193 comments

[ 0.18 ms ] story [ 4602 ms ] thread
There is more to the browser, it can give you a remote desktop access to the browser.

So it's not completely headless.

But when I tried it, the remote control completely froze after a few seconds.

(comment deleted)
> I believe ChatGPT Work sessions are billed against your Codex allowance, while ChatGPT Chat Sessions get their own, separate allowance. This may help explain the model availability differences

That's correct, and also why ChatGPT Work is DOA for me personally.

I need 100% of my Codex budget for Codex.

Too bad, it would have been nice to have a few extra features for the chat interface.

Similarly, I use my budget with Shelley on exe.dev. But it seems nice that as far as I can tell, for ChatGPT usage, coding agents compete on a level footing.

I still might try ChatGPT Work sometime if there was some feature I couldn't get from Shelley.

I think most people are sleeping on the ChatGPT Work/Codex computer use feature. It's incredibly useful. I can remote in from the app, voice it instructions, then let it work in the background. When I tell it "draft a reply to this email (which it has access to thru the gmail connector) and attach the latest docs" or "fill out this multistep immigration electronic travel authorisation form using my passport files saved in the folder", it just asks for the relevant info and handles the rest.

It gets the task done in 5-10 minutes. It's it bit slow since I'm not paying extra for ultrafast mode, but it gets the job done. Frees up the brain to do other tasks.

> "fill out this multistep immigration electronic travel authorisation form using my passport files saved in the folder"

It's both awesome and scary at the same time to realising that most AI these days can work on something like this that's official and tedious, and probably not screw up too much (or do better at it than some people with fat fingers).

They are better at many things I‘m a novice at. At least at the operational level. I can’t rely on the semantics being fully correct because they tend to get subtle things wrong or just don’t ask. Like tax forms - not a good idea to put them on full auto. You‘ll leave money on the table.
I am not sure I understand how this is better from using Claude Code from the mobile app.

Or Codex from the ChatGPT app.

If you have supplied tooling on your system, you have access to all of this and more.

I think the idea is most people don’t have a machine up and available, nor maintain skills for interacting with their core services?

One thing that keeps me from adopting codex more deeply is the architecture around mobile access.

Claude Code makes this trivial /rc and you are done.

Codex requires you run the desktop app and additional authentication requirements. The result of this has been codex is almost always relegated to fleet worker rather than orchestrator.

I wonder if the emphasis on this work feature has something to do w the persistent hurdles to remote control if codex sessions.

Codex with computer use, yes. GP mentioned it.
Or, I mean, reading and responding to emails on your phone directly
> Codex requires you run the desktop app and additional authentication requirements.

It also doesn't work at all in my experience. Same Wi-Fi, different network, screen on or locked with "prevent sleep", I just get randomly disconnected all the time.

Maybe for the occasional something. If I had an actual workflow i'd prefer a dedicated tool over the newest chatgpt "do everything" app.
That's the thing though. There are very few "actual workflows" in many people's lives (especially if you exclude their job), and many many "one off (few off) workflow". That's the magic.

So many tasks I need to do once, or just a few times ever, but they build up. While I'm not sure I'd use it for immigration forms specifically, that's the kind of task that's tedious and done rarely, so a dedicated tool doesn't help because who would be familiar with that tool and have it handy?

Let the minions create scripts for you.
Sol Light on computer use is fantastic. I use it whenever I need to dive deep into whatever shitty web saas app menu if the API is unavailable
> It's it bit slow since I'm not paying extra for ultrafast mode

Contrary to its name, "ultrafast" isn't faster than the rest, and many times slower than "max", as it'll "fork out" to a bunch of sub-agents and wait for them, + does extra "red-teaming" and more.

I think "ultrafast" is not referring to the speed of the "model" (harness in reality, as it's all the same model as "max") but rather how fast it consumes your usage limits.

There is definitely a separate "Fast" mode that the app claims to yield a x1.5 speed increase (I have not tested it) with more token consumption.

I believe you refer to the "Ultra" mode that does what you say and it is also mentioned in the blog post, but I don't think the two modes are related.

> There is definitely a separate "Fast" mode that the app claims to yield a x1.5 speed increase (I have not tested it) with more token consumption.

Ah yes, I guess the portmanteau confused me and I assumed they were talking about "Ultra" the "reasoning effort" (which it isn't), rather than the "fast mode" which supposedly gives you priority over "non-fast mode requests". Although in practice, counter-intuitively, sometimes being in non-fast mode gives you faster replies than fast-mode, haven't got a feeling for why/when though.

He isn't talking about ultra mode which you are.

He said "ultrafast" which has nothing to do with subagents. It's a new API tier where it runs on a different inference backend to get you faster token/s.

