Key takeaways
- AI agents can complete a variety of requests without your intervention.
- Launched on Tuesday, the new skill is accessible through the agentic ChatGPT Work, which carries out assignments on its own based on your…
- The first time ChatGPT needs to access one of your website accounts, you'll be prompted to enter your username and password or your…
What happened
AI agents can complete a variety of requests without your intervention. One task that does typically need your input is logging in to a password-protected website. But a new option available with ChatGPT can automatically sign you in to one of your online accounts, at least under certain conditions.
After I deleted the cookies and tried again, I had to enter my username and password. This type of skill sounds convenient. But here's the big question: Is it a privacy risk? OpenAI says that ChatGPT can't see your username or password and that your credentials are never viewed by the AI model or used in model training. You control which websites ChatGPT Work is able to access.
The AI will also always ask for confirmation before consequential actions, such as completing a reservation or payment. But that brings us back to the same question: Is this a privacy risk? "This sounds like a privacy risk, but I would characterize it more accurately as an identity, security, and authorization risk," said Morey Haber, chief security advisor at identity security provider BeyondTrust.
"OpenAI states that ChatGPT is not exposed to the username or password (credentials)," Haber noted. "However, protecting credentials does not necessarily protect an identity from harm or hijacking. Once authentication succeeds, the AI agent is operating inside an authenticated session with whatever privileges and entitlements the user possesses. At that point, a threat actor may not need the password since attacking the session itself becomes the actual prize," Haber said.
To highlight the risk, Haber pointed to AI attack vectors like prompt injection. Here, an attacker can hijack an AI session to capture data or perform unwanted actions. Cybercriminals have already proven that they can steal session cookies and tokens. Put all these elements together, and your login details could be at risk, just like cookies from other browsers.
"Using the same credentials repeatedly for these connections, regardless of how they are stored, is a common problem that privileged access management and non-human secrets management have attempted to address for decades," Haber added. "So, is it a privacy risk," he asked? "Potentially, but the larger concern is delegated identity security risk. The password is merely the key to authentication. " Not necessarily.
Why it matters
Launched on Tuesday, the new skill is accessible through the agentic ChatGPT Work, which carries out assignments on its own based on your requests. Available only for ChatGPT Pro and Plus accounts, this new option uses ChatGPT's built-in browser to keep your session signed in for future tasks. How? By storing your login information in cookies, just like any other browser.
The first time ChatGPT needs to access one of your website accounts, you'll be prompted to enter your username and password or your passcode. You can manually type them or autofill them from a third-party password manager. The AI will then sign in to your account as expected. The next time ChatGPT needs to log in to that same site, you won't be prompted.
Instead, the AI will use the cookies generated from the previous session to sign you in without your input. To put this to the test, I fired up the ChatGPT Windows app, which uses its own built-in cloud browser. I asked ChatGPT Work to log in to my Amazon website account and list all the items and prices on my public wish list.
The first time I did this, the AI naturally prompted me to sign in with my Amazon credentials. But upon subsequent attempts, ChatGPT automatically signed in to my Amazon account without my input. I did bump into a couple of hiccups. First, trying this on the ChatGPT website resulted in an error in which Amazon blocked the attempt from the ChatGPT cloud browser.
In my testing, only the ChatGPT Windows app worked. Second, the first two times I tried this with the Windows app, the requests were successful. But when I attempted it a couple more times, access to Amazon was blocked. When I asked ChatGPT about this issue, the AI suggested that Amazon may be rejecting access because of recent or repeated activity.
What do you do if you no longer want your credentials stored this way? Just as you can delete a cookie from any other browser, you can also delete the ones stored in the ChatGPT browser. To do this, go to Settings and select Cloud Browser. Under Browser data, click the setting for Cookies.
You can then review the saved cookies for logged-in sites and delete any or all of them. I tried this by telling ChatGPT Work to sign in to my eBay account and list the items on my watchlist. With the eBay cookies stored in the cloud browser, I didn't need to enter my credentials on subsequent attempts.
What to watch
But you should exercise caution over which sites you let ChatGPT access.
"Users trying this feature should start with lower-stakes sites where the task is routine, and hold off on anything tied to sensitive information, such as finances or healthcare, until OpenAI provides more detail about how persistent access is protected and how to review or revoke it," said Shane Barney, chief information security officer at cybersecurity software provider Keeper Security.




