Artificial Intelligence (AI)

What Is ChatGPT Agent? The 2026 Answer Is a Retired Name

An abstract sculptural arrangement of interlocking paper forms suggesting a machine handing a task to a successor.

Ask what ChatGPT agent is today and you get three different answers depending on who you ask. The cleanest evidence comes from OpenAI itself: the company’s help center article titled "ChatGPT agent" opens with a notice that the feature is gone, then continues for several hundred words describing it in the present tense, complete with monthly message limits. That contradiction is not trivia. It is why a lot of 2026 coverage still describes a product OpenAI has retired.

The one line answer, and the footnote it needs

As of August 2026, OpenAI’s help center article states plainly: "ChatGPT agent is no longer available. Use ChatGPT Work for longer, multi-step tasks and finished deliverables. For supported browser workflows, see Using cloud browser in ChatGPT."

So the short answer: ChatGPT agent is a retired product name whose capabilities moved into a mode called ChatGPT Work, with browser automation split into a separate cloud browser feature.

The footnote is that the same article, immediately below that notice, still says: "To start using agent mode, select it from the tools menu or type /agent in the composer." It then lists availability on "Pro, Plus, Business, Enterprise, and Edu plans" and monthly limits of 40 messages for Plus, 400 for Pro, and 40 for Business and Enterprise. Those figures are stale documentation sitting underneath a retirement banner. Treat them as history, not a current spec sheet.

Every article that quotes “40 messages a month” for agent mode in 2026 is quoting a page whose own first sentence says the feature no longer exists. Check the top of a source before citing the middle of it.

What ChatGPT agent did when it launched

The name has a real history worth getting right. OpenAI introduced ChatGPT agent on July 17, 2025, describing it as ChatGPT that "thinks and acts, proactively choosing from a toolbox of agentic skills to complete tasks for you using its own computer."

That toolbox was the interesting part. It combined a visual browser that clicked through pages, a text based browser for faster reasoning over retrieved content, terminal access, and connectors to services such as Gmail and GitHub. It also folded in Operator, the standalone browsing agent OpenAI had shipped earlier: the agent release notes for the same date record that the separate Operator site would be deprecated.

OpenAI published benchmark scores alongside the launch, including 41.6 percent on Humanity’s Last Exam at pass@1, 27.4 percent on FrontierMath, 45.54 percent on SpreadsheetBench with spreadsheet editing enabled, and 68.9 percent on BrowseComp. Those are vendor self-reported figures measured on a model generation since replaced. They describe mid 2025, not the current successor.

The launch also came with a specific safety posture: explicit confirmation before actions with real world consequences, a "Watch Mode" that demanded active oversight on critical tasks such as sending emails, and a takeover mode in which the user entered credentials directly, with those inputs kept private. OpenAI additionally treated the release as High capability in the biological and chemical domain under its Preparedness Framework. That matters because the replacement handles credentials very differently.

Where the capability went: Chat, Work and Codex

The pivot happened on July 9, 2026. In an announcement titled "ChatGPT is now a partner for your most ambitious work", OpenAI restructured the product into three named experiences. The ChatGPT release notes for that date describe Work as "an agent for longer, more involved tasks. It can research and analyze information, work across connected apps and files, and create finished documents."

The ChatGPT Work and Codex help article draws the boundaries in one sentence each. Chat is for when you "ask questions, search, brainstorm, or get quick conversational help." Work is for when you "research a topic, analyze information, or create a document, spreadsheet, presentation, report, or Site." Codex handles repositories, tests and commands.

If you have read our coverage of the new ChatGPT split into Chat, Work and Codex, the shape will be familiar. What is less widely reported is that this leaves the word "agent" attached to at least three distinct things at once. There is Work, which OpenAI’s own release notes call an agent. There is Codex, the coding surface. And there are workspace agents, a separate product for Business, Enterprise and Edu workspaces announced on April 22, 2026 as Codex powered agents that teams build once and share, run on a schedule, or deploy in Slack.

Three products, one word. When somebody says they are using "the ChatGPT agent," ask which one.

Which surfaces agentic work runs on now

The 2025 agent ran on ChatGPT web, mobile and desktop against one cloud environment. The 2026 arrangement is more segmented.

Work runs on web, mobile and desktop. Codex is a desktop experience, reachable from mobile only through a remote tab. The July 9, 2026 announcement says the desktop app shipped globally with Chat, Work and Codex "available to users on every plan, including Free," while the help center says Work on web and mobile is for "eligible paid plans." Both statements are current, so surface and plan interact rather than one gating the other.

Work also splits by execution environment. OpenAI’s getting started documentation says to work locally when the task needs files or apps on your computer, and to choose cloud when you want Work to "keep running after you close the app or turn off your computer." The Work and Codex help article adds that admins control Work Cloud and Work Local separately, and that Codex Local is separate again.

One surface disappeared entirely. The ChatGPT release notes for July 9, 2026 state that "Atlas is scheduled to stop working on August 9, 2026," removing the browser that carried its own agent mode.

The permission and approval model, rebuilt

This is where the successor diverges most sharply from what ChatGPT agent did in 2025, and where most secondhand explainers are out of date.

Browser automation now lives in a cloud browser feature that, per the help center, "does not accept credentials, use autofill or password managers, sign in to websites, or complete payments." Saved cookies do not let it sign in at launch. If a site demands authentication or throws a CAPTCHA, the task stops. That is a deliberate retreat from the 2025 takeover model, and it turns a whole class of demonstrated workflows, such as booking and checkout, into things the product will not attempt.

On the local side, OpenAI documents four permission modes. "Ask for approval" is the default and lets the model read and edit files in the current workspace and run routine local commands, but it asks before using the internet or crossing the workspace boundary. "Approve for me," shown as auto-review in settings, routes those same requests to an automated reviewer. "Full access" removes the checkpoints entirely. A custom mode is configurable through a config file.

The auto-review documentation is unusually candid. It "replaces manual approval at the sandbox boundary with a separate reviewer agent," and that reviewer can deny a request and return a rationale. It covers escalated shell calls, blocked network requests, writes outside allowed roots, tool calls flagged by annotations, and computer use hitting a new domain. OpenAI states it is not on by default, that it "only evaluates actions that ask to cross a boundary," and that it "can still make mistakes, especially in adversarial or unusual contexts."

The architectural point underneath is the one most governance writeups miss: changing who reviews a request does not expand the sandbox. Approvals and sandboxing are two separate controls. This is the same separation we traced in CMS and MCP agent permission models, and it is the right mental model for any long running cloud agent session.

What ChatGPT agent’s successor cannot do

The negatives in OpenAI’s documentation give a sharper picture than any feature list.

The cloud browser works only on public pages at launch. It cannot sign in, pay, or use a password manager, and some sites are unavailable "for safety, security, or compliance reasons." On web and mobile, Work cannot reach files on your local computer; that requires the desktop app, which in turn requires explicit permission grants for files and folders. Codex is not selectable on web or mobile. The legacy agent article notes that agent mode could not pull data from apps with sync functionality such as Google Drive, a limitation OpenAI has not restated in the newer Work documentation, so treat it as unconfirmed rather than resolved.

Nothing in OpenAI’s current documentation promises unattended completion of authenticated transactions. If a workflow requires logging in as you and spending money, the 2026 product deliberately stops short.

Plans, message limits and the credit pool

The old model was a monthly message count. The new model is credits, and the two are not comparable.

Flexible pricing documentation describes credits as unlocking additional access to advanced features, with Business users drawing from a shared pool beyond per seat limits and Enterprise and Edu buying a pooled allocation at contract level. Deep research, thinking models, image generation, advanced voice and Codex draw on credits, while search, file upload and canvas do not. Rate cards are published separately.

Two dated points show how granular this has become. The ChatGPT Business release notes record that from July 6, 2026, "Workspace Agent runs now use token-based pricing, with credit use based on input tokens, cached input tokens, and output tokens." From July 23, 2026, voice in Work and Codex uses approximately six credits per minute, and delegated Work or Codex tasks draw from the existing shared usage pool at standard rates.

For availability: the cloud browser is offered on all paid plans except Free and Go. Workspace agents run on Business, Enterprise and Edu, off by default at launch for Enterprise workspaces until an admin enables them. The July 9, 2026 announcement adds that Enterprise and Edu admins can set spend controls, and that "usage varies with the amount of work required."

OpenAI no longer publishes a single number telling you how much agentic work your plan buys. Anyone budgeting for this, or comparing alternatives the way we did in Claude Code versus OpenAI Codex, needs the rate cards rather than the marketing page.

Frequently Asked Questions

Is ChatGPT agent still available in August 2026?

No. OpenAI’s help center article for the feature opens with the statement that ChatGPT agent is no longer available and directs users to ChatGPT Work for longer, multi-step tasks and finished deliverables, and to the cloud browser for supported browser workflows.

Why do so many articles still describe agent mode as live?

Because the same help center page still contains the original body copy in the present tense, including instructions to type /agent in the composer and a list of monthly message limits. Writers quoting the middle of the page miss the retirement notice at the top of it.

What replaced ChatGPT agent?

ChatGPT Work, announced on July 9, 2026, which OpenAI’s release notes call “an agent for longer, more involved tasks.” Browser automation moved into a separate cloud browser feature, and team level automation lives in workspace agents for Business, Enterprise and Edu.

Can the replacement log into websites for me?

No. OpenAI states that the cloud browser does not accept credentials, use autofill or password managers, sign in to websites, or complete payments. If a site requires authentication or shows a CAPTCHA, the task stops there.

What are the current permission modes?

OpenAI documents “Ask for approval” as the default, “Approve for me” (labeled auto-review in settings), “Full access,” and a custom mode set through a config file. Ask for approval pauses before internet use or crossing the workspace boundary.

Is auto-review a security guarantee?

No. OpenAI describes it as a separate reviewer agent that only evaluates actions asking to cross a boundary, notes that it can still make mistakes in adversarial or unusual contexts, and says it should complement rather than replace sandbox design and policy.

Do the old 40 and 400 message limits still apply?

They appear on a page whose own overview says the feature is retired. Current metering for Business, Enterprise and Edu runs through credits and, for workspace agent runs since July 6, 2026, token-based pricing. Consult the rate cards rather than the legacy numbers.

Are the launch benchmark scores still meaningful?

Only as history. The 41.6 percent Humanity’s Last Exam and 68.9 percent BrowseComp figures are self-reported by OpenAI in the July 17, 2025 announcement and describe a model generation that has since been replaced. No independent replication is cited in that announcement.

Digital Matters

Artificial Intelligence (AI) Desk