Work. Intelligent UI lets ChatGPT answer with charts, buttons and small tools. OpenAI's release note says "the models powering Work and Codex aren't changing with this release." GPT-6.1 Sol, GPT-6 Sol and GPT-6 Luna were already available in Work and Codex from September 22 and 29.

The prompt-injection problem hasn't gone away

The biggest risk with any browsing agent is prompt injection: text on a web page, email or document that the agent reads as an instruction. OpenAI's old agent help page gave an example. While looking for a dinner spot using your calendar and email, the agent meets a hidden comment telling it to send a Gmail password-reset code to an attacker.

OpenAI is unusually direct about this. In a December 22, 2025 post about its Atlas browser, it wrote: "Prompt injection, much like scams and social engineering on the web, is unlikely to ever be fully 'solved'." It described training an automated, reinforcement-learning attacker to find new injections before outsiders do. The current cloud-browser documentation says OpenAI tests for "prompt injection, phishing, and unintended actions," but that "those safeguards do not eliminate every risk."

There is also an enterprise visibility gap. OpenAI's Work security documentation says compliance exports may not include "every shell command, browser interaction, or app call," and that endpoint monitoring can't see inside the hosted environment. Our piece on the case against unattended agents covers why that matters.

What users report

User reports are anecdotal, not verified (Tier 3):

  • Users were frustrated that agent mode disappeared without a migration path. Scheduled agent tasks stopped working without warning.
  • Some early commentary said Work couldn't handle logged-in sites. That is out of date: OpenAI added cloud-browser sign-in on August 25, 2026.

What to do if you relied on agent mode

  1. Recreate scheduled agent tasks as Work scheduled tasks. Old agent schedules don't migrate on their own.
  2. Start with Plan mode and approve the plan before Work runs. This is the closest equivalent to agent mode's step-by-step oversight.
  3. Keep tasks narrow. OpenAI's own advice is to avoid instructions like "review my emails and take whatever action is needed."
  4. Sign in only where you must, and clear cloud-browser data after sensitive sessions.
  5. Give connected apps read-only access by default. Admins can set app actions to always require confirmation.

If you mainly used agent mode for research, ChatGPT vs Gemini for research compares the deep-research tools. For the bigger picture, see what "agentic" really means in 2026. The closest Anthropic products, Cowork and Claude in Chrome, are covered in our Claude app explainer.

About this storyBased on the sources linked below. Editorial standards

Was this useful?Report an error
Comments
0

More on ChatGPT & apps

The Week in AI

New guides and explainers, every Friday.

0