ChatGPT Agent Mode: What Replaced It, With 12 Examples
ChatGPT agent mode has been retired, and its job now belongs to ChatGPT Work and its cloud browser. What agent mode was, how Work takes a task today, what it stops to ask you, twelve example tasks with the checkpoint in each, and the risks that have not gone away.
7 min read
ChatGPT agent mode is no longer available. OpenAI’s help centre now says so at the top of the agent mode article and sends readers to ChatGPT Work for longer, multi-step tasks and finished deliverables, and to the cloud browser for work on websites. The idea survived; the switch did not. Instead of picking agent from the tools menu or typing /agent, you choose Work at the top of ChatGPT, describe the outcome you want, and it decides whether to use a connected app, a browser on a computer in the cloud, or both, stopping for your sign-in, your approval of a new website and your confirmation before anything hard to undo. If you searched for agent mode, Work is what you are looking for.
What agent mode was
Agent mode arrived in July 2025 and folded in Operator, OpenAI’s earlier browser agent. According to OpenAI’s announcement and help centre, it gave ChatGPT a visual browser that clicked through web pages, a text browser for simpler reading, a terminal and access to connected apps, and let it switch between research and action in one task: fill in a form, edit a spreadsheet, book something, with pauses for your confirmation. It ran on paid plans with a monthly allowance of agent requests. Older guides describing the tools menu, the /agent command and watch mode describe that product.
What replaced it: Chat, Work and Codex
ChatGPT now has three experiences. Chat is the quick, conversational one. Work is an agent for multi-step tasks that end in a deliverable: research, analysis, a document, spreadsheet, presentation or report. Codex is for software, in the desktop app. OpenAI’s overview of ChatGPT Work (opens in a new tab) says that on the web its tasks run in the cloud, not on your device, and that it can use the files, apps and tools available to you, including a cloud browser and code execution. In the desktop app, Work can also use local files and desktop apps with your permission.
- Where: ChatGPT on the web and mobile, and the desktop app. OpenAI’s pricing page (opens in a new tab) says Work is included in the Free, Go, Plus, Pro, Business, Edu and Enterprise plans, and lists the cloud browser in ChatGPT on the web only for Plus, Pro, Business, Edu and Enterprise. Availability also depends on workspace settings for business accounts.
- Runs without you: a task keeps going after you close the chat or your laptop, and pauses when it needs you.
- Repeats: Work can run once, on a schedule, or when an event happens in a connected app, such as a new Gmail message or activity on a GitHub pull request.
- Uses your computer: in the desktop app on macOS and Windows, computer use (opens in a new tab) lets Work operate other apps on screen. It asks before each app, and on Windows it runs in the foreground, so you cannot use the same session meanwhile.
- Produces files: documents, spreadsheets and presentations, including native Google Docs, Sheets and Slides when the Google Workspace app is connected.
The current docs describe two routes beyond the web. In the desktop app, getting started with Work (opens in a new tab) describes a composer control set to Work locally, for tasks that need files or apps on your computer, and a Cloud option, where offered, for tasks that should keep running after you close the app or turn off your computer. From the desktop app, the ChatGPT browser extension also lets Work read and act in your own Chrome, Edge, Brave, Opera or Vivaldi tabs, on sites where you are already signed in.
How to start a task
- Open ChatGPT and choose Work (from the toggle on desktop, or the dropdown on mobile).
- Describe the outcome, not the clicks: the website, the details that matter, the constraints, and what “done” looks like.
- Attach any files it should use, and connect the apps it will need.
- Approve website access when it asks, and sign in through the secure form if a site needs an account.
- Follow progress in the chat, answer its questions, and confirm or decline each consequential step.
- Check the result and its sources before you rely on it.
The checkpoints it stops at
The pauses are the part worth understanding, because they are where you stay in control. OpenAI’s browser documentation (opens in a new tab) describes four.
- Website access. By default it asks before visiting a new site. Settings offer Always ask, Auto approve (it checks the site and asks only if something looks wrong) and Always allow, which OpenAI does not recommend. You can also allow or block single sites.
