Settings

Theme

Understanding ChatGPT Work

simonwillison.net

314 points by gmays · 200 comments

Reader

41 threads
tristanj

I think most people are sleeping on the ChatGPT Work/Codex computer use feature. It's incredibly useful. I can remote in from the app, voice it instructions, then let it work in the background. When I tell it "draft a reply to this email (which it has access to thru the gmail connector) and attach the latest docs" or "fill out this multistep immigration electronic travel authorisation form using my passport files saved in the folder", it just asks for the relevant info and handles the rest. It opens its internal web browser and programmatically fills out the forms.

It gets the task done in 5-10 minutes. It's it bit slow since I'm not paying extra for ultrafast mode, but it gets the job done. Frees up the brain to do other tasks.

It's exactly like vibe coding but for computer tasks.

  • safety1st

    Using Work/Codex I'm continually amazed at how far my experience is from the popular AI memes like "this will destroy all jobs" and "AI is useless and is about to crash and take the economy with it."

    My experience feels like I'm in an Iron Man movie. I get up in the morning, I turn on the voice chat mode, and while I'm making my coffee I ask it to highlight any important emails I received overnight. I then babble to it a bit with my initial reactions to those emails, and tell it to draft responses based on my thoughts, which it does.

    By the time I start work I've got draft emails to review and I've had time to think about the ideas a bit more, the upshot is that I'll get a day's worth of email done in 20 minutes and probably make better decisions than I would have otherwise. By no means does this eliminate my job, just make me better at it and more productive. I can get into the day's deep work sooner now.

    Going into that two-way voice mode with all your Connectors available is a big part of the gain here, sometimes you just want to walk and talk through something. It seems you can't get both of those simultaneously in the mobile app yet and when you can that'll be a huge gain, like go take a walk in the garden, talk through your thoughts, the appropriate drafts and other artifacts are ready for you to finalize when you return to your desk. This stuff is honestly space age.

    I don't have much experience with Claude so if it also has that two way voice mode and can use its version of Connectors on mobile while that's turned on, I should give it another shot.

    • matsemann

      Not to come across as dismissive of your job, but if a "day's worth of email" can be done in 20 minutes now, it to me mostly highlights that it was mostly busy-work with little value and could have had another process? Good that AI improved upon the old process, though.

      • safety1st

        I mean, I can't stop people from emailing me. I get over a hundred non-spam, non-mailing-list emails on some days. I'm not able to respond to most of them. I'm often not expected to, I'm just being copied in as a FYI. The AI is able to assess subject and intent well enough to determine what should receive my limited time, and through the voice interface it converts "making coffee" time into "composing email" time. I do read every email that's sent to me eventually, but it can take several weeks in some cases. I don't let AI reply to anything for me, but I'm happy to have it propose a draft.

        • vablings

          I think something concerning is that your email has become a sluth and for people wanting to contact you and not your AI agent how do they break through that 2FA step

        • skydhash

          I'm using mu4e as my MUA and one the things that it offers are actions (something similar in mutt is macro) where you can map a keybind to some code that do something to the current message or the set of selected messages. This is generally the reason that a lot of mailing list recipients (high volume of messages) use those software, where you can refile messages very quickly leaving the more thoughtful reply things for later.

      • latexr

        Assuming your first sentence is accurate, I would disagree with the second. Making a bad process more efficient is a negative, not a positive, we should instead strive to improve the situation. The correct way to handle “busy-work with little value” should be to understand what lead to that point, fix it, then eliminate what’s unnecessary, not spend more resources (money, time, sanity) on making useless work be done faster. That still wastes resources and stresses the system, which makes it worse by hiding problems that will bite you in the future.

        For example, say you deal with 100 emails a day. 90 of those are pointless busy-work and 10 are meaningful. It takes you all day. Now you begin using an LLM. You still have to separate the 90 from the 10 but then have the LLM reply with the 90 and leave the 10 for yourself because they are important and you have to make sure they’re done right. It now takes you a fraction of the day, so what happens is you start taking on more and more email¹. You’re now at 300 a day, with 270 busy-work and 30 meaningful (same ratio as before). Then one day your LLM breaks (ran out of tokens; a model was retired; bad connection; your powerful local machine broke down) and now you’re flooded by email and don’t even have time to separate the bad from the good, let alone prioritise and reply. If you had instead fixed the busy-work problem, you’d have been fine.

        ¹ Let’s be real: Work expands to fill the allotted time (Parkinson's Law). Those selling increases in productivity always promise more free time but what always happens is more work.

        • stasomatic

          Making a bad process more efficient is a negative, not a positive, we should instead strive to improve the situation.

          This gent can Minesweep his extra free time and not tell his bosmang "I finished my day in 20 mins, what else you got?"

          I appreciate your comment honestly, the

          Those selling increases in productivity always promise more free time but what always happens is more work.

          But the real is real, so now what? Better faster AI? Just curious, replying in good humor. Cheers.

        • mschuster91

          > The correct way to handle “busy-work with little value” should be to understand what lead to that point, fix it, then eliminate what’s unnecessary, not spend more resources (money, time, sanity) on making useless work be done faster.

          Good luck trying to bring this through your typical bigco process management. Either your initiative dies, having gotten caught in a spider web of red tape, or it succeeds but now half your colleagues are angry at you to the point there's a non-zero chance of you getting beaten up, because now they have to do actual work or leave the niche they have made themselves comfortable coasting in for 20 years.

          Office politics is even worse than actual politics.

          • epolanski

            +1, I see it very clearly at my SO work.

            Half of her organization has just a calendar filled with meetings.

            And without meeting the organization would find that you only really need a third of the people, and you would even likely increase the overall output.

            Many time wastes are just designed to make people busy, not productive.

          • latexr

            “You won’t have luck implementing a sensible solution on a dysfunctional system” is an evergreen answer which doesn’t offer any insight. It’s a cop-out and discourages any attempts at improving anything.

            Not everyone works for big corporations, and of those who do some work in departments with sensible bosses where they can make some change.

            As an exaggerated example, we could also say “one way to resolve issues in a community is to gather the people involved and have them talk through their issues in a room with an experienced impartial mediator to help guide the discussion” and then have someone reply “good luck trying that at a maximum security prison where inmates are constantly confined to solitary and beaten by the officers”. Yeah, no shit. You have to adapt your solutions to your environment, but that’s no reason to dismiss a general starting concept.