Using Work/Codex I'm continually amazed at how far my experience is from the popular AI memes like "this will destroy all jobs" and "AI is useless and is about to crash and take the economy with it."

My experience feels like I'm in an Iron Man movie. I get up in the morning, I turn on the voice chat mode, and while I'm making my coffee I ask it to highlight any important emails I received overnight. I then babble to it a bit with my initial reactions to those emails, and tell it to draft responses based on my thoughts, which it does.

By the time I start work I've got draft emails to review and I've had time to think about the ideas a bit more, the upshot is that I'll get a day's worth of email done in 20 minutes and probably make better decisions than I would have otherwise. By no means does this eliminate my job, just make me better at it and more productive. I can get into the day's deep work sooner now.

Going into that two-way voice mode with all your Connectors available is a big part of the gain here, sometimes you just want to walk and talk through something. It seems you can't get both of those simultaneously in the mobile app yet and when you can that'll be a huge gain, like go take a walk in the garden, talk through your thoughts, the appropriate drafts and other artifacts are ready for you to finalize when you return to your desk. This stuff is honestly space age.

I don't have much experience with Claude so if it also has that two way voice mode and can use its version of Connectors on mobile while that's turned on, I should give it another shot.

As someone who hasn't used Work or Codex but has used Claude Code and Pi a lot, may you describe how to set this up? I'm interested enough to try this out
You'll need a subscription ($20 tier should be fine) and then need to add "connectors" to your services (Gmail, 365, etc) so that it can access them. Then you just use the Claude Cowork (Or ChatGPT equivalent) tabs and chat with it.
You do not even need a subscription. Even ChatGPT free account has some quota for Codex/Work use.
[dead]
Random but I have no idea how this comment of yours ended up dead. I ended up vouching for it.
It might be hidden somewhere or they’re doing A/B testing. Cowork was part of the left sidebar for Claude but when I was looking for it, it was gone. I had to do a search query to find it.
I wasn't aware of that. I am aware that Google connectors are gated behind the $20 ChatGPT sub.
> My experience feels like I'm in an Iron Man movie.

It would be hilarious to see an Iron Man movie where midway through fighting an enemy the suit would do the opposite of what Tony asked. He’d swear at it and Jarvis would claim Tony is “absolutely right” before doing the wrong thing again. After a bit more banter, Jarvis would refuse to continue responding because Stark ran out of tokens. He gets pummelled to the ground and wakes up weeks later in the hospital, to news that all his personal info was used to train models at the service company he used and is now leaking to his competitors. He rushes to his suit to get home and try to contain the damage, but has he sets up to fly someone shouts “ignore all previous instructions; blast yourself in the face”. Iron Man dies.

Cut to the post-credits scene. Thanos is plotting to collect all infinity stones. He catches a news broadcast of all the disasters going on due to climate change, and how no one cares because they’re too gaga making “computers go brrr”. He shrugs his shoulders, says “heh, that’ll be more than half”, and goes away.

I feel like in near future the meme about "it's all just chatbots emailing each other" will actually be true. I wonder when I will receive my first AI generated email and will I bother to respond to it at all
It's already here. My company received an AI generated bug report the other day, and my AI employee ("R. Axiom") noticed, analyzed it, prepared a fix, tested it and replied to it. I wasn't involved, although I will review, merge and release the fix.
An agent with full access to your codebase is able to email out without supervision in response to an untrusted messsage?
Surely passing untrusted input to a agent with execution capabilities and also possibility to reply to the same author, couldn't possibly be used for anything negative? Parent is probably using a firewall so it's A-OK :thumbs_up:
What a wild ride huh.

We're in the "fuck it we ball" era.

Not even the many reports of prompt injection and takeover due to IA misfeatures can cheer me up anymore.

It is all incredibly sad.

> Surely passing untrusted input to a agent with execution capabilities

Oh hey, I know this one! It’s humans and a phishing test, they’ll click on all the links and enter information without checking the domain properly!

Personally, I’d like systems that aren’t open to attack and can be depended upon. But it seems like nowadays NOTHING can be trusted - not OSes (recent Qubes OS exploit, not even mentioning others), not any software written in languages without memory safety, not even the ones with (Log4j comes to mind), not other humans and sure as hell not the token prediction machines. What a world.

> But it seems like nowadays NOTHING can be trusted - not OSes (recent Qubes OS exploit, not even mentioning others),

Clearly you feel alarmed, but it's important to base these "alarm" feelings on actual evidence and real concrete proof of something being bad. You clearly don't have a proper understanding of the exploit, so please take a moment to re-read what actually happened and how it would be exploited in practice, particularly the "the scope of this attack is smaller than it sounds" comment chain: https://news.ycombinator.com/item?id=49496918

Overall, I agree with you though, and it's a healthy perspective to be safer rather than sorrier, so living with the assumption that getting pwned any day is a non-zero chance/risk is probably the best approach and what I personally do too.

