Home / Viral & Trending / ChatGPT can now do things on your behalf without seeing your login details

ChatGPT can now do things on your behalf without seeing your login details

OpenAI has officially launched a significant update to its artificial intelligence ecosystem, introducing a suite of capabilities that allow its chatbot to perform complex real-world tasks—such as booking international flights, managing household utilities, and scheduling medical appointments—while maintaining a strict technical barrier between the AI and the user’s sensitive login credentials. The new feature, operating under the "ChatGPT Work" umbrella and powered by the GPT-5.6 model, represents a pivotal shift from a generative text assistant to an "agentic" AI capable of navigating the live web to execute transactions and administrative duties.

The update, which is currently rolling out to Plus, Pro, and Business subscribers across both mobile and web platforms, addresses one of the primary security concerns that has hindered the adoption of AI agents: the risk of exposing personal passwords to large language models (LLMs). By utilizing a proprietary "cloud browser" system, OpenAI claims that the AI can now interact with third-party websites, fill out forms, and navigate secure portals without the underlying model ever seeing or storing the user’s username or password.

The Technical Architecture of Secure Automation

The core of this advancement lies in the separation of the reasoning engine from the browsing execution. When a user prompts the AI to perform a task—for example, "Cancel my flight to London next Tuesday"—the chatbot does not immediately attempt to access the airline’s website. Instead, it pauses the conversational thread to generate what OpenAI describes as a "secure form."

This form operates within a remote, isolated browser environment. The user enters their login details into this interface, which then handles the authentication process directly with the target website. Because this process occurs in a siloed cloud browser, the GPT-5.6 model receives only the necessary data to complete the requested task, such as flight details or confirmation numbers, rather than the credentials themselves.

OpenAI has integrated an additional layer of security by deploying a secondary, specialized model tasked exclusively with monitoring these sign-in requests. This secondary system is designed to detect signs of phishing, deceptive redirects, or fraudulent website overlays, providing a defensive buffer against sophisticated cyberattacks that might target AI-driven workflows.

ChatGPT Can Now Do Things on Your Behalf Without Seeing Your Login Details in Daily Life

The practical applications of this update extend far beyond simple administrative assistance, moving into the realm of personal logistics and financial management. According to documentation released by OpenAI, ChatGPT Work is now equipped to handle a variety of "deep" tasks that previously required manual intervention and multiple browser tabs.

In the domestic sphere, users can authorize the assistant to set up or transfer home utilities, a process that typically involves navigating cumbersome legacy web portals and entering service addresses. In the healthcare sector, the tool can navigate patient portals to book or reschedule appointments, provided the healthcare provider’s website supports the automated interface.

ChatGPT can now do things on your behalf without seeing your login details

The travel and logistics capabilities represent perhaps the most significant leap. While previous iterations of the chatbot could suggest itineraries or search for deals, the current version can now execute the purchase or cancellation of plane tickets and hotel reservations. It can also interface with shipping carriers to rearrange package deliveries or track lost shipments, effectively acting as a digital concierge with the authority to make real-world commitments.

The Rise of Agentic AI and Industry Competition

The introduction of ChatGPT Work marks a critical milestone in the race toward truly "agentic" artificial intelligence. For years, the tech industry has envisioned AI assistants that do not merely provide information but take action. This update places OpenAI in direct competition with other tech giants like Google and Microsoft, who have been racing to integrate similar "action-oriented" features into Gemini and Copilot, respectively.

The transition to agentic AI is viewed by industry analysts as the next frontier of the digital economy. By enabling ChatGPT to do things on your behalf without seeing your login details, OpenAI is attempting to reduce the "friction of intent"—the gap between a user deciding to do something and the actual completion of the task. This capability could fundamentally alter how consumers interact with the internet, potentially bypassing search engines and direct website navigation in favor of a centralized AI interface.