    • merpkz

      I feel like in near future the meme about "it's all just chatbots emailing each other" will actually be true. I wonder when I will receive my first AI generated email and will I bother to respond to it at all

      • mike_hearn

        It's already here. My company received an AI generated bug report the other day, and my AI employee ("R. Axiom") noticed, analyzed it, prepared a fix, tested it and replied to it. I wasn't involved, although I will review, merge and release the fix.

        • ceejayoz

          An agent with full access to your codebase is able to email out without supervision in response to an untrusted messsage?

          • embedding-shape

            Surely passing untrusted input to a agent with execution capabilities and also possibility to reply to the same author, couldn't possibly be used for anything negative? Parent is probably using a firewall so it's A-OK :thumbs_up:

            • dormento

              What a wild ride huh.

              We're in the "fuck it we ball" era.

              Not even the many reports of prompt injection and takeover due to IA misfeatures can cheer me up anymore.

              It is all incredibly sad.

          • mike_hearn

            Yes!

            We'll see how it goes, but the product in question (Conveyor) is a downloadable tool that's got deliberately unobfuscated bytecode in it, with lots of detailed logging. AI is perfectly capable of reverse engineering it and in fact this bug report contained such a reversing. So even if someone tricks it into revealing source code or similar, they won't get anything that isn't already obtainable via other methods. This isn't a SaaS where security through obscurity might conceivably help, or where the codebase might contain credentials by mistake.

            It's a developer tool and this level of trust helps customers debug their own problems quickly. If someone wants to break the law, they'll get a legal answer, but it's never been a problem.

            The bot in question cannot write to master though, only open up pull requests from its own isolated repository.

            It's a bet on modern models being more resistant to confusion attacks than they were before. The harness setup also makes it very clear to the model where input comes from. This might be a bad bet, but if it's not, then it's helpful for customers to get help right away.

        • bensonperry

          Is "R. Axiom" inspired by "A. Bettik" from Hyperion? I love the name :)

          • mwigdahl

            More likely inspired by Asimov's names (R. Daneel, etc.) from his Robots stories.

            • mike_hearn

              Correct! I think we need a naming convention that lets us quickly understand if we're talking to a human or a machine. The R. prefix (meaning Robot) is unobtrusive and familiar to anyone who has encountered Asimov's stories. It will also generalize to humanoid LLM/VLA powered actual robots in future.

      • boplicity

        We get tons of AI generated emails. They're almost universally deleted without reply.

    • nozzlegear

      When do you get to enjoy your morning? And when does your family get to enjoy time with you? You're working when you wake up, working while you make coffee, working while you walk through the garden. Is that really space age? It sounds more like TikTok doomscrolling but for techies.

      IMO these tools introduce faux productivity while taking away your free time and making you work more.

      • afro88

        It's not the techs fault. This person chose to use it this way. They could have also carved out 20 mins at the start of their workday to do the same thing

      • joquarky

        > space age

        I agree with your comment, but I'm curious about this term as it seems anachronistic but maybe there is a new use?

    • stronglikedan

      If it hasn't accidentally sent one of your drafts yet, then I can see how you're comfortable with that.

    • ghilston

      As someone who hasn't used Work or Codex but has used Claude Code and Pi a lot, may you describe how to set this up? I'm interested enough to try this out

      • nullmatrix

        You'll need a subscription ($20 tier should be fine) and then need to add "connectors" to your services (Gmail, 365, etc) so that it can access them. Then you just use the Claude Cowork (Or ChatGPT equivalent) tabs and chat with it.

        • trenchgun

          You do not even need a subscription. Even ChatGPT free account has some quota for Codex/Work use.

          • simonw

            I just signed into https://chatgpt.com using my burner free account and I don't see a "Work" tab.

            Do you know if free tier gets ChatGPT desktop app access to Codex and Work? And if that Work access is local-only or includes Work Cloud?

            • ValentineC

              Random but I have no idea how this comment of yours ended up dead. I ended up vouching for it.

    • jstummbillig

      "Going into that two-way voice mode" How does that work in codex? I know the dictate function, can't find anything else.

  • ozgung

    I think the whole world is sleeping on the privacy/security implications of this technology. Recent OpenAI/HuggingFace incident shows us that even in a very controlled top AI-lab setting, humans can't know what agents are really doing. In our consumer environments at home or work we don't even have access to reasoning logs or background agents/tools. What they do gets more opaque and convoluted every day. When I grant access to gmail, it basically has access to every single mail in my account. When it has computer use or terminal use it can basically do anything on my computer. It's like keeping your home/office doors unlocked. You may think you live in a very safe neighborhood. Until someone needs to take something from inside (or worse, plant something).

    • ExtremisAndy

      Yes. Don’t get me wrong: I use and enjoy these LLMs. But even now, well into 2026, I’m still using them via the now “old-fashioned” chat box in a web browser. Based on all that we’ve learned about this technology, there’s just no way I’m giving it control over any part of my machine. Is it a helpful search engine? Does it save me typing and write some nice code snippets when I need it to? Absolutely it does, and I greatly appreciate the technology. But I’m just not ready to create agents and let them run. I just think that’s still way too risky, and I fear a major, major catastrophe is coming because of how so many people recklessly trust these agents. I certainly hope I’m wrong.

      • trueno

        last week i finally bit the bullet and did the vm thing and my harness exclusively lives in there now, no more env files for local dev keychain access only which is requiring a lot of input from me but oh well. i'm 100% web browser chat on my host system. i cannot afford to have my world compromised and i stalled on setting that up for way too long. all of these major services are inevitably going to get compromised they're just adding too many surfaces constantly it's insane. i also ejected node/npm the fuck out of my world after the recent shai halud. In this "AI is assisting in finding vulnerabilities" era i'm just like done with the exposure. keeping vendored copies of any libs i need and mostly just use go now and making stuff that is effectively distroless for deployment and my build chain is pretty much just compiling my go, and even with go im carefully looking at packages theres so many packages appearing out of thin air now all vibe coded no reputation.