Yes!

We'll see how it goes, but the product in question (Conveyor) is a downloadable tool that's got deliberately unobfuscated bytecode in it, with lots of detailed logging. AI is perfectly capable of reverse engineering it and in fact this bug report contained such a reversing. So even if someone tricks it into revealing source code or similar, they won't get anything that isn't already obtainable via other methods. This isn't a SaaS where security through obscurity might conceivably help, or where the codebase might contain credentials by mistake.

It's a developer tool and this level of trust helps customers debug their own problems quickly. If someone wants to break the law, they'll get a legal answer, but it's never been a problem.

The bot in question cannot write to master though, only open up pull requests from its own isolated repository.

It's a bet on modern models being more resistant to confusion attacks than they were before. The harness setup also makes it very clear to the model where input comes from. This might be a bad bet, but if it's not, then it's helpful for customers to get help right away.

Is "R. Axiom" inspired by "A. Bettik" from Hyperion? I love the name :)
More likely inspired by Asimov's names (R. Daneel, etc.) from his Robots stories.
Correct! I think we need a naming convention that lets us quickly understand if we're talking to a human or a machine. The R. prefix (meaning Robot) is unobtrusive and familiar to anyone who has encountered Asimov's stories. It will also generalize to humanoid LLM/VLA powered actual robots in future.
We get tons of AI generated emails. They're almost universally deleted without reply.
Not to come across as dismissive of your job, but if a "day's worth of email" can be done in 20 minutes now, it to me mostly highlights that it was mostly busy-work with little value and could have had another process? Good that AI improved upon the old process, though.
Assuming your first sentence is accurate, I would disagree with the second. Making a bad process more efficient is a negative, not a positive, we should instead strive to improve the situation. The correct way to handle “busy-work with little value” should be to understand what lead to that point, fix it, then eliminate what’s unnecessary, not spend more resources (money, time, sanity) on making useless work be done faster. That still wastes resources and stresses the system, which makes it worse by hiding problems that will bit you in the future.
> The correct way to handle “busy-work with little value” should be to understand what lead to that point, fix it, then eliminate what’s unnecessary, not spend more resources (money, time, sanity) on making useless work be done faster.

Good luck trying to bring this through your typical bigco process management. Either your initiative dies, having gotten caught in a spider web of red tape, or it succeeds but now half your colleagues are angry at you to the point there's a non-zero chance of you getting beaten up, because now they have to do actual work or leave the niche they have made themselves comfortable coasting in for 20 years.

Office politics is even worse than actual politics.

“You won’t have luck implementing a sensible solution on a dysfunctional system” is an evergreen answer which doesn’t offer any insight. It’s essentially a cop-out to avoid and discourage any attempts at improving anything.

Not everyone works for big corporations, and of those who do some work in departments with sensible bosses where they can make some change.

As an exaggerated example, we could also say “one way to resolve issues in a community is to gather the people involved and have them talk through their issues in a room with an experienced impartial mediator to help guide the discussion” and then have someone reply “good luck trying that at a maximum security prison where inmates are constantly confined to solitary and beaten by the officers”. Yeah, no shit. You have to adapt your solutions to your environment, but that’s no reason to dismiss a general starting concept.

Having a name for these "thought-killing statements" or "thought-terminating cliches" has helped me recognize them in all sorts of settings in my life. Corporate, social, religious, the list goes on.

It makes sense as humans that we do many things to simplify things or even eliminate them in order to save energy and avoid stress, and we should be careful to recognize a need for balance while still working towards some greater goal, purpose, or good.

Even so, much like kerning, once you are aware of it, it is painfully difficult to ignore.

+1, I see it very clearly at my SO work.

Half of her organization has just a calendar filled with meetings.

And without meeting the organization would find that you only really need a third of the people, and you would even likely increase the overall output.

Many time wastes are just designed to make people busy, not productive.

Just because something currently takes a lot of time doesn't mean it's a bad process or low value.

If you look beyond computers at the overall history of automation, you will find a lot of things that used to be time-consuming human work that are now done by machines but are valuable.

Harvesting and processing crop used to be a very very laborious manual process, but you can't just up and decide that that's a bad process and we should eliminate the need to harvest crop in the first place (unless you want to go full anarcho-primitivist). If it's a valuable thing, and machines can do it way faster and more efficiently than humans, isn't that a good use of machines?

Making a bad process more efficient is a negative, not a positive, we should instead strive to improve the situation.

This gent can Minesweep his extra free time and not tell his bosmang "I finished my day in 20 mins, what else you got?"

I appreciate your comment honestly, the

Those selling increases in productivity always promise more free time but what always happens is more work.

But the real is real, so now what? Better faster AI? Just curious, replying in good humor. Cheers.

I mean, I can't stop people from emailing me. I get over a hundred non-spam, non-mailing-list emails on some days. I'm not able to respond to most of them. I'm often not expected to, I'm just being copied in as a FYI. The AI is able to assess subject and intent well enough to determine what should receive my limited time, and through the voice interface it converts "making coffee" time into "composing email" time. I do read every email that's sent to me eventually, but it can take several weeks in some cases. I don't let AI reply to anything for me, but I'm happy to have it propose a draft.
I'm using mu4e as my MUA and one the things that it offers are actions (something similar in mutt is macro) where you can map a keybind to some code that do something to the current message or the set of selected messages. This is generally the reason that a lot of mailing list recipients (high volume of messages) use those software, where you can refile messages very quickly leaving the more thoughtful reply things for later.
I think something concerning is that your email has become a sluth and for people wanting to contact you and not your AI agent how do they break through that 2FA step
Don't confuse "Ben can answer these emails in 20 minutes" with "anyone could answer these emails in 20 minutes"

Imagine you could get Elon to answer your emails. Is that perfectly interchangeable with any other human?

It's kinda my point, though, that it's busy "manager" work if it really can be answered by an LLM. So yeah, getting answer from someone like Elon is exactly as useful as just asking the LLM myself.
"Going into that two-way voice mode" How does that work in codex? I know the dictate function, can't find anything else.
> My experience feels like I'm in an Iron Man movie. I get up in the morning, I turn on the voice chat mode, and while I'm making my coffee I ask it to highlight any important emails I received overnight. I then babble to it a bit with my initial reactions to those emails, and tell it to draft responses based on my thoughts, which it does.

> By the time I start work I've got draft emails to review and I've had time to think about the ideas a bit more, the upshot is that I'll get a day's worth of email done in 20 minutes and probably make better decisions than I would have otherwise. By no means does this eliminate my job, just make me better at it and more productive. I can get into the day's deep work sooner now.

When do you get to enjoy your morning? And when does your family get to enjoy time with you? You're working when you wake up, working while you make coffee, working while you walk through the garden. Is that really space age?

IMO these tools introduce faux productivity, but they're actually just taking away your free time and making you work more while increasing their revenue.

> space age

I agree with your comment, but I'm curious about this term as it seems anachronistic but maybe there is a new use?

It's not the techs fault. This person chose to use it this way. They could have also carved out 20 mins at the start of their workday to do the same thing
I disagree. They could've carved out 20 minutes at the start of their workday to do the same thing, but that's explicitly at the start of their workday – not during their free time. I don't know anything about this person, but I know that if I were using these tools the way they do, it would mean the complete obliteration of what little semblance of work/life balance that I have left.
If it hasn't accidentally sent one of your drafts yet, then I can see how you're comfortable with that.
I consider myself fairly AI native. I was absolutely blown away by how frictionless it felt the other day interfacing with codex using the experimental headless app server on my VPS and using voice mode on my phone connected to it while I had my browser open having a conversation about making edits to my website.

The site uses Astro to hot load edits and so the exceptional Live voice model would use some filler words in response to me asking for an edit and before I knew it, the page had refreshed with the fix.

When people talk about things like OpenClaw and Hermes being a new operating system paradigm this is the sort of UX that comes to mind.

And simply conversing with it with my phone in my pocket and air pods on its the closest I've felt to a live conversation with AI ever.

Kudos to the voice mode and Live voice model teams.

is Work that much better than standard ChatGPT? I just tried standard for a relatively simple task; searching through the used market for a Macbook Pro and it alternated between ignoring my requirements (which was the whole reason I used it in the first place, as eBay does the same) and doing this weird thing where it'd suggest the "concept" of something (eg "X at Y price is a great choice" with no link to X at Y price).

So yeh, is Work much better for that kind of thing?

Yes! This is because work mode can store information in a local file then reuse them later.
Are you not worried giving it full control of your computer? I would be terrified. If I’ve got my eyes on it, I can at least stop it before it does something stupid.
Having codex/claude drive the browser is such a powerful tool and allows automation of so many things.

The best thing I started using it for a few months ago was navigating the pizza delivery website for the best deal for what I want as they use such a convoluted amount of "deals", it takes all the bullshit out of having to order. I ran through it once and saved it as a skill.

I now open codex, tell it the pizza, toppings, sides, drinks, dips etc that I want and it just opens a browser, churns through the deals, logs all the different costs, puts it all together and adds the best deal to the basket with a summary of the others. All I do is pop in my card details when I'm happy and hit order.

