Business and economy·July 9, 2026, 19:00
ChatGPT Work: OpenAI's new AI agent gives IT departments a headache
AI-generated and checked against the sources listed below.
OpenAI has launched ChatGPT Work, an AI agent that can work on office tasks for hours at a time. Security experts and testers point to unresolved risks before companies let it into their systems.

OpenAI has launched ChatGPT Work, an AI agent for workplace tasks. An agent is an AI that doesn't just answer questions but carries out several steps in sequence on its own. According to Bloomberg, it can work on tasks for hours and produce documents, spreadsheets, presentations and web applications. It runs on OpenAI's latest model, GPT-5.6.
The article is based on coverage of the launch and on tests and assessments by others.
Why it's an IT problem
According to TechRepublic, ChatGPT Work can pull company information from connected apps and files, operate websites and programs, move files and continue scheduled work while the user is away. That means the agent can touch far more systems than an ordinary chatbot.
TechRepublic therefore recommends that IT departments map all connected systems and note whether the agent uses the employee's own login credentials, a shared account or a dedicated identity. The agent should only have access to the data and functions it needs for a specific task. Initially, it should also ask for approval before it sends messages, edits shared files, changes calendars or posts, or moves data.
The tester's concern: Open internet
Well-known software developer Simon Willison has tried out the tool. He found that Work is a unified agent platform with a code environment that apparently has open access to the internet. According to him, it can, among other things, pull code from GitHub, install programs and talk to external services. It also has a built-in browser that can fill out forms and take screenshots, and it can run several subagents at the same time.
His main point is that OpenAI has not explained how Work defends itself against prompt injection. That is an attack in which hidden instructions in a website or document trick the AI into doing something the user didn't ask for. The documentation was so sparse that Willison had to ask the tool itself to find out that it has 223 tools and 44 skills.
What it means for you
If your workplace starts using this kind of agent, the question is what they should be allowed to access. An agent with your permissions can in principle do everything you can, including by mistake. So ask your IT department whether there are rules for its use, and avoid giving the agent access to sensitive data until security has been sorted out.
Sources
Get the week's AI news in your inbox
Choose your level, topics and length. One email a week, unsubscribe at any time.
Subscribe to Promptly Newsletter