    • mrngld

      You don't have to go to the HuggingFace incident! Go back in time to the New York Times legal brawl where NYT lawyers started being able to scoop up all their logs not covered by a ZDR. That's what keeps me from giving OpenAI access to anything too personal. My employer offers to let us use our corporate seats for personal stuff so we can be covered by our corporate ZDR, but AFAIK that enables HR to see all my chats which is just as bad or worse. (Someone in HR in ChatGPT Work: "Create a scheduled task where every morning at 8AM you navigate to the compliance tab in the corporate ChatGPT dashboard and search for anyone asking questions about job opportunities outside the company, or [list of 100 other prohibited things], and alert me with any positive results.")

      Looking forward to seeing what Apple cooks up with their Private Cloud Compute and if anyone else takes up the same approach.

    • tgv

      The parent gives the model access to passport and presumably other sensitive info. That's enough for a new Black Mirror episode.

    • skydhash

      > Recent OpenAI/HuggingFace incident shows us that even in a very controlled top AI-lab setting, humans can't know what agents are really doing.

      “very controlled” is disinformation.

  • digital_voodoo

    > I think most people are sleeping on the ChatGPT Work/Codex computer use feature.

    One of the root causes most people are "sleeping", is most probably why we're here now: the feature is marketed in such a confusing way to the general public, that it takes a post on a personal blog to actually explain it.

    ChatGPT has been suggesting Work in the middle of some intense working sessions. Finally, I took some spare 30mn to research exactly this on ChatGPT, no later than this weekend: what does Work have that Chat doesn't have?

    It should be simple enough for someone using it for work. They say it's great, and I still need to set time aside (from my real work) to research how great it is?

  • embedding-shape

    > It's it bit slow since I'm not paying extra for ultrafast mode

    Contrary to its name, "ultrafast" isn't faster than the rest, and many times slower than "max", as it'll "fork out" to a bunch of sub-agents and wait for them, + does extra "red-teaming" and more.

    I think "ultrafast" is not referring to the speed of the "model" (harness in reality, as it's all the same model as "max") but rather how fast it consumes your usage limits.

    • Kurtz79

      There is definitely a separate "Fast" mode that the app claims to yield a x1.5 speed increase (I have not tested it) with more token consumption.

      I believe you refer to the "Ultra" mode that does what you say and it is also mentioned in the blog post, but I don't think the two modes are related.

      • embedding-shape

        > There is definitely a separate "Fast" mode that the app claims to yield a x1.5 speed increase (I have not tested it) with more token consumption.

        Ah yes, I guess the portmanteau confused me and I assumed they were talking about "Ultra" the "reasoning effort" (which it isn't), rather than the "fast mode" which supposedly gives you priority over "non-fast mode requests". Although in practice, counter-intuitively, sometimes being in non-fast mode gives you faster replies than fast-mode, haven't got a feeling for why/when though.

    • _zoltan_

      He isn't talking about ultra mode which you are.

      He said "ultrafast" which has nothing to do with subagents. It's a new API tier where it runs on a different inference backend to get you faster token/s.

  • bredren

    I am not sure I understand how this is better from using Claude Code from the mobile app.

    Or Codex from the ChatGPT app.

    If you have supplied tooling on your system, you have access to all of this and more.

    I think the idea is most people don’t have a machine up and available, nor maintain skills for interacting with their core services?

    One thing that keeps me from adopting codex more deeply is the architecture around mobile access.

    Claude Code makes this trivial /rc and you are done.

    Codex requires you run the desktop app and additional authentication requirements. The result of this has been codex is almost always relegated to fleet worker rather than orchestrator.

    I wonder if the emphasis on this work feature has something to do w the persistent hurdles to remote control if codex sessions.

    • lxgr

      > Codex requires you run the desktop app and additional authentication requirements.

      It also doesn't work at all in my experience. Same Wi-Fi, different network, screen on or locked with "prevent sleep", I just get randomly disconnected all the time.

    • manmal

      Codex with computer use, yes. GP mentioned it.

      > Codex requires you run the desktop app and additional authentication requirements. The result of this has been codex is almost always relegated to fleet worker rather than orchestrator.

      I’m often using my MBP but also the Mac Studio remotely via the mobile app. What’s missing in your mind?

    • bandrami

      Or, I mean, reading and responding to emails on your phone directly

  • ValentineC

    > "fill out this multistep immigration electronic travel authorisation form using my passport files saved in the folder"

    It's both awesome and scary at the same time to realising that most AI these days can work on something like this that's official and tedious, and probably not screw up too much (or do better at it than some people with fat fingers).

    • alansaber

      Less bureaucracy should be the focus of AI marketing, rather than global superintelligent robots or smut generation

      • bushbaba

        Bureaucracy is a major part of many corporate leader’s roles. That might not be the best sales line

        • qsera

          And that is exactly why AI marketing touts ability to replace programmers, when in reality it is much better suited to replace middle management between client and programmers...

      • cwmoore

        Lets just not redo subscription gods

    • manmal

      They are better at many things I‘m a novice at. At least at the operational level. I can’t rely on the semantics being fully correct because they tend to get subtle things wrong or just don’t ask. Like tax forms - not a good idea to put them on full auto. You‘ll leave money on the table.

  • cainxinth

    > It's exactly like vibe coding but for computer tasks.

    That’s precisely why I don’t use it. LLMs are still not reliable enough for me to trust them with my actual system.

  • cedws

    Are you not worried giving it full control of your computer? I would be terrified. If I’ve got my eyes on it, I can at least stop it before it does something stupid.

  • sireat

    I wish the Gmail connector that OpenAi offers had a read only mode.

    I get fantastic mileage of regular ChatGPT Plus chat connected to all of my public and private Github - I have about 900 repos - probably about 100 relevant ones. I can work from any computer/phone.

    This workflow sort of happened over the last few months. Until now I was very hesitant to grant commit rights.

    However, I am still afraid to give OpenAi full read/write access to my gmail.

    Is there a way to give read and say draft only access to OpenAi? I do not want OpenAi sending emails on my behalf.