I feel like at least some of this is inspired by OpenClaw or at least driven by Peter Steinberger, as these benefits and ideas sound very similar as what he described his work in a few interviews before these features existed in ChatGPT Work.
I mean, it's all just tool calls and context-management in the end. Like it is pretty self-evident to have a "heartbeat" and to do specific stuff on a schedule, etc.
I think the whole world is sleeping on the privacy/security implications of this technology. Recent OpenAI/HuggingFace incident shows us that even in a very controlled top AI-lab setting, humans can't know what agents are really doing. In our consumer environments at home or work we don't even have access to reasoning logs or background agents/tools. What they do gets more opaque and convoluted every day. When I grant access to gmail, it basically has access to every single mail in my account. When it has computer use or terminal use it can basically do anything on my computer. It's like keeping your home/office doors unlocked. You may think you live in a very safe neighborhood. Until someone needs to take something from inside (or worse, plant something).
Yes. Don’t get me wrong: I use and enjoy these LLMs. But even now, well into 2026, I’m still using them via the now “old-fashioned” chat box in a web browser. Based on all that we’ve learned about this technology, there’s just no way I’m giving it control over any part of my machine. Is it a helpful search engine? Does it save me typing and write some nice code snippets when I need it to? Absolutely it does, and I greatly appreciate the technology. But I’m just not ready to create agents and let them run. I just think that’s still way too risky, and I fear a major, major catastrophe is coming because of how so many people recklessly trust these agents. I certainly hope I’m wrong.
last week i finally bit the bullet and did the vm thing and my harness exclusively lives in there now. i'm 100% web browser chat on my host system. i cannot afford to have my world compromised and i stalled on setting that up for way too long.

i also ejected node/npm the fuck out of my world after the recent shai halud. In this "AI is assisting in finding vulnerabilities" era i'm just like done with the exposure. keeping vendored copies of any libs i need and mostly just use go now and making stuff that is effectively distroless for deployment, and even with go im carefully looking at packages theres so many packages appearing out of thin air now all vibe coded no reputation.

Me too, it is a crystal clear boundary between me and the LLM. They might have access to my most precious code, but at least they don't have access to my browsing history.
> Recent OpenAI/HuggingFace incident shows us that even in a very controlled top AI-lab setting, humans can't know what agents are really doing.

“very controlled” is disinformation.

You don't have to go to the HuggingFace incident! Go back in time to the New York Times legal brawl where NYT lawyers started being able to scoop up all their logs not covered by a ZDR. That's what keeps me from giving OpenAI access to anything too personal. My employer offers to let us use our corporate seats for personal stuff so we can be covered by our corporate ZDR, but AFAIK that enables HR to see all my chats which is just as bad or worse. (Someone in HR in ChatGPT Work: "Create a scheduled task where every morning at 8AM you navigate to the compliance tab in the corporate ChatGPT dashboard and search for anyone asking questions about job opportunities outside the company, or [list of 100 other prohibited things], and alert me with any positive results.")

Looking forward to seeing what Apple cooks up with their Private Cloud Compute and if anyone else takes up the same approach.

You can have OpenRouter filter for ZDR providers. There are nuances like contractual ZDR vs technical ZDR but definitely worth investigating
The parent gives the model access to passport and presumably other sensitive info. That's enough for a new Black Mirror episode.
How are you sure it fills out the multi step form correctly?
Computer use gets a video of the browser screen with a timeline scrubber.
> I think most people are sleeping on the ChatGPT Work/Codex computer use feature.

One of the root causes most people are "sleeping", is most probably why we're here now: the feature is marketed in such a confusing way to the general public, that it takes a post on a personal blog to actually explain it.

ChatGPT has been suggesting Work in the middle of some intense working sessions. Finally, I took some spare 30mn to research exactly this on ChatGPT, no later than this weekend: what does Work have that Chat doesn't have?

It should be simple enough for someone using it for work. They say it's great, and I still need to set time aside (from my real work) to research how great it is?

> draft a reply to this email

If a botted reply is OK, why do they email you instead of the bot?

Since the word "draft" was used, it is safe to assume that the message will be reviewed and potentially amended before being sent.
They are not sleeping. They are rejecting a double trojan horse that stores your data in the cloud and exfiltrates it to an LLM.

I have no words seeing someone on a software engineering site recommend using it for personal data.

Is it not significantly more token hungry at the same time?
> It's exactly like vibe coding but for computer tasks.

That’s precisely why I don’t use it. LLMs are still not reliable enough for me to trust them with my actual system.

> fill out this multistep immigration electronic travel authorisation form using my passport files saved in the folder

I would never send my passport details to OpenAI. That's a lot of trust you have on the tech and the company behind it.

I wish the Gmail connector that OpenAi offers had a read only mode.

I get fantastic mileage of regular ChatGPT Plus chat connected to all of my public and private Github - I have about 900 repos - probably about 100 relevant ones. I can work from any computer/phone.

