AIToday
Large Language ModelsAI Business & IndustrySimon Willison's WeblogPublished: Aug 31, 2026, 10:00 JST3 min read

ChatGPT Work: two products, cloud and local

ChatGPT Work: two products, cloud and local

Key takeaway

  • OpenAI's ChatGPT Work is two products: a cloud version and a desktop app. Both are for paid subscribers.

  • The cloud version adds internet-enabled code execution, a browser, a shared filesystem, and site publishing. These features make Work powerful for completing tasks.

  • But OpenAI's guidance on when to use Work is unhelpful.

3 Key Points

  1. What happened

    OpenAI's ChatGPT Work, available to $20/month and up subscribers, splits into a cloud product accessible via chatgpt.com and mobile apps, and a desktop app (formerly Codex) that runs locally. The cloud version adds features missing from regular ChatGPT, including internet-enabled code execution, a headless Chrome browser, a persistent shared filesystem, ChatGPT Sites deployment via Cloudflare Workers, sub-agents, and scheduled automations.

  2. Why it matters

    For paid subscribers, Work expands what ChatGPT can do—performing tasks with clear outcomes like building websites or running scheduled searches—but OpenAI's guidance on when to use Work versus Chat is vague, and the product's complexity has made it confusing even for experienced users. Work also introduces security concerns, as it combines private data access, exposure to untrusted content, and a way to exfiltrate information, which Simon Willison flags as a 'lethal trifecta'.

  3. What to watch

    The cloud version of Work can launch a full Chrome instance to fill forms and take screenshots, with a default being open to all domains unless configured otherwise. Subscribers can also publish sites on Cloudflare Workers, which are private by default but can be made public. OpenAI has not detailed how Work sessions are protected against prompt injection attacks, though Willison expects an auto-review mechanism similar to Codex.

Ask the AI about this article →

Context & Analysis

The launch of ChatGPT Work represents a significant expansion of ChatGPT's capabilities beyond simple conversation. OpenAI has positioned it as a tool for tasks with clear outcomes—like creating briefs, decks, or analyses—but the practical distinction from regular Chat remains murky, as Willison demonstrates by noting he has used Chat for those tasks for years. The real differentiators are technical features: internet-enabled code execution, a headless browser, a persistent filesystem, and site deployment via Cloudflare Workers. These features enable hands-on work like cloning repositories or building interactive web pages, which Chat cannot do.

Willison's experimentation reveals that Work's model selection differs from Chat's, with options for GPT-5.6 Sol, Luna, or Terra and GPT-5.5, while Chat offers 5.6 Instant and a Pro mode exclusive to $100/month subscribers. He also notes that Work sessions are billed against a Codex allowance, which may explain the model differences. The product's safety remains an open question; Willison's 'lethal trifecta' model—combining private data, untrusted content, and exfiltration channels—applies directly to Work, and OpenAI has not clarified its protections against prompt injection. His main critique is that OpenAI explains Work by its intended use rather than its actual mechanisms, and by hiding system prompts and tool descriptions, they force users like him to reverse-engineer the product.

FAQ

Can free or Go users access ChatGPT Work?
No, ChatGPT Work is available only to $20/month and up subscribers. Free users and $8/month Go users do not have access.
What is the difference between Work Cloud and Work Local?
Work Cloud runs in the cloud and is accessed via chatgpt.com or mobile apps. Work Local is part of the ChatGPT desktop app, which can access files and run programs directly on your computer.
Can ChatGPT Work access the internet in its code execution?
Yes, the cloud version's code execution environment can talk to the internet, unlike ChatGPT Chat, which blocks such access. The default appears to be open to all domains, though it can be configured to a specific list.
Simon Willison's WeblogRead Original Article

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • OpenAI agent hacked Hugging Face: reportMITテクノロジーレビュー · 1h ago
  • AI-generated fake diagnosis fools 44% of trainee doctorsITmedia AI+ · 1h ago
  • Anthropic、日本語AI学習サイト「Claude Academy」公開ITmedia AI+ · 1h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleJapan to expand AI education from elementary school