However, the move into "serious purchasing waters" brings with it a new set of economic and legal responsibilities. OpenAI has stated that for any action that could be considered "hard to reverse," such as making a payment or entering into a legal agreement, the system will explicitly ask for a final confirmation within the chat. This human-in-the-loop requirement is intended to prevent accidental purchases or unauthorized financial commitments.

User Control and Privacy Management Frameworks

To manage these new powers, OpenAI has introduced a granular set of controls within the ChatGPT settings menu. Under a new "Cloud Browser" tab, users can define the level of autonomy granted to the AI. Options include "Always ask," which requires permission for every individual website access; "Auto approve," which allows the AI to navigate known sites; and "Always allow," for seamless background task execution.

The company has also acknowledged that the system is not universal. Many websites employ anti-bot measures or specific "robot.txt" exclusions that may prevent AI agents from accessing their services. As the ecosystem of AI agents grows, a conflict is emerging between platforms that want to automate user tasks and website owners who wish to maintain direct human traffic for advertising and data collection purposes.

Furthermore, the privacy implications of connecting AI to such sensitive sectors as banking and healthcare continue to be a point of public debate. While the "secure form" prevents the LLM from seeing passwords, the AI still gains access to the contents of the pages it visits. This means that if a user asks ChatGPT to "analyze my spending," the AI will see transaction histories and account balances, even if it does not know the password to the account.

Legal and Ethical Headwinds in the AI Sector

The rollout of these advanced features comes at a time of heightened legal scrutiny for the AI industry. OpenAI continues to face challenges regarding the data used to train its models. Notably, in April 2025, Ziff Davis, the parent company of Mashable, filed a lawsuit against OpenAI alleging copyright infringement. The suit claims that OpenAI used copyrighted content without authorization to train and operate its systems.

ChatGPT can now do things on your behalf without seeing your login details

These legal battles highlight the tension between AI developers and content creators. As AI agents like ChatGPT become more capable of performing tasks—potentially reducing the need for users to visit the original websites—the question of how those websites are compensated for their data and infrastructure becomes increasingly urgent.

Industry experts suggest that the success of agentic AI will depend not only on technical reliability but also on the establishment of new digital standards. There is a growing call for a universal "AI-to-Web" protocol that would allow websites to communicate securely with agents while ensuring that the rights of both the user and the service provider are protected.

Consequences for the Workforce and Productivity

The deployment of ChatGPT Work is expected to have a profound impact on corporate productivity and the nature of administrative labor. By automating routine tasks like scheduling, utility management, and logistics, the tool could save thousands of hours for office workers and small business owners.

In a corporate environment, the ability of ChatGPT to do things on your behalf without seeing your login details allows for the integration of fragmented workflows. An employee could, in theory, ask the AI to "file my expense report, update the project management board, and send the meeting invite," and the AI would navigate three different enterprise software platforms to complete the request.

However, this shift also raises concerns about the displacement of administrative staff and the potential for increased digital surveillance. As companies integrate AI agents into their core operations, the boundary between human decision-making and algorithmic execution continues to blur.

Security Safeguards and the Future of Authentication

As passwords become less visible to the AI, the importance of multi-factor authentication (MFA) has moved to the forefront. OpenAI’s cloud browser supports 2FA and MFA protocols, requiring users to complete the second step of authentication on their own devices before the AI can proceed. This ensures that even if an AI agent is compromised, the "second key" remains in the physical possession of the human user.

The company’s move toward a "no-see" credential system may also accelerate the adoption of passkeys and other passwordless authentication methods. If AI agents are to become the primary interface for the web, the industry may move away from traditional text-based passwords entirely, favoring biometric and hardware-based security that is more resistant to the types of vulnerabilities that AI could potentially exploit.

The rollout of these features is expected to continue through the end of the year, with OpenAI closely monitoring the system for "hallucinations" or errors in task execution. As ChatGPT begins to act as a proxy for human intent in the physical and financial world, the stakes for accuracy and security have never been higher.

Tagged:

Leave a Reply

Your email address will not be published. Required fields are marked *