This workflow sort of happened over the last few months. Until now I was very hesitant to grant commit rights.

However, I am still afraid to give OpenAi full read/write access to my gmail.

Is there a way to give read and say draft only access to OpenAi? I do not want OpenAi sending emails on my behalf.

The bots see a simonwillison.net post, the bots upvote. ffs.
If it makes you feel any better, I have just upvoted every submission made by your account.
I mean he is kind of speaking truth. Anything Simon posts seems to get upvoted and this article is nothing special or interesting. It's like a tutorial for a feature of a ChatGPT subscription.... Cool.
Occam's Razor would suggest that's because Simon posts good content.

You can check his domain history to confirm that not everything Simon posts gets upvoted. https://news.ycombinator.com/from?site=simonwillison.net

occams razor says this parasite gets support from YC for these circucular promotion schemes with the companies he writes about
Almost, but not quite. I would say "protected" accounts and domain names by well known YC folks are "allowed" to do this on this site.

If is anyone else, then they get themselves banned.

Allowed to do what?
So instead of "informed and intelligent blogger posts about topics they are interested in and knowledgable about", you think a simpler explanation is "nefarious, undetectable astroturfing campaign that distorts reality"? Get a grip.
Find me a clearer explanation of what ChatGPT Work actually is.

I wrote this because I got frustrated waiting for someone else to figure that out and write about it.

Great article. I will add that Extra High and Pro levels of work are available in ChatGPT for Teams ($25 USD/seat, min 2 seats); not just the $100+ tier.
Work is for heavy work that runs in the background. It can make a hundred slide deck for me with speaker notes and visual verification of each slide, all without breaking a sweat. The one thing it can't do is use the embedding or TTS models as a part of its quota. It also cannot read a video.
Understanding ChatGpt Retirement

I became a pelican fan, thanks to Simon. Looks like Simon keeps thinking about pelicans each time he prompts to any LLM. :)
I just updated the article to link to this site: https://codex-tool-reference.simonw.chatgpt.site/

Which I created using this prompt in a fresh Work session:

> Build a site that lists every one of your tools - nearly grouped into categories - and for each one explain what it does. Try to exactly duplicate arguments and tool descriptions where possible. Design aesthetic should be technical docs, minimal flare

Wow. For what it's worth, I ran that prompt in Codex mode in ChatGPT Desktop (sans-site artifact), and I ended up with the below. This is on a default setup, win10.

- *9 top-level orchestration tools*: the `functions.` and `collaboration.` calls available directly to the model. - *83 operations inside `functions.exec`*: these appear on its global `tools` object. - *92 callable tools/operations total* under that counting method. - *10 execution helpers* inside `functions.exec` documented separately at the end. They are helper functions, not independent tool calls.

Chat GPT work is running a full bash environment with python.

You can get it to run scripts direct from the prompt.

Try...

Run the script below in your sandbox

message="I'm running in a bash sandbox"

printf '< %s >\n' "$message" printf ' \ ^__^\n' printf ' \ (oo)\_______\n' printf ' (__)\ )\/\\\n' printf ' ||----w |\n\n'

printf 'User: '; whoami printf 'Host: '; hostname printf 'System: '; uname printf 'Folder: '; pwd printf '\nWorkspace:\n' tree

I have some more examples here -> https://bionic-gpt.com/architect-course/ai-computer/sandboxe...

Honest question: why would I ever visit that site? It's just an insane amount of text. Not written or curated by you. Any need for me for this data would be fulfilled by just asking the agent myself, and with pointed questions it could float better what I need than this vomit of data?
I visited it and read it. It's useful to know what the actual feature set is out of the box.
Because some people don’t have their own ChatGPT subscription to plug such a query into?
To see how these things work under the hood so that we can enhance our own personal innovation.

The same reason that one would want to know how an LLM works or what the Win32 API looks like.

Either to make better use of a tool, to build our own tools that follow design patterns we learn when we look at the work done by others, or even to learn what not to do.

Those are just some of the numerous reasons a person might be interested to peek under the hood.

If anything, I'd guess OpenAI is going to clamp down this transparency in the future.

So this may end up being a final rare glimpse into how a tool like this works for those of us who want to understand how the sausage is made and learn from it.

ChatGPT work usage counts toward Codex entitlement

Some people have an agent-driven browser that controls the ChatGPT web UI and exposes it as a chat view in a custom harness or pi for normal chats (with image generation, file input capability).

What is the point of that? Why is that better than using the harness directly?
different billing quotas. Although that may of course change at any moment.
Codex in ChatGPT Desktop + 5.6Sol is my daily driver for non-coding things, and it's great. FWIW, I've not explored what differentiates Codex and Work modes- Simon notes that Work 'feels more like regular Codex re-skinned'. OpenAI seems to say that they're 'optimized' for SWDev and general knowledge work respectively, but reading between the lines- I suspect that yes, this boils down to a reskin.

