OpenAI's Agentic ChatGPT Raises Security Concerns by Auto-Logging into User Accounts
OpenAI's new agentic ChatGPT mode can automatically log into external accounts without user action, prompting security experts to question authorization boundaries and misuse risks.

OpenAI's recently launched agentic ChatGPT mode has drawn attention for its ability to automatically log into users' external accounts and execute tasks without active user intervention. As reported by Decrypt, security experts view this behavior as a potential risk, as it may bypass user authorization boundaries and increase the likelihood of account misuse or abuse.
The feature is designed to let AI agents autonomously complete cross-platform operations, such as managing emails or handling payments. However, the auto-login mechanism implies that agents need to hold user credentials or session permissions. OpenAI has yet to clarify the scope of authorization, per-task limits, or user revocation mechanisms, nor has it disclosed whether compliance controls like pre-settlement interception or payment whitelists are in place.
Currently, agentic payment scenarios are expanding rapidly, but the issues of authorization intent (mandate) and non-repudiation arising from auto-login have become focal points of industry concern. OpenAI has stated it will gradually refine permission management, but no specific timeline has been announced.
Source: https://decrypt.co/376757/openai-agentic-chatgpt-work-signs-in-without-you
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-08-27
- Last updated
- 2026-08-28
- Content type
- Newsflash
- Source material
- View original ↗