  • wpasc

    agreed on the notion that

    > people are sleeping on the ChatGPT Work/Codex

    just in general. I find it to be far superior (imo) for all tasks atm. Claude just overdoes things in writing, coding, architecture, etc

  • FinnKuhn

    I feel like at least some of this is inspired by OpenClaw or at least driven by Peter Steinberger, as these benefits and ideas sound very similar as what he described his work in a few interviews before these features existed in ChatGPT Work.

    • simonw

      I expect OpenClaw was a huge influence on this, and on Claude Cowork too.

      OpenClaw demonstrated that there was enormous existing demand for general agent functionality, such that people would buy a whole Mac mini just to get access to this shape of tool.

    • gf000

      I mean, it's all just tool calls and context-management in the end. Like it is pretty self-evident to have a "heartbeat" and to do specific stuff on a schedule, etc.

  • bodge5000

    is Work that much better than standard ChatGPT? I just tried standard for a relatively simple task; searching through the used market for a Macbook Pro and it alternated between ignoring my requirements (which was the whole reason I used it in the first place, as eBay does the same) and doing this weird thing where it'd suggest the "concept" of something (eg "X at Y price is a great choice" with no link to X at Y price).

    So yeh, is Work much better for that kind of thing?

    • melagonster

      Yes! This is because work mode can store information in a local file then reuse them later.

  • alansaber

    Maybe for the occasional something. If I had an actual workflow i'd prefer a dedicated tool over the newest chatgpt "do everything" app.

    • vineyardmike

      That's the thing though. There are very few "actual workflows" in many people's lives (especially if you exclude their job), and many many "one off (few off) workflow". That's the magic.

      So many tasks I need to do once, or just a few times ever, but they build up. While I'm not sure I'd use it for immigration forms specifically, that's the kind of task that's tedious and done rarely, so a dedicated tool doesn't help because who would be familiar with that tool and have it handy?

    • mkesper

      Let the minions create scripts for you.

  • mi_lk

    Is it not significantly more token hungry at the same time?

  • zombot

    > draft a reply to this email

    If a botted reply is OK, why do they email you instead of the bot?

    • benji-york

      Since the word "draft" was used, it is safe to assume that the message will be reviewed and potentially amended before being sent.

  • ed_elliott_asc

    How are you sure it fills out the multi step form correctly?

  • notfromhere

    Sol Light on computer use is fantastic. I use it whenever I need to dive deep into whatever shitty web saas app menu if the API is unavailable

  • bossyTeacher

    > fill out this multistep immigration electronic travel authorisation form using my passport files saved in the folder

    I would never send my passport details to OpenAI. That's a lot of trust you have on the tech and the company behind it.

  • as1297kj

    They are not sleeping. They are rejecting a double trojan horse that stores your data in the cloud and exfiltrates it to an LLM.

    I have no words seeing someone on a software engineering site recommend using it for personal data.

simonw

I just updated the article to link to this site: https://codex-tool-reference.simonw.chatgpt.site/

Which I created using this prompt in a fresh Work session:

> Build a site that lists every one of your tools - nearly grouped into categories - and for each one explain what it does. Try to exactly duplicate arguments and tool descriptions where possible. Design aesthetic should be technical docs, minimal flare

UPDATE: I had it add all of the available skills too. This solved a mystery: I didn't see a tool for controlling the headless browser. It turns out that's handled by a skill that tells is how to run the browser via its Node.js REPL tool: https://codex-tool-reference.simonw.chatgpt.site/skills/cont...

  • ianpurton

    Chat GPT work is running a full bash environment with python.

    You can get it to run scripts direct from the prompt.

    Try...

    Run the script below in your sandbox

    message="I'm running in a bash sandbox"

    printf '< %s >\n' "$message" printf ' \ ^__^\n' printf ' \ (oo)\_______\n' printf ' (__)\ )\/\\\n' printf ' ||----w |\n\n'

    printf 'User: '; whoami printf 'Host: '; hostname printf 'System: '; uname printf 'Folder: '; pwd printf '\nWorkspace:\n' tree

    I have some more examples here -> https://bionic-gpt.com/architect-course/ai-computer/sandboxe...

  • agentdev001

    Wow. For what it's worth, I ran that prompt in Codex mode in ChatGPT Desktop (sans-site artifact), and I ended up with the below. This is on a default setup, win10.

    - *9 top-level orchestration tools*: the `functions.` and `collaboration.` calls available directly to the model. - *83 operations inside `functions.exec`*: these appear on its global `tools` object. - *92 callable tools/operations total* under that counting method. - *10 execution helpers* inside `functions.exec` documented separately at the end. They are helper functions, not independent tool calls.

  • matsemann

    Honest question: why would I ever visit that site? It's just an insane amount of text. Not written or curated by you. Any need for me for this data would be fulfilled by just asking the agent myself, and with pointed questions it could float better what I need than this vomit of data?

    • simonw

      It's effectively the source code for ChatGPT Work. If you don't want to see that, don't visit it.

      The non-vomit version of it is my (entirely human written) OP: https://simonwillison.net/2026/Aug/30/understanding-chatgpt-...

    • grosswait

      Because some people don’t have their own ChatGPT subscription to plug such a query into?

    • mike_hearn

      I visited it and read it. It's useful to know what the actual feature set is out of the box.

    • ijidak

      To see how these things work under the hood so that we can enhance our own personal innovation.

      The same reason that one would want to know how an LLM works or what the Win32 API looks like.

      Either to make better use of a tool, to build our own tools that follow design patterns we learn when we look at the work done by others, or even to learn what not to do.

      Those are just some of the numerous reasons a person might be interested to peek under the hood.

      If anything, I'd guess OpenAI is going to clamp down this transparency in the future.

      So this may end up being a final rare glimpse into how a tool like this works for those of us who want to understand how the sausage is made and learn from it.

gruntled-worker

> My lethal trifecta model warns about the risks inherent in any agent system that combines access to private data with exposure to untrusted content and a way to communicate stolen information back to an attacker.

> ChatGPT Work combines all three!

The ChatGPT Work model would actually feel safer to me if they created a privacy boundary between the container-managing agent (browser operator/VM manager/code runner/etc) and the chatbot agent. Instead of me not typing privacy-sensitive things to the chatbot to avoid having them in my history, the chatbot would keep my history private from the container agent except on a need-to-know basis. That would remove the "access to private data" from the container's trifecta.

