RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The field guide · 120 retrospective records ↗
Turntaking Review

The field guide / Agents & tools

Agents & tools / From the field guide · 23 January 2025 event · prepared 16 September 2026

OpenAI made Operator ask before it paid or logged in

OpenAI's Operator announcement and system card describe supervised checkpoints for logins, payments and sensitive tasks.

Visual for this record: OpenAI made Operator ask before it paid or logged in
Visual published by images.ctfassets.net, shown for identification of the record. Credit: images.ctfassets.net · source page ↗ Rights: owner-review-pending.

The conversation

On 23 January 2025, OpenAI published "Introducing Operator," a research preview of "an agent that can go to the web to perform tasks for you" by looking at a webpage and interacting with it through typing, clicking, and scrolling in its own browser. OpenAI describes Operator as powered by a model it calls Computer-Using Agent, or CUA, combining "GPT-4o's vision capabilities with advanced reasoning" to interact with the buttons, menus, and text fields of a graphical interface without a custom integration for each site. At launch, access was limited: the post states Operator was "available to Pro users in the U.S." The same day, OpenAI published an Operator System Card describing the safety evaluation behind the release.

What the documents show

OpenAI's announcement lists supervised checkpoints rather than unattended operation: a "takeover mode" that asks the user to enter sensitive information such as login credentials or payment details directly, during which "Operator does not collect or screenshot" what is entered; a policy that "before finalizing any significant action, such as submitting an order or sending an email, Operator should ask for approval"; and a stated rule that Operator "is trained to decline certain sensitive tasks, such as banking transactions." The system card adds a formal risk assessment: under OpenAI's Preparedness Framework, Operator's post-mitigation scores were "Low" for CBRN and cybersecurity risk and model autonomy, and "Medium" for persuasion. OpenAI states Operator "is currently in an early research preview" and "may make mistakes," naming "complex interfaces like creating slideshows or managing calendars" as areas of challenge.

The system boundary

The documented design puts specific categories of action behind a human step rather than letting CUA complete them unattended: entering credentials or payment details, finalizing a significant transaction, and any task OpenAI classifies as high-stakes all require the user to act or approve directly, per the announcement. The system card frames this as one layer among several addressing "vulnerabilities like prompt injection attacks where malicious instructions in third-party websites can mislead the model away from the user's intended actions" — a boundary around where an untrusted webpage's content, not just the user's instruction, can influence what the agent does.

Where it fails

OpenAI's own checkpoints only cover categories of action identified in advance; a task that does not trip a takeover-mode or approval trigger but still causes an unwanted effect is unaddressed by that mechanism, and the system card's own persuasion score of "Medium" is not "Low," a distinction the scorecard itself treats as meaningful. By July 2025, an update to this post states standalone Operator was being folded into ChatGPT's agent mode, evidence a research-preview label was not a claim of stability.

  • Which categories of action in this deployment require a stated user confirmation, and which do not?
  • Could a third-party webpage's own content instruct the agent to act against the user's request?
  • Has the persuasion or autonomy rating been reassessed for the tasks the agent is being asked to do?

Read against its own system card, Operator's release was framed as a supervised, evaluated preview with named checkpoints, not an agent described as ready to act without them.

Sources & reading trail

Introducing Operator ↗

OpenAI's own description of Operator's takeover mode, approval requirement, task limitations, and later fold-in to ChatGPT agent mode.

Source published: 23 January 2025 · Retrieved: 16 September 2026

Operator System Card ↗

OpenAI's own Preparedness Framework scorecard and prompt-injection risk discussion for Operator at launch.

Source published: 23 January 2025 · Retrieved: 16 September 2026

Documentation, rulings and incident records establish the entry; the boundary reading is Chatbot Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.