- Sign-in. It pauses at a sign-in page and gives you a secure form. A separate review model checks the request for phishing first; what you type goes to the remote browser and is not visible to the model. The session then persists for later tasks until it expires.
- Consequential actions. Before anything hard to reverse or that creates a financial, legal or account commitment, such as confirming a booking or paying, it asks in the chat. Allowing a website does not remove this step.
- Take over. If it gets stuck, it asks you to take control of the cloud browser from your phone or computer, and you can ask for control at any time.
Connected apps add a fifth: an app’s write actions follow that app’s permission settings, and an admin can restrict an app to read-only actions. How that works is covered in ChatGPT connectors and apps.
12 example tasks, with the checkpoint in each
The first seven follow the kinds of task OpenAI lists for the cloud browser; the rest use Work’s files, apps and schedules. The checkpoint named is where you should expect it to stop.
- Find a table for six on Friday near the office, under a set budget, and hold the best option. Checkpoint: confirmation before it books.
- Compare flights for given dates across two airports and list the three best by total time. Checkpoint: nothing to confirm while it compares; a payment is a consequential action it asks you to confirm.
- Track a parcel using the shipping email in your connected inbox and the carrier’s site. Checkpoints: the app connection, and approval of the carrier’s website.
- Find the earliest appointment at a government office and prepare the booking. Checkpoint: it prepares, you approve submitting your details.
- Sign in to your energy supplier and compare your tariff with the ones on offer. Checkpoint: the secure sign-in form, with two-factor if the site uses it.
- Find flats that meet a list of criteria and save the listings to a spreadsheet. Checkpoint: approval for each new listings site.
- Match this month’s supplier invoices against the accounting software and flag the gaps before updating anything. Checkpoint: sign-in, then confirmation before any record changes.
- Every Monday, collect prices for five competitor products and add a row to a Google Sheet. Checkpoint: the schedule you set, and a look at the first few runs.
- Turn this quarter’s research notes into a presentation that follows the attached master deck. Checkpoint: your review of the file before it is shared.
- When a new email arrives from a named client, summarise it and draft a reply. Checkpoint: the trigger and the app permissions; sending stays with you.
- When a pull request is opened in a repository, write a plain-English summary of the change for the release notes. Checkpoint: the authorised repository and the trigger.
- Before a meeting, read the calendar invite and the linked documents and write a one-page brief. Checkpoint: which apps it may read, set before it starts.
Limits and risks
- Prompt injection. A page or email can contain text written to steer the agent. OpenAI’s example from the agent mode era was a malicious comment asking it to fetch a password reset code from Gmail and send it elsewhere. The advice still applies: connect only the apps the task needs, keep prompts specific, and stop the task if it opens the wrong site.
- Websites that refuse it. Some sites block automated browsers. That is the site’s choice; open the page yourself or try another source.
- Not every step is supported. A sign-in or payment step may not work in the cloud browser, and you may have to finish it yourself.
- Its browser is not yours. The cloud browser keeps its own cookies and sessions and never sees your own browser’s tabs, passwords or sign-ins. Clear its data under Settings, Cloud browser, Browser data after a sensitive task.
- Never paste passwords, security codes or card numbers into the chat. Use the secure sign-in form, or take over.
- Check the output. A report with sources is a draft until you have opened the sources.
When the results are work for other people
Work is good at producing a finished thing: a brief, a comparison, a sheet. What it produces often contains a to-do list, and that list is shared work, which belongs somewhere with owners and states rather than in a chat. fenbs is a small task board that ChatGPT can connect to as a custom MCP connector where your plan allows it. With it connected, ChatGPT can add tasks and comment on them under your role, in lanes To Do, Next Up, In Progress and Completed, and each change is recorded in the board’s History under its own name. The steps are on ChatGPT and fenbs, and turning a pile of requests into tasks is in turn feature requests into tasks with AI.
Related
What an AI agent is, in general: the glossary. Apps and connectors inside ChatGPT: ChatGPT connectors and apps. Organising ongoing work in ChatGPT: ChatGPT Projects best practices.