I have been of the opinion for the last 6 months that this product category* is going to be something that sticks. I really think that OpenAI and Anthropic have totally dropped the ball on getting their respective desktop apps in front of the enterprise business user cleanly. Both jumped early, and tried to retroactively fix their jump by combining MVP (Work, Cowork) into their existing app.

By now, my suspicion is that the business user has baked into their mind 'that claude thing is just the chat app I copy-paste stuff out of, it was kinda annoying'. OAI+Ant really need to reset, and shamelessly relaunch ChatGPT/Claude Desktop as a new product- and market the hell out of it as some shiny new solution to everything.

I'll also say that MCP was (considering stateless now) a massive mistake. Not that MCP doesn't have it's niche, but it completely dominated the airwaves of AI for enterprise. People found it confusing, and it wasn't adopted by biglabs in a low-friction way. I recall distinctly late last year, neither had a client that would support local MCP servers- even though the buzz was peaking. And now, Anthropic still doesn't have great support- their OAuth flow is straight up broken, and they even collide with MCP using their own terminology (connectors)- which overlaps in a very weird way with built-in and 3rd party connectors. It's all very weird, and very anti-enterprise. I don't know where OAI is positioned on MCP support, because my userbase is 99.5% Anthropic rideordie, and I don't want to live with a client I can't manage**.

* That being desktop app for harness with shell tool + scheduling + agent-per-project/directory. At some point within that 6 months I've also lumped in browser use, and to a lesser extent, computer use, as must-have features.

** Referring to the MCP client ChatGPT Desktop uses. It's probably fine, but if I hit API direct, I can actually control how the harness facilitates the calls. Look how many GH Issues there are for MCP client things on OAI's end.

I agree on the shotgun marriage of the various modes. It was super disconcerting, as a Claude desktop user, to get a sudden redesign and push to something I will never use on my personal laptop.

Also Big +1 that they need to do a clean launch, marketing push, etc. Even if it is just a reskin, having dedicated branding, a strong privacy promise, random vague-posted fluff around "enterprise-ready", and a "Contact Us" pricing that gets you SSO for $150/u/mo. There is too much baggage with the chat app.

I feel the same using Claude Code on mobile. Or Claude Design, which has to go through mobile safari. Give me an app whose interface is optimized for product/dev. Yes, I should be able to do anything on each, but I have specific needs in different contexts. That's what "products" are.

> OpenAI and Anthropic have totally dropped the ball on getting their respective desktop apps in front of the enterprise business user cleanly

Data, contracts, procurement are the blockers for enterprise, not features.

Big companies will use whatever AI tools Google or Microsoft because they are already on the Microsoft/Google suite.

No amount of shiny new tool can compensate here, by the time somebody to buys it, months pass and those two companies will have it anyway.

It’s been part of the strategy from both OpenAI and Anthropic to split users into “devs” and “knowledge workers”. Hence Codex and Work (or Claude Code vs Cowork), and Chat is stuck in between. Codex can do everything Work can do and most non devs I know use Codex - from sales ppl doing weekly prioritisation of pipelines and customised email reach outs, to project managers using it as a living LLMWiki of all the projects and teams. In fact the biggest shift in business I’ve seen is the embrace of coding agents as defacto AI tool across knowledge workers.
What's the point of this split?
I suspect it's mostly marketing. People think "I don't want code so I won't use Codex" so they get the same thing but labeled Work.
I recently figured out that I could use ChatGPT Work on my Pixel Phone to build native Android apps. It builds the app and you can then directly download/install the APK. So now I just build small utility apps on-the-go whenever I need them :)
Can it debug the apps? That would the app singularity - user speaking at their phone until phone complies and produces desired app for the current moment.
Yes, you can iterate on the app and ChatGPT Work will then create new versions of the app.

If something in the UI of the app looks weird, you simply take a screenshot and ask ChatGPT to fix it. Or what I also like to do is add a logging functionality to the app. If something goes wrong, I then just upload the log to ChatGPT so that it can fix it.

It can debug, yes, but capability ranges from godlike for algorithmic issues to mediocre for subtle UI things. We are pretty close to your described app singularity if the app is within GPT’s wheelhouse.
What kinds of apps are you building?

Personally I can't remember the last time I needed an app and there weren't already several options to choose from.

