AI Safety & Security
ChatGPT's Agent Now Keeps Your Login in the Cloud
ChatGPT Work's cloud browser can sign in to websites and keep the session on OpenAI's servers — a durable credential your password manager never sees.
OpenAI turned on authenticated browsing in ChatGPT Work on August 25, and the important detail is not the login form. It is what survives after it. The agent’s cloud browser now holds a signed-in session on OpenAI’s infrastructure, and OpenAI’s documentation says the authentication “will persist for future tasks until it expires”, softening a few paragraphs later to “may remain active.” A durable authenticated session now exists in a place the user’s device does not control.
The capability itself is not new plumbing so much as a policy reversal. OpenAI’s own computer-use tool documentation describes the model loop that drives a remote browser — the model proposes a click or keystroke, the harness executes it, a screenshot returns. Until last week that loop simply refused to cross a login boundary. What changed is not the mechanism but the trust boundary the mechanism is permitted to cross.
The credential handling itself is careful. When the agent reaches a login wall it stops and presents a form; the user types the username, password, and any second factor directly. OpenAI states the model never sees or stores those values and does not train on them, and a separate review model checks the destination for phishing before the form appears. Password managers work. On the narrow question of “does the model learn my password,” the answer is no.
The session is the asset, not the password
Security teams have spent two years learning that a stolen session cookie defeats both the password and the second factor, which is why “the model never sees your credentials” answers a question nobody was asking. The artifact worth protecting is the cookie, and it now lives on a machine that keeps running “including after you close your computer or turn off your phone.”
Coverage of the change caught the asymmetry immediately. TechTimes described the update as adding both new automation and a new attack route, noting that the cloud browser runs on OpenAI’s infrastructure rather than the user’s machine and previously could not handle any page behind a login wall. An automation surface and an attack surface are, in agent design, usually the same surface described by two different departments.
Revocation is the tell. There is no way to sign the agent out from the website itself; the user must open Settings, then Cloud browser, then Browser data, and clear data for one site or all of them. That is a fine mechanism and a terrible discovery path. Any control an incident responder cannot find in ninety seconds is a control that will not be used during an incident.
The approval model compounds it. Three levels govern which sites the agent may open: “Always ask,” the default; “Auto approve,” which lets ChatGPT vet addresses; and “Always allow,” which OpenAI itself annotates with the words “This is not recommended.” Shipping a setting alongside the vendor’s own warning against it is an admission that the safe configuration and the useful configuration have diverged. OpenAI also concedes it tests for prompt injection, phishing, and unintended actions but that “those safeguards do not eliminate every risk.”
What operators should change this quarter
The risk is not theoretical, and the market has already priced it once this month. When testers examined the viral assistant Instinct, one found it could be phished through a simple email to a connected inbox, another found it pulling sign-up codes out of email to complete a booking, and a third found it still summarizing an inbox hours after access was disconnected. Same capability class, same failure mode: an agent with a live session and an untrusted input channel.
Concretely, three things change for anyone whose employees have ChatGPT Work seats.
Treat the cloud browser as a new identity endpoint. It holds sessions to your SaaS estate that your SSO logs will attribute to a normal user login. If your detection depends on device fingerprints or impossible-travel heuristics, a persistent cloud session breaks both. Add it to the inventory before it appears in an audit.
Ban “Always allow” by policy and check it. The vendor already tells you not to use it. A configuration the vendor discourages, enabled by a user who wanted fewer prompts, is the most predictable finding in next year’s penetration test.
Write the revocation runbook now. Three clicks in a settings panel is the entire kill switch for every authenticated session your agent holds. Document the path, assign an owner, and rehearse it, because the alternative is discovering it during the incident. The same reasoning applied when we examined Claude’s expansion into write actions on workspace data: capability arrives before the governance surface does.
The counterpoint deserves weight. Login walls were the reason browser agents were useless for real work, and the previous design — where the agent stopped dead at every authenticated page — pushed users toward pasting credentials into chat, which is strictly worse. A structured form with a phishing check and a stated no-training policy is a genuine improvement over the status quo it replaces. The rollout is also staggered, limited to paid tiers, and OpenAI publishes no country list, so exposure is narrower than the headlines suggest.
The verdict: adopt it for internal, low-blast-radius systems, keep it away from anything that can move money or change permissions, and revisit when OpenAI publishes session lifetimes and an administrative revocation API rather than a per-user settings toggle. Evidence that would change the call is an enterprise control plane — org-wide session expiry, audit logs of agent authentications, and revocation that does not depend on the individual employee remembering where the button is. The economics pushing every vendor to ship agent autonomy faster than its governance are the subject of today’s lead on Anthropic’s $16.3 million megawatt-years; capacity that expensive has to be monetized by agents that do more, not less.
Sources
- Notebookcheck — OpenAI’s cloud browser sign-in, session persistence, and the three approval levels
- TechCrunch — privacy and security concerns raised by testers of the Instinct assistant
- OpenAI API documentation — the computer-use tool underpinning agentic browsing
- TechTimes — the ChatGPT Work update read as both new automation and a new attack route