ChatGPT Work: OpenAI's Powerful and Confusing New Product, Explained
Understanding ChatGPT Work

OpenAI's ChatGPT Work is actually two products: a cloud-based agent with internet access, a headless Chrome browser, and a persistent filesystem, and a desktop app for local file access. Available only to paid subscribers, Work offers features missing from regular Chat, including model options (Sol, Luna, Terra), code execution with unrestricted internet, the ability to build and deploy websites via Cloudflare Workers, and sub-agents. Simon Willison explores these capabilities and raises safety concerns about prompt injection risks.
The code execution environment can now talk to the rest of the internet!
- tristanj
I think most people are sleeping on the ChatGPT Work/Codex computer use feature. It's incredibly useful. I can remote in from the app, voice it instructions, then let it work in the background. When I tell it "draft a reply to this email (which it has access to thru the gmail connector) and attach the latest docs" or "fill out this multistep immigration electronic travel authorisation form using my passport files saved in the folder", it just asks for the relevant info and handles the rest. It opens its internal web browser and programmatically fills out the forms.
It gets the task done in 5-10 minutes. It's it bit slow since I'm not paying extra for ultrafast mode, but it gets the job done. Frees up the brain to do other tasks.
It's exactly like vibe coding but for computer tasks.
- noname120
The elephant in the room is that ChatGPT Work/Codex use agentic quota, whereas Chat doesn’t (and is effectively unlimited on Plus and Pro plans).
On this principle I’ve built Codexify[1], a connector that provides a Codex environment to ChatGPT Chat. This enables unlimited 5.6 Sol high/xhigh usage on the Plus and Pro plans as well as access to the 5.6 Sol Pro model (which is not available in official Codex).
- simonjgreen
Missing from here is the marketing position. Claude _very_ rapidly gained traction in the business/enterprise space earlier this year with Claude Cowork leading that drive. So successful it was, it lead to Microsoft licensing the Claude Cowork IP and white labelling it as Copilot Cowork (has anything like that ever happened before?!). ChatGPT Work was, imo, largely driven by a panic at OpenAI that they were haemorrhaging market intrigue and LinkedIn zeitgeist and headspace to Anthropic. ChatGPT had been the de facto, almost the Generic Trademark in business, and they got comfortable. Claude Cowork was eating their lunch. The way Anthropic targeted finance teams, legal teams, sales teams, with their positioning was absolute product marketing genius.
ChatGPT Work is trying to reclaim some of that magic that Claude Cowork affords its users that is so hard to explain succinctly.
- schmorptron
Within the general theme of token subsidies slowing down, this seems like the logical step.
In my mind the timeline goes something like this product wise:
- Pepole figure out that having a general purpose not-just-coding agent actually works with newer models, openclaw and its buddies spawn
- How do you get this to the general consumer? Offer integration with services even stronger than before and give the chat a cloud vm with persistent storage as one path, claude computer use as the other.
- - Perplexity computer releases, and they slowly start nudging users from plan-included chat usage to more stongly limit using or even extra credit usage billed computer tasks
- - chatgpt and other main labs do the same with work, but they can afford to subsidize it a bit more still by just having it use codex quota
We'll see where it goes from here, but i do see the general trend of pushing people towards strongly billed features without explicitly taking away the previous chat experience because that'd make them look bad
- gruntled-worker
> My lethal trifecta model warns about the risks inherent in any agent system that combines access to private data with exposure to untrusted content and a way to communicate stolen information back to an attacker.
> ChatGPT Work combines all three!
The ChatGPT Work model would actually feel safer to me if they created a privacy boundary between the container-managing agent (browser operator/VM manager/code runner/etc) and the chatbot agent. Instead of me not typing privacy-sensitive things to the chatbot to avoid having them in my history, the chatbot would keep my history private from the container agent except on a need-to-know basis. That would remove the "access to private data" from the container's trifecta.
Not perfectly safe of course, just safer. Particularly if I could review the logs between the two agents.
- simonw
I just updated the article to link to this site: https://codex-tool-reference.simonw.chatgpt.site/
Which I created using this prompt in a fresh Work session:
> Build a site that lists every one of your tools - nearly grouped into categories - and for each one explain what it does. Try to exactly duplicate arguments and tool descriptions where possible. Design aesthetic should be technical docs, minimal flare
UPDATE: I had it add all of the available skills too. This solved a mystery: I didn't see a tool for controlling the headless browser. It turns out that's handled by a skill that tells is how to run the browser via its Node.js REPL tool: https://codex-tool-reference.simonw.chatgpt.site/skills/cont...
- agentdev001
Codex in ChatGPT Desktop + 5.6Sol is my daily driver for non-coding things, and it's great. FWIW, I've not explored what differentiates Codex and Work modes- Simon notes that Work 'feels more like regular Codex re-skinned'. OpenAI seems to say that they're 'optimized' for SWDev and general knowledge work respectively, but reading between the lines- I suspect that yes, this boils down to a reskin.
I have been of the opinion for the last 6 months that this product category* is going to be something that sticks. I really think that OpenAI and Anthropic have totally dropped the ball on getting their respective desktop apps in front of the enterprise business user cleanly. Both jumped early, and tried to retroactively fix their jump by combining MVP (Work, Cowork) into their existing app.
By now, my suspicion is that the business user has baked into their mind 'that claude thing is just the chat app I copy-paste stuff out of, it was kinda annoying'. OAI+Ant really need to reset, and shamelessly relaunch ChatGPT/Claude Desktop as a new product- and market the hell out of it as some shiny new solution to everything.
I'll also say that MCP was (considering stateless now) a massive mistake. Not that MCP doesn't have it's niche, but it completely dominated the airwaves of AI for enterprise. People found it confusing, and it wasn't adopted by biglabs in a low-friction way. I recall distinctly late last year, neither had a client that would support local MCP servers- even though the buzz […]
- xatxat
I recently figured out that I could use ChatGPT Work on my Pixel Phone to build native Android apps. It builds the app and you can then directly download/install the APK. So now I just build small utility apps on-the-go whenever I need them :)