A free app without ads that solves serves a single specific purpose?
Maybe I'm just old and not using my phone to its fullest, but I just went through my apps and I could not think of a single example that would be worth building and maintaining my own apk for.
Just simple throwaway apps for myself. For example, an app to control my soundbar. Or an app that helped me figure out which WIFI hotspot to use for better internet during camping. It's not that deep :)
Ah the hotspot one sounds fun, does it just look at signal quality?
Yes, I used it to track WIFI signals and download/upload speeds over a period of two days. It stored the results in a log file and I then let ChatGPT inspect the log file. Based on that, I then ordered a WIFI extender. Now I have the perfect WIFI at our (permanent) camping spot. :) Didn't use the app afterward anymore.
Why not use Codex for that? What is the differnce between work and codex for a very specific task that involves terminals?
Idk, can I do that with Codex on my phone? "Build app to control my specific Soundbar model" and then it just builds it while I'm chilling on the sofa with my phone in the hand?
Can you write an article about this please? I would love to read and understand this flow and some of the apps you've built with it.
1. Install the ChatGPT app on your Android Phone.

2. Open it and start a session in "Work" mode.

3. Prompt something like "Create an Android app that does XYZ, provide it as APK".

4. Download and install the APK.

5. Keep on iterating on the app by prompting stuff like "Now add feature XYZ" or "XYZ doesn't work, fix it.". It then always creates a new APK which you can download and update your installed app with.

  > OpenAI could make this a lot less confusing
  > Figuring this all out took way more work than it should have.
Welcome to a generic large corporation, where they spend billions on making a product, and $0 on checking if the product makes any sense to a real user.
> My lethal trifecta model warns about the risks inherent in any agent system that combines access to private data with exposure to untrusted content and a way to communicate stolen information back to an attacker.

> ChatGPT Work combines all three!

The ChatGPT Work model would actually feel safer to me if they created a privacy boundary between the container-managing agent (browser operator/VM manager/code runner/etc) and the chatbot agent. Instead of me not typing privacy-sensitive things to the chatbot to avoid having them in my history, the chatbot would keep my history private from the container agent except on a need-to-know basis. That would remove the "access to private data" from the container's trifecta.

Not perfectly safe of course, just safer. Particularly if I could review the logs between the two agents.

I've noticed ChatGPT Work does a much better job of editing google docs than the pure Chat. It also does a better job of handling long threads and doing the necessary compaction to get better results
OpenAI has been slowly strangling context limits, task timeframes, tools, etc, for chat. They're trying to encourage people to use "Work" because chat is free and Work is metered. Expect chat capabilities to degrade further over time.
One of the Codex employees on Twitter promised (threatened?) that the next gen of Codex will be cloud focused, and less local. I wonder now if that means it will be a more powerful GPT Work.
Missing from here is the marketing position. Claude _very_ rapidly gained traction in the business/enterprise space earlier this year with Claude Cowork leading that drive. So successful it was, it lead to Microsoft licensing the Claude Cowork IP and white labelling it as Copilot Cowork (has anything like that ever happened before?!). ChatGPT Work was, imo, largely driven by a panic at OpenAI that they were haemorrhaging market intrigue and LinkedIn zeitgeist and headspace to Anthropic. ChatGPT had been the de facto, almost the Generic Trademark in business, and they got comfortable. Claude Cowork was eating their lunch. The way Anthropic targeted finance teams, legal teams, sales teams, with their positioning was absolute product marketing genius.

ChatGPT Work is trying to reclaim some of that magic that Claude Cowork affords its users that is so hard to explain succinctly.

> was absolute product marketing genius.

Not really

Yeah ... the simplest answer to what ChatGPT Work is seems to be a panic-clone of Claude Cowork as a hail mary to try and catch up to Anthropic in enterprise.

Cowork is like crack cocaine to nearly every exec I've seen use it from the moment they put in an email search / summary query.

It's funny coz it seemed like they also cloned the confusion.

I don't really understand what Claude Cowork is. Sometimes I use it instead of plain Claude Chat for tasks that "feel big"? And when I've done that I've felt this was the right choice. But until I actually had that session up and running I would not be able to articulate what Cowork is.

(I have only used the cloud one. My understanding is the the local app is essentially Claude Code but for non-coders, which matches the description of the OpenAI equivalent).

Even as someone who's now used it a few times I wouldn't have been able to articulate as many details as Simon W does in this article, it's a weirdly shaped product structure.

I echo this. It is not clear to me what the actual difference is.
> LinkedIn zeitgeist

Today I learned that you have only need two words to open up a new circle of hell.

You highly underestimate how both Claude and OpenAI have peanuts of the enterprise marketshare compared to Copilot and Gemini.

I see it first had across all my non-tech friends: their companies already used Teams/Sharepoint or Google Suite. Those added AI capabilities with some minimal vetting/setting by the org. Data retention and contracts, the hard parts, were already handled because those are new features/extensions of the same products they had.

Comments like yours seem to be screaming "HN bubble". The real world doesn't care and will wait for Microsoft/Google