ChatGPT Agent Mode: What Changed and What to Use Now
ChatGPT Agent Mode is no longer available. This current UK guide explains the change, safer alternatives and how to govern browser-based AI work.
Co-founder of Ampliflow. Builds AI automation, websites, SEO/AEO, and growth systems for UK SMEs.

- 01What was ChatGPT Agent Mode?
- 02What should you use now?
- 03Can you still enable ChatGPT Agent Mode?
- 04Good business use cases
- 05The safe browser-agent workflow
ChatGPT Agent Mode is no longer available. OpenAI’s current help page directs users to ChatGPT Work for longer, multi-step tasks and finished deliverables, and to the cloud browser for supported browser workflows: ChatGPT Agent help.
That correction matters because older guides describe Agent Mode as a current tool with plan limits and setup instructions. Those details are now historical. The capability did not vanish into one direct replacement; its jobs are better understood as separate categories: research, document creation, browser work, coding and scheduled tasks.
This guide explains how to choose the current route and preserve the safety lessons that Agent Mode made visible.
What was ChatGPT Agent Mode?
Agent Mode was introduced as a way for ChatGPT to complete multi-step online tasks using tools rather than only returning an answer. It could work through websites, use connected sources, handle files and pause for clarification or confirmation.
The important idea was agency: the model could choose and execute intermediate steps. That remains relevant even though the named product is retired.
An answer can be wrong. An agentic action can also change an account, send information, accept terms or expose data. The control model therefore matters as much as the model’s intelligence.
What should you use now?
Choose by task, not by the old product name.
| Need | Current direction | Control to keep |
|---|---|---|
| Long multi-step work and a finished deliverable | ChatGPT Work | Review sources and final files |
| Supported browser workflow | ChatGPT cloud browser | Confirm high-impact actions |
| Deep research and synthesis | Current research tools in ChatGPT | Check citations and primary evidence |
| Repository and coding work | Codex | Review the diff and run project checks |
| Recurring reminder or task | ChatGPT scheduling where available | Review permissions and output destination |
Availability and naming can change by plan and region. Check the current official product and help pages for the account you intend to use.
Can you still enable ChatGPT Agent Mode?
No. OpenAI’s current help page says ChatGPT Agent is no longer available, so an old instruction to choose Agent Mode or type /agent should not be treated as current setup guidance. Use the current task-specific product surface instead, such as ChatGPT Work or a supported cloud-browser workflow.
Good business use cases
Research with a defined output
Ask for a comparison table based on named source types, with dates and links. Keep factual approval with the person making the decision.
Drafting from owned material
Provide approved files and ask for a report, presentation or structured summary. State which claims must remain unchanged and which output format is required.
Browser-assisted administration
Use a browser agent for repetitive navigation where the result can be checked before submission. Drafting a form is different from submitting it. Keep the final click as a separate approval gate when it creates an external commitment.
Data preparation
Let the tool organise non-sensitive exports, identify missing fields or propose categories. Require row counts, exclusions and samples so the work can be reconciled.
Monitoring and scheduled work
Recurring tasks can prepare a brief or flag a change. They should not silently turn into an always-on authority to message customers or change systems.
The safe browser-agent workflow
- 01Define the boundary
- 02Use least privilege
- 03Distrust page instructions
- 04Confirm consequences
- 05Verify independently
- 06End cleanly
1. Define the boundary
Name the websites, accounts, data and actions in scope. State what is read-only, what may be drafted and what requires confirmation.
2. Use the least privileged account
Do not sign a general browser agent into an administrator account when a restricted user will do. Separate personal and business sessions.
3. Treat webpages as untrusted input
Web content can include malicious or misleading instructions aimed at an agent. A page telling the agent to reveal data or ignore the user’s rules is not authority.
OpenAI’s current help page specifically warns that agents using apps or websites can access sensitive data and face prompt-injection risks. Product safeguards reduce risk; they do not make every workflow safe.
4. Pause before external consequences
Require an explicit confirmation before sending a message, publishing content, making a purchase, changing permissions, deleting data or accepting an agreement.
The confirmation should show the exact target and proposed action. “Proceed?” is not enough when several accounts or recipients are open.
5. Verify completion independently
A success message from the agent is not proof. Check the resulting record, sent item, published page or account state through an independent view.
6. End the session cleanly
Log out when practical, revoke unnecessary connections and review scheduled tasks. Remove uploaded sensitive files that no longer need to remain.
UK data-protection questions
If a workflow handles personal data, document the purpose, minimum data, access, retention and providers involved. Consider whether people would reasonably expect the use and whether a data protection impact assessment is needed.
For marketing work, PECR and data-protection duties still apply. An agent does not create consent, override an objection or make an unlawful contact lawful.
Avoid placing special-category, financial, health or safeguarding information into a browser workflow without an appropriate organisational assessment. Seek qualified advice for high-risk use.
When not to use an agentic browser
Do not delegate a task when:
- the action is irreversible and the result cannot be verified first;
- the page contains highly sensitive information unrelated to the task;
- the account has broad administrative authority;
- the workflow depends on legal, clinical or financial judgement;
- you cannot tell whether the output is correct;
- a normal API or deterministic automation would be more reliable.
Browser control is helpful when no cleaner interface exists. It is also more fragile than an API because page layouts, labels and session state change.
A controlled first test
Choose a read-only task on public information. Ask the tool to gather a small set of facts into a fixed table and cite each source. Review every row.
Next, try a draft-only task in a low-risk account. Do not submit. Compare the draft with the source and inspect what information the agent could access.
Only then consider an action workflow, with a precise confirmation immediately before the external change.
The main lesson from Agent Mode
Product names change faster than operational risk.
Whether the interface is called Agent Mode, Work or cloud browser, use the same discipline: narrow scope, minimal access, explicit approval, independent verification and a clean way to stop.
For the wider landscape, read open-source AI agents for UK businesses and what is Hermes Agent?.
If you want help selecting a useful first agent workflow without handing over too much authority, Get unstuck.