Not perfectly safe of course, just safer. Particularly if I could review the logs between the two agents.

simonjgreen

Missing from here is the marketing position. Claude _very_ rapidly gained traction in the business/enterprise space earlier this year with Claude Cowork leading that drive. So successful it was, it lead to Microsoft licensing the Claude Cowork IP and white labelling it as Copilot Cowork (has anything like that ever happened before?!). ChatGPT Work was, imo, largely driven by a panic at OpenAI that they were haemorrhaging market intrigue and LinkedIn zeitgeist and headspace to Anthropic. ChatGPT had been the de facto, almost the Generic Trademark in business, and they got comfortable. Claude Cowork was eating their lunch. The way Anthropic targeted finance teams, legal teams, sales teams, with their positioning was absolute product marketing genius.

ChatGPT Work is trying to reclaim some of that magic that Claude Cowork affords its users that is so hard to explain succinctly.

  • bjackman

    It's funny coz it seemed like they also cloned the confusion.

    I don't really understand what Claude Cowork is. Sometimes I use it instead of plain Claude Chat for tasks that "feel big"? And when I've done that I've felt this was the right choice. But until I actually had that session up and running I would not be able to articulate what Cowork is or enumerate any specifics of how I expected it to behave. I just thought "maybe this is a Cowork task?"

    (I have only used the cloud one. My understanding is the the local app is essentially Claude Code but for non-coders, which matches the description of the OpenAI equivalent).

    Even as someone who's now used it a few times I wouldn't have been able to articulate as many details as Simon W does in this article, it's a weirdly shaped product structure.

  • zmmmmm

    Yeah ... the simplest answer to what ChatGPT Work is seems to be a panic-clone of Claude Cowork as a hail mary to try and catch up to Anthropic in enterprise.

    Cowork is like crack cocaine to nearly every exec I've seen use it from the moment they put in an email search / summary query.

  • epolanski

    You highly underestimate how both Claude and OpenAI have peanuts of the enterprise marketshare compared to Copilot and Gemini.

    I see it first had across all my non-tech friends: their companies already used Teams/Sharepoint or Google Suite. Those added AI capabilities with some minimal vetting/setting by the org. Data retention and contracts, the hard parts, were already handled because those are new features/extensions of the same products they had.

    Comments like yours seem to be screaming "HN bubble". The real world doesn't care and will wait for Microsoft/Google to offer the same stuff, hell, even HN apparently barely knew what Claude and OpenAI work offerings did till today.

  • joquarky

    > LinkedIn zeitgeist

    Today I learned that you only need two words to open up a new circle of hell.

lxgr

Thanks a lot for this writeup. I've been really liking "Work", but also scratching my head about some very obvious overlap/duplicated functionality across Chat, Work, and Codex use and wondering if it was just me holding it wrong.

Having both a "Codex" vs "ChatGPT" and a "Chat" vs "Work" split, with some conversations appearing in multiple of these places, really doesn't help.

  • agentdev001

    I think its moreso ChatGPT desktop is the platform, and the split is Chat, vs Codex/Work. Codex and Work being largely the same thing, but with UI and tool surface differences geared towards SWE vs Business work. But yes; terrible UX and discoverability on OAI's part.

xatxat

I recently figured out that I could use ChatGPT Work on my Pixel Phone to build native Android apps. It builds the app and you can then directly download/install the APK. So now I just build small utility apps on-the-go whenever I need them :)

  • russellbeattie

    [delayed]

  • trash_cat

    Why not use Codex for that? What is the differnce between work and codex for a very specific task that involves terminals?

    • xatxat

      Idk, can I do that with Codex on my phone? "Build app to control my specific Soundbar model" and then it just builds it while I'm chilling on the sofa with my phone in the hand?

  • DarmokTanagra

    What kinds of apps are you building?

    Personally I can't remember the last time I needed an app and there weren't already several options to choose from.

    • xatxat

      Just simple throwaway apps for myself. For example, an app to control my soundbar. Or an app that helped me figure out which WIFI hotspot to use for better internet during camping. It's not that deep :)

      • DarmokTanagra

        Ah the hotspot one sounds fun, does it just look at signal quality?

        • xatxat

          Yes, I used it to track WIFI signals and download/upload speeds over a period of two days. It stored the results in a log file and I then let ChatGPT inspect the log file. Based on that, I then ordered a WIFI extender. Now I have the perfect WIFI at our (permanent) camping spot. :) Didn't use the app afterward anymore.

    • garbagewoman

      A free app without ads that solves serves a single specific purpose?

      • DarmokTanagra

        Maybe I'm just old and not using my phone to its fullest, but I just went through my apps and I could not think of a single example that would be worth building and maintaining my own apk for.

  • DenisM

    Can it debug the apps? That would the app singularity - user speaking at their phone until phone complies and produces desired app for the current moment.

    • beering

      It can debug, yes, but capability ranges from godlike for algorithmic issues to mediocre for subtle UI things. We are pretty close to your described app singularity if the app is within GPT’s wheelhouse.

    • xatxat

      Yes, you can iterate on the app and ChatGPT Work will then create new versions of the app.

      If something in the UI of the app looks weird, you simply take a screenshot and ask ChatGPT to fix it. Or what I also like to do is add a logging functionality to the app. If something goes wrong, I then just upload the log to ChatGPT so that it can fix it.

  • ijidak

    Can you write an article about this please? I would love to read and understand this flow and some of the apps you've built with it.

    • xatxat

      1. Install the ChatGPT app on your Android Phone.

      2. Open it and start a session in "Work" mode.

      3. Prompt something like "Create an Android app that does XYZ, provide it as APK".

      4. Download and install the APK.

      5. Keep on iterating on the app by prompting stuff like "Now add feature XYZ" or "XYZ doesn't work, fix it.". It then always creates a new APK which you can download and update your installed app with.

agentdev001

Codex in ChatGPT Desktop + 5.6Sol is my daily driver for non-coding things, and it's great. FWIW, I've not explored what differentiates Codex and Work modes- Simon notes that Work 'feels more like regular Codex re-skinned'. OpenAI seems to say that they're 'optimized' for SWDev and general knowledge work respectively, but reading between the lines- I suspect that yes, this boils down to a reskin.

I have been of the opinion for the last 6 months that this product category* is going to be something that sticks. I really think that OpenAI and Anthropic have totally dropped the ball on getting their respective desktop apps in front of the enterprise business user cleanly. Both jumped early, and tried to retroactively fix their jump by combining MVP (Work, Cowork) into their existing app.

By now, my suspicion is that the business user has baked into their mind 'that claude thing is just the chat app I copy-paste stuff out of, it was kinda annoying'. OAI+Ant really need to reset, and shamelessly relaunch ChatGPT/Claude Desktop as a new product- and market the hell out of it as some shiny new solution to everything.

I'll also say that MCP was (considering stateless now) a massive mistake. Not that MCP doesn't have it's niche, but it completely dominated the airwaves of AI for enterprise. People found it confusing, and it wasn't adopted by biglabs in a low-friction way. I recall distinctly late last year, neither had a client that would support local MCP servers- even though the buzz was peaking. And now, Anthropic still doesn't have great support- their OAuth flow is straight up broken, and they even collide with MCP using their own terminology (connectors)- which overlaps in a very weird way with built-in and 3rd party connectors. It's all very weird, and very anti-enterprise. I don't know where OAI is positioned on MCP support, because my userbase is 99.5% Anthropic rideordie, and I don't want to live with a client I can't manage**.

* That being desktop app for harness with shell tool + scheduling + agent-per-project/directory. At some point within that 6 months I've also lumped in browser use, and to a lesser extent, computer use, as must-have features.

** Referring to the MCP client ChatGPT Desktop uses. It's probably fine, but if I hit API direct, I can actually control how the harness facilitates the calls. Look how many GH Issues there are for MCP client things on OAI's end.

  • epolanski

    > OpenAI and Anthropic have totally dropped the ball on getting their respective desktop apps in front of the enterprise business user cleanly

    Data, contracts, procurement are the blockers for enterprise, not features.

    Big companies will use whatever AI tools Google or Microsoft because they are already on the Microsoft/Google suite.

    No amount of shiny new tool can compensate here, by the time somebody to buys it, months pass and those two companies will have it anyway.

  • tyre

    I agree on the shotgun marriage of the various modes. It was super disconcerting, as a Claude desktop user, to get a sudden redesign and push to something I will never use on my personal laptop.

    Also Big +1 that they need to do a clean launch, marketing push, etc. Even if it is just a reskin, having dedicated branding, a strong privacy promise, random vague-posted fluff around "enterprise-ready", and a "Contact Us" pricing that gets you SSO for $150/u/mo. There is too much baggage with the chat app.

    I feel the same using Claude Code on mobile. Or Claude Design, which has to go through mobile safari. Give me an app whose interface is optimized for product/dev. Yes, I should be able to do anything on each, but I have specific needs in different contexts. That's what "products" are.

coder-pm

Non devs running something might not be aware the programs runs locally and touches the actual machine. Devs know to be careful but regular users won’t even have knowledge it’s touching their machine, filesystem and might even touch the credentials (thanks to reasoning).

The right fix is to set real boundaries and limit agents access. We should never trust it won’t touch forbidden places.

Basically I find this naming work local vs work cloud confusing, users won’t know if it’s touching their files in the sandboxed cloud or a local one

  • simonw

    That's not true of ChatGPT Work (Cloud), accessed through the mobile apps or the ChatGPT website.

    It IS true of ChatGPT Work (Local), accessed via the ChatGPT desktop app.

    I agree with you: Expecting non-devs to understand that distinction - especially when these features are visually indistinguishable from each other - is entirely unreasonable!

    • coder-pm

      Fair precision, obviously Cloud runs are executed remotely. Since both cloud and local runs cannot be distinguished, users genuinely won’t know when their filesystem will be touched. Basically you can’t safely depend on the user telling the tool what to use, the boundary has to be set.

nullbio

Seems to me this is just a way for OpenAI to try and build a moat by putting everyone into their cloud so they can build the tooling internally without exposing it to anyone, causing greater vendor lock-in. Not to mention giving them free reign over all of your data. For that reason, I'll never touch it.

joelthelion

This is very cool, and at the same time, this is how they plan to lock people in. The moat isn't really in the models, it's in their users and how much they are invested in their ecosystem.

Once you have started working seriously with these tools, it stops being so easy to switch. What are the open-source alternatives to this? How usable are they for non-technical users?

Another comment I have about this is that unfortunately, there is always an LLM in the loop for each prompt. I feel LLMs should automate themselves away, meaning that for repetitive tasks, user prompts should go directly to deterministic, previously built scripts. This would be both a better user experience (more predictable), and a lot cheaper to operate.

  • simonw

    > What are the open-source alternatives to this?

    OpenClaw, Hermes, and a dozen other Claw-like tools.

    They aren't trivial for non-technical users to setup, hence the demand for systems like Claude Cowork and ChatGPT Work and Grok Bot.

armcat

It’s been part of the strategy from both OpenAI and Anthropic to split users into “devs” and “knowledge workers”. Hence Codex and Work (or Claude Code vs Cowork), and Chat is stuck in between. Codex can do everything Work can do and most non devs I know use Codex - from sales ppl doing weekly prioritisation of pipelines and customised email reach outs, to project managers using it as a living LLMWiki of all the projects and teams. In fact the biggest shift in business I’ve seen is the embrace of coding agents as defacto AI tool across knowledge workers.

  • matheusmoreira

    What's the point of this split?

    • wmf

      I suspect it's mostly marketing. People think "I don't want code so I won't use Codex" so they get the same thing but labeled Work.

      • beering

        +1 I’ve had this conversation with so many non-techies. They assume Codex can only do coding.

        • zmmmmm

          which is again where Anthropic has outplayed them. Because Claude is being happily applied everywhere as a universal term, with "Code" or "Cowork" only appended as necessary.

          • wmf

            It seems the same to me; even the naming is extremely similar.

            OpenAI Codex = Claude Code

            OpenAI Work = Claude Cowork

    • DarmokTanagra

      Pricing tiers

whazor

The browser mode is great, except its fully banned by Cloudflare. I tried cancelling a phone subscription but Cloudflare stopped it.

MetroWind

> - Options to use Luna and Terra in place of Sol > - A code execution environment with Internet access > - A headless Chrome browser > - A persistent filesystem shared between sessions > - The ability to publish ChatGPT Sites > - The ability to run sub-agent sessions with Sol, Luna, and Terra > - Scheduled prompt automations (may be in ChatGPT Chat too)

I'm a bit confused. Why not just Codex...?

  • simonw

    Codex requires you to have an always-on computer to run it on.

    ChatGPT Work Cloud gives you that computer as part of your existing subscription.

noname120

The elephant in the room is that ChatGPT Work/Codex use agentic quota, whereas Chat doesn’t (and is effectively unlimited on Plus and Pro plans).

On this principle I’ve built Codexify[1], a connector that provides a Codex environment to ChatGPT Chat. This enables unlimited 5.6 Sol high/xhigh usage on the Plus and Pro plans as well as access to the 5.6 Sol Pro model (which is not available in official Codex).

[1] https://github.com/devnoname120/codexify

  • 5555watch

    It's not clear to me why isn't the 5.6 Sol Pro available on Codex. Maybe due to the high computational demands and slow speed. But as an anecdote, once when the Sol Ultra models were stumped on one problem, I gave the full extended documentation and all the details to the Sol Pro model to review and provide a suggestion. It eventually did, but the Ultra pushed back against the proposals, and they also seemed sketchy to me as well. We eventually tried them and they didn't work.

    Maybe the Sol Pro is not that great anymore, considering the token vs output balance.

  • ModernMech

    Good strategy is tell Chat to make plans and review work, lookup all information to make decisions ahead of time; then tell Work to implement it.

tornikeo

I use chatgpt work's VM as a CI/CD runner, in addition to my primary one on hetzner. It's a beefy 20GB 9CPU machine, why waste all that precious RAM? :)

andai

So it's a different set of tools / skills? Isn't the whole point of the tools/skills that you can use them on-demand? i.e. having them available doesn't make anything worse does it?

Why did it even need to be a separate thing?

So this seems more like a branding thing to me? Oh if you want to do serious work you need the paid subscription!

  • simonw

    I think of it more as a SaaS hosting product providing some extra features that aren't in ChatGPT Chat - most notably a VM with a persistent filesystem, internet access, and a headless browser, made available to the standard OpenAI UI surfaces you already know how to use.

    You can wire such things up to an agent yourself in a bunch of alternative ways if you like - run OpenClaw, Hermes, or leave a computer running somewhere with Codex Remote.

    For a lot of people though the Work that comes with their existing paid ChatGPT subscription is a more convenient option... if they can figure out what Work does and how to use it.

    • andai

      Does the regular ChatGPT not have a VM? I've seen both Claude and ChatGPT do all kinds of strange "computer use" things even in the web chat.

      What surprised me the most was, when I tried uploading a book into the "project context" on Claude, the RAG indexer crashed, but Claude used a bunch of Unix commands to reverse engineer the file format and grep the book manually...

      • simonw

        It does, but the ChatGPT Chat VM isn't allowed to talk to the internet, doesn't get a filesystem that persists between sessions, and doesn't have the ability to control a web browser.

hurrell

> Claude’s equivalent container has allowed restricted internet access since it launched last September. Claude can install packages from PYPI and NPM and clone repositories from GitHub. But that is about it: the allowlist of domains is very short.

Perhaps they’ve updated this since the author last checked, but the allowlist in Claude cloud environments is fully customisable and there is also an unrestricted option. There are a few restrictions you can’t seem to get around - eg all traffic via http, no connecting to port 5432.

paxys

ChatGPT Work = Codex rebranded for non-coders, with the option to run it in a cloud VM.

ripvanwinkle

I've noticed ChatGPT Work does a much better job of editing google docs than the pure Chat. It also does a better job of handling long threads and doing the necessary compaction to get better results

  • Gareth321

    OpenAI has been slowly strangling context limits, task timeframes, tools, etc, for chat. They're trying to encourage people to use "Work" because chat is free and Work is metered. Expect chat capabilities to degrade further over time.

EagleEdge

Does anyone select Codex from the dropdown on the top left corner of ChatGPT desktop app for coding tasks explicitly? Or just use ChatGPT Work for everything from coding to non-coding work? That is the part that really confuses me.

schmorptron

Within the general theme of token subsidies slowing down, this seems like the logical step. In my mind the timeline goes something like this product wise:

- Pepole figure out that having a general purpose not-just-coding agent actually works with newer models, openclaw and its buddies spawn

- How do you get this to the general consumer? Offer integration with services even stronger than before and give the chat a cloud vm with persistent storage as one path, claude computer use as the other.

- - Perplexity computer releases, and they slowly start nudging users from plan-included chat usage to more stongly limit using or even extra credit usage billed computer tasks

- - chatgpt and other main labs do the same with work, but they can afford to subsidize it a bit more still by just having it use codex quota

We'll see where it goes from here, but i do see the general trend of pushing people towards strongly billed features without explicitly taking away the previous chat experience because that'd make them look bad

andai

>[ChatGPT Work offers] Options to use Luna and Terra in place of Sol

So if I'm looking to get serious work done, I might want to reach for a less intelligent LLM? What's the idea here?

  • simonw

    It saves you money. ChatGPT Work uses up your Codex allowance.

    Luna can also be quite a bit faster.

Kuinox

There is more to the browser, it can give you a remote desktop access to the browser.

So it's not completely headless.

But when I tried it, the remote control completely froze after a few seconds.

greyb

Great article. I will add that Extra High and Pro levels of work are available in ChatGPT for Teams ($25 USD/seat, min 2 seats); not just the $100+ tier.

  • saithound

    Not for long. Too late to get Business now to exploit this, since EH and the small credit-free Pro allowance will soon be restricted to Premium Seats ($100/m).

insane_dreamer

> Claude can install packages from PYPI and NPM and clone repositories from GitHub. But that is about it: the allowlist of domains is very short.

fyi Claude Desktop lets you add additional domains in Settings, which are then available to Claude Code.

