OpenAI's agentic ChatGPT Work can now sign into your password-protected website accounts without your involvement — and without ever seeing your password after the first time. The new capability, launched earlier this week and detailed by ZDNET, removes one of the last points of friction that forced AI agents to stop and wait for their human overseers.

It is a meaningful step forward for agent usability. It is also exactly the kind of feature that security researchers have spent two years warning about. For more context on this story, see our ongoing AI trends.

How the Automatic Sign-In Works

The new skill is available through ChatGPT Work, OpenAI's agentic product that carries out multi-step assignments on the user's behalf, and it is limited to ChatGPT Pro and Plus subscribers, according to ZDNET's Lance Whitney, who tested the feature.

The mechanics are simple. The first time ChatGPT needs to access one of your website accounts, it prompts you to enter your username and password or passcode — typed manually or autofilled from a third-party password manager. The agent then signs in normally. The difference comes on the next visit: ChatGPT's built-in browser stores the session in cookies, just like any conventional browser, so subsequent sign-ins to the same site happen automatically, with no prompt and no user interaction.

In effect, OpenAI has given its agent the same persistent-session capability that browsers have always granted to humans. The agent is no longer a guest that has to be buzzed in each time. It has a key.

What OpenAI Says You Can Do With It

The use cases OpenAI suggests lean heavily on tedious, bureaucratic web tasks that people dread. According to ZDNET, OpenAI's examples include figuring out which utilities serve a new apartment and signing up for the right plan, booking a DMV appointment or filling out passport renewal forms, checking X-ray and bloodwork costs through an insurance portal, and finding profiles of candidates who fit a job description and are open to work.

These are precisely the tasks where agentic browsers shine: repetitive form-filling across sites with clunky interfaces. Removing the login prompt from the loop makes genuinely hands-off completion possible for the first time in these scenarios.

ZDNET's Test: Promising, With Speed Bumps

Whitney's hands-on testing surfaced both the promise and the limits. Using the ChatGPT Windows app, which runs its own built-in cloud browser, he asked ChatGPT Work to log into his Amazon account and list the items and prices on his public wish list. The first attempt prompted him for credentials as expected. On subsequent attempts, ChatGPT signed in automatically.

But the experiment also hit friction. The same task attempted through the ChatGPT website failed, with Amazon blocking the attempt from the cloud browser. And even in the Windows app, after two successful runs, Amazon began blocking access — a reminder that destination sites, not OpenAI, ultimately decide whether agents are welcome. Amazon did not respond to a request for comment on the blocks.

That last point matters more than it may seem. Sites have spent two years tightening bot defenses against AI scrapers and agents. Persistent cookies will not soften that hostility; they may sharpen it, as sites weigh whether a cookie-backed agent session is a trusted user or an impersonator.

The Security Trade-Off

Granting an AI agent durable, cookie-based access to your accounts concentrates risk. Cookies bypass the login step entirely, which means they also bypass the moment when a user might pause and reconsider what the agent is about to do. ZDNET's advice to readers is caution: be deliberate about which sites you allow ChatGPT to access.

The concern compounds as the feature intersects with OpenAI's broader agent push. Decrypt has reported on unease around ChatGPT Work signing into accounts on the user's behalf, and Tech Times reported this week that new ChatGPT Work automation features, including Gmail webhooks and inbox login, create new attack routes if an agent is manipulated. Separately, MacStories reported that OpenAI updated the ChatGPT iOS app with customizable widgets for ChatGPT Work and a Codex remote, extending the agent's reach onto the phone's home screen.

None of this means users should avoid the feature. It means the calculus has changed: handing ChatGPT Work your insurance portal is a different decision than letting it browse public pages, and users now need to make that decision site by site.

A Line Crossed That Won't Uncross

The password prompt was always an awkward artifact in agent design — a human checkpoint inside an automated workflow. OpenAI has shown it can be engineered away with nothing more exotic than cookies. Expect the same capability from every competing agent stack before long, because the productivity argument is overwhelming and the first mover has already normalized the approach.

The open question is governance. OpenAI says users control which sites the agent can access. Regulators in Europe and the US are only beginning to think through what it means when millions of consumers delegate persistent authenticated access to sensitive accounts — health data, government services, financial portals — to a model provider's cloud browser. The technology arrived this week. The rules are years behind.

For more on agentic AI tools and what they mean for security and productivity, follow AI Buzz Wire's tools coverage.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →