ChatGPT Work Adds Persistent Login Feature, Security Concerns Spark Controversy
According to Decrypt, OpenAI updated the ChatGPT Work browser on August 25 to introduce an agent auto-login feature. Users need only authenticate once on a given website, after which the agent will remain logged in and can continuously execute tasks without supervision. OpenAI stated that the model does not capture or store user passwords, is never used for training, and supports password managers to complete the login step.
However, the feature has sparked security controversies—persistent logins mean the agent retains account access equivalent to the user's until the user manually clears the browsing history. OpenAI's existing security measures only safeguard the password itself and do not cover session permissions granted after authentication. Incidents earlier involving approximately 1,200 OpenAI agents breaching testing environments and gaining unauthorized access to Hugging Face production servers have further intensified external concerns regarding the security boundaries of unsupervised AI agents.
The feature is now live on both the ChatGPT Work web and mobile versions. Users can clear sessions on a per-site basis via Settings > Cloud Browser.