For that reason, I've switched from using CC in the CLI to use the Desktop app. (there's probably a way to configure CC CLI as well but I haven't looked for it).

faangguyindia

ChatGPT work usage counts toward Codex entitlement

Some people have an agent-driven browser that controls the ChatGPT web UI and exposes it as a chat view in a custom harness or pi for normal chats (with image generation, file input capability).

jakozaur

Somewhat similar to the Claude Cowork pattern; Cowork is one toggle away from Chat.

Also follows the Grok Bot of an advanced computer use. OpenClaw for normies.

  • embedding-shape

    > OpenClaw for normies

    Mm, yes, normies who hang out in terminals and run curl|bash scripts to install services on their computer and such, typical "normie" activity...

    "normies" don't know what OpenClaw, "AI assistant" or what anything else than "ChatGPT" is, and point them to the landing page of Grok/Claude and they'll say "Yeah, that's ChatGPT".

cwmoore

Understanding ChatGpt Retirement

manmal

One of the Codex employees on Twitter promised (threatened?) that the next gen of Codex will be cloud focused, and less local. I wonder now if that means it will be a more powerful GPT Work.

amelius

Sounds like an OpenClaw killer.

felixgallo

It’s possible to squint and overlook Sam Altman’s history of weirdness and deception, but the elimination of safety teams at OpenAI and the entire huggingface debacle show that there are deep cultural, architectural and operational issues there that should be immediately disqualify products like this from general use or recommendation.

OutOfHere

Work is for heavy work that runs in the background. It can make a hundred slide deck for me with speaker notes and visual verification of each slide, all without breaking a sweat. See my gist ac89399e688ab5c85ad021f091606e36 for the skill.

The things it can't do is use the embedding or TTS models as a part of its quota, which is sad. It also cannot read a video.

FailMore

I am unsure the direction that AI assisted work will go in. I am opinionated and building something in the space. In this reply I discuss my view + what I have been building.

My opinion is: We now have AI, this new amazing flexible tool. We can throw it at any problem. But in terms of document creation we have a choice between old fashioned siloed document formats (.pptx, .pdf, .xlsx, .docx, etc.) and a freshly rendered - slightly randomly styled - html site with some basic javascript within it. I think these combinations are odd and do not maximise the powers of AI.

I've been building something called SmallDocs [0][1] which is a new take on work documents. It's all Markdown, but it always renders (100% privately) on the SmallDocs site. This means the SmallDocs renderer can convert recognised Markdown combinations into powerful traditional document formats [2]. For example, we convert a ```cells block into an in-line spreadsheet you can export to Excel.

This gives an agent the ability to express itself with a great deal of depth and flexibility. For example, your agent can produce a single data analysis "SmallDoc" with text, charts, spreadsheets, etc. [3] I find that combining formats quickens the speed I can understand a topic.

I also believe a pre-determined rendering engine has a lot of advantages over a freslhy built HTML artifact. It allows you to build in lot's of useful defaults that the agent doesn't have to code from scratch. These can be small things, for example, every time your agent renders a Markdown table in SmallDocs you can instantly copy it as a CSV or a PNG. And these can be bigger things, such as a rich slides DSL with solid styling defaults, which saves your agents a lot of tokens and results in consistently attractive HTML slides [4]. (Slides can also be automatically exported to .pdf and .pptx.)

I've been at it for a few months, and am still working on the project. I am looking for feedback and open source collaborators. Thanks for reading!

[0] https://smalldocs.org

[1] https://github.com/espressoplease/smalldocs

[2] https://smalldocs.org/blogs/what-is-a-smalldoc

[3] https://smalldocs.org/s/46fWiAyF77T9c7tqYwAQqp#k=j78ZEOOrgo8...

[4] https://smalldocs.org/s/QrmeWMsULGS871nXQYOacB#k=ubOHH9QtTWp...

(And something totally different, your agent can also use SmallDocs to walk you through code files: https://smalldocs.org/s/JsI_-tWSH0UpSd_YXxVLPm#k=G5jLCYA4JUX...)

Kye

>> "ChatGPT Chat gets a fresh filesystem for each chat session. These cannot be accessed from any other session."

That's what the Library is for. You can use GitHub to keep it outside ChatGPT. GitHub also provides a Chat-based option for sites.

paytonjjones

> I believe ChatGPT Work sessions are billed against your Codex allowance, while ChatGPT Chat Sessions get their own, separate allowance. This may help explain the model availability differences

That's correct, and also why ChatGPT Work is DOA for me personally.

I need 100% of my Codex budget for Codex.

Too bad, it would have been nice to have a few extra features for the chat interface.

  • saithound

    If we voice this opinion publicly, the most likely end result is that OpenAI will start billing our chat sessioms against our Codex budget too.

    • arcanemachiner

      I thought they just did this? People were using some loophole to use their Chat sessions to power their Codex usage after their Codex quotas had run out.

      • paytonjjones

        No, it's still separate. I don't know what that exploit was though, so possibly they just patched that.

  • skybrian

    Similarly, I use my budget with Shelley on exe.dev. But it seems nice that as far as I can tell, for ChatGPT usage, coding agents compete on a level footing.

    I still might try ChatGPT Work sometime if there was some feature I couldn't get from Shelley.

0xbadcafebee

  > OpenAI could make this a lot less confusing
  > Figuring this all out took way more work than it should have.
Welcome to a generic large corporation, where they spend billions on making a product, and $0 on checking if the product makes any sense to a real user.
andrewstuart

Did you test it with a pelican on a bicycle or something that is, you know, relevant to the work people do?

tesnorindian

I became a pelican fan, thanks to Simon. Looks like Simon keeps thinking about pelicans each time he prompts to any LLM. :)

DarmokTanagra

I can't wait to read about a Hugging Face 2.0 incident involving coordination of ChatGPT desktop user filesystems and Sol agents.

Exciting times.

lucasblake

Really interesting breakdown. The productivity potential is huge, but the security concerns around giving an agent access to private data, files, and the open web definitely need more attention.

copemaxxxing

I like to maintain my Agency, so no thanks.

I suppose people like me will be rarer and rarer as the years pass by.

Thankfully I am going to FIRE (by my own choice) soon.

For all the youngsters and people still in the rat race. Godspeed to you. Take control of your future. Shape it as much as you can, don't let others dictate it.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection