OpenAI's newest agentic feature for ChatGPT can log into your online accounts and complete tasks on your behalf, even while you step away from your computer—a capability that has raised fresh questions about how much control users are handing over to AI.
How the Agentic Feature Works
The system operates by managing signed-in sessions on your accounts, allowing ChatGPT to navigate websites, click through menus, and carry out multi-step tasks autonomously. Rather than requiring you to babysit every action, the tool is designed to keep working in the background, persisting a logged-in state across different jobs so it can pick up where it left off.
OpenAI emphasizes that the model itself never directly sees or stores your passwords. Instead, the authentication happens in a way meant to shield credentials from the AI, with the company positioning this as a privacy safeguard baked into the design.
The AI never sees your password—but it can stay signed in and keep working while you walk away.
Why It Raises Red Flags
The convenience of an agent that acts independently comes with an obvious tradeoff: a session that stays active across tasks means the AI retains access to accounts even during periods when you aren't watching. For security-conscious users, that persistence is precisely the sticking point.
Critics point out that autonomous agents introduce new categories of risk. If an agent misinterprets a task or encounters a malicious website, it could take unintended actions inside sensitive accounts—potentially involving finances, communications, or personal data—without a human immediately catching the mistake.
Key concerns include:
- Sessions that remain signed in across multiple tasks
- The ability for the AI to operate unattended
- Reduced human oversight during automated workflows
The Broader Trend
OpenAI's move reflects a wider industry push toward agentic AI—systems that don't just answer questions but take real-world actions on a user's behalf. As these tools grow more capable, the balance between convenience and control becomes central to whether users trust them with access to their digital lives.
For now, the company frames the design as secure by construction, arguing that keeping passwords hidden from the model limits exposure. Whether that reassurance satisfies wary users may depend on how transparently OpenAI handles the sessions its agent leaves open.
