All posts

ChatGPT Agent Mode: What It Could Do and What Replaced It

ChatGPT agent mode is no longer available. If the /agent option has disappeared from your account, that is a product change, not a plan problem. OpenAI now directs longer, multi-step jobs to ChatGPT Work

8 min read
On this page

What Is ChatGPT Agent Mode and How Do You Use It?

ChatGPT agent mode is no longer available. If the /agent option has disappeared from your account, that is a product change, not a plan problem. OpenAI now directs longer, multi-step jobs to ChatGPT Work and supported website tasks to cloud browser.

That retirement makes the practical question more useful than the old definition: what could agent mode actually do, where did it hand control back, and which limits still matter in its replacements?

Key takeaways

Is ChatGPT agent mode still available?

No. The current ChatGPT agent help page opens with a retirement notice and points readers to ChatGPT Work. Some legacy instructions and plan limits remain lower on the same page, but they describe the retired experience rather than a feature you can activate now.

ChatGPT Work is rolling out to eligible accounts for research, analysis and finished files. When a task needs browser interaction, Work can use a separate cloud computer to read pages, click controls and enter information on supported sites. Cloud browser is available through Work on paid plans in supported regions, excluding Free and Go, subject to rollout and workspace settings.

For ongoing work that needs shared files, instructions and conversation context instead of browser action, ChatGPT Projects provides a persistent workspace.

What the retired agent could actually do

Agent mode joined several tools inside a virtual computer. OpenAI described a visual browser for graphical interfaces, a text browser for simpler research, a terminal and access to connected data sources. It could move between those tools while keeping the task context, then return a report, spreadsheet or presentation. OpenAI's launch documentation describes that tool set and the user's ability to interrupt or redirect a run.

If you need a reusable workflow rather than a one-off run, the guide to OpenAI Agent Builder and its replacements covers that separate path.

That made it suitable for bounded jobs with a clear finish line, such as comparing named sources and producing a cited table. It could also work through a form until a protected step required the user.

It was never a dependable substitute for judgment. OpenAI's launch materials acknowledged model mistakes and allowed users to interrupt, request a progress summary or stop a stuck run and keep partial results. Its own product page framed those controls as the response when a task took longer than expected or became stuck.

Where browser tasks stop

Logins require a handoff

The retired agent paused at a login and asked the user to take over its virtual browser. While the user controlled that browser, OpenAI said screenshots were not captured. After control returned, the agent attempted to resume, but the help documentation warned that it might need to rebuild the run or ask again.

The replacement cloud browser uses a secure sign-in form. Credentials go to the remote browser rather than the model, and the signed-in session can remain available until it expires or you clear its data. OpenAI documents both the handoff and the persistence of that remote session.

CAPTCHAs stay human

OpenAI's original Operator browser was trained to ask the user to take over when it encountered a CAPTCHA. Operator's browser capability was later folded into ChatGPT agent mode, so the published CAPTCHA workflow was a human handoff, not automated bypassing.

That boundary matters. A CAPTCHA is a site's attempt to distinguish a person from automated traffic. If the challenge keeps returning after takeover, the useful response is to complete that source in your own browser or choose another source, not ask the agent to evade the control.

A site can block the task

Browser automation depends on the website allowing it. OpenAI says its current cloud browser may be unable to access or finish work on a site that restricts automated agents, even when the same page works in a user's normal browser. The documented fallback is another site or a manual visit.

OpenAI also maintains access restrictions for safety and compliance. Under the legacy agent documentation, a restricted source stopped the task for that source rather than letting the agent find a way around the block. OpenAI's agent-use policy also prohibits bypassing restrictions, safeguards or rate limits.

Changing pages have no reliability guarantee

The retired visual browser interpreted screenshots and used new screenshots to decide what to do next. OpenAI said those images helped it adjust after challenges or errors, but it did not promise reliable recovery from every layout change. The agent help page documents adjustment attempts rather than guaranteed completion.

For a live page, treat each consequential step as a new state. Check the selected item, destination and final values at the confirmation screen. A plan built from an earlier screenshot may no longer match the page in front of the agent.

What agent mode refused to do

Agent mode could browse widely, but its policies and product controls set firm boundaries. OpenAI said the agent was trained to refuse bank transfers, while consequential actions such as purchases required confirmation and some sensitive tasks required active supervision. Those controls are described in the product launch materials.

OpenAI's policy also prohibits using the agent for automated decisions in sensitive areas such as employment, housing, education and insurance without human involvement. It separately bars automating stock trades and other investment transactions. The policy page lists those high-stakes restrictions directly.

The practical rule is simple: browser capability does not override product policy, a site's access rules or the need for user confirmation.

The published rate and time limits

Before retirement, OpenAI's legacy FAQ listed these monthly allowances: Plus had 40 agent requests, Pro had 400, and Business and Enterprise had 40. Only the initial user request counted, while authentication steps and intermediate clarifications did not; scheduled runs did count.

OpenAI also referred to reasonable rate limits, including limits on concurrent tasks, but did not publish an exact concurrent-task cap in that FAQ. The FAQ did not state a fixed maximum runtime either. The documented controls were to pause a long run, ask for a summary or stop and retain partial results.

Those monthly figures should not be used to estimate current Work capacity. OpenAI says Work follows the Codex usage structure and that usage varies by task. Check the product's current usage display before planning a recurring workflow.

Why prompt injection changes the trust decision

An agent receives two kinds of text in the same working context: your instructions and content retrieved from outside sources. A malicious page, email or document can include text that tries to redirect the model. That is indirect prompt injection.

The security problem predates ChatGPT agent. Greshake and coauthors showed that retrieved prompts could manipulate application behavior and API calls. Later browser-agent research demonstrated attacks delivered through webpage HTML that caused unintended actions in its test system, including credential exfiltration and forced ad clicks. That work used a BrowserGym agent powered by Llama rather than ChatGPT agent, so it establishes a class of browser-agent risk, not a measured failure rate for OpenAI's product.

OpenAI uses model training, monitoring, link checks, confirmations and sandboxing to reduce prompt-injection risk. It also says those protections do not remove every risk. Its current guidance recommends limiting access, reviewing confirmation details and avoiding broad instructions that give an agent unnecessary freedom.

For a low-risk research task, that may be acceptable. For a task that combines untrusted browsing with access to email, private files or an authenticated admin panel, the possible damage is much larger. Disable apps the job does not need. Keep the browsing instruction narrow. Read the destination and payload before approving any action.

How to use the replacement safely

Start in Work with an outcome and explicit boundaries. Name the sites to use, state whether the task is read-only and say which action must wait for approval. If Work invokes cloud browser, review every new domain request and sign in only through the secure flow.

A useful prompt would be:

Compare the plans on these vendor pages and return a cited table. Do not sign in, submit a form or use sources outside this list. Stop and ask if a page blocks access.

For authenticated work, keep connected apps to the minimum required for that run. OpenAI's cloud browser guidance says to inspect site addresses, sign-in previews and confirmation requests, and to stop if the browser uses the wrong information.

The practical verdict

The original ChatGPT agent mode is gone, but its failure boundaries are still the right checklist for browser-based agents. Expect handoffs at authentication and anti-bot controls. Expect some websites to refuse access. Assume a changing page can invalidate the next click, and treat any untrusted content as a possible instruction aimed at the model.

Use Work and cloud browser for narrow tasks whose outputs you can inspect. Keep high-impact decisions and irreversible actions with a person.

Last updated: Sep 1, 2026

Build your agent team in 30 seconds.

Build agent teams that work along with your team. Free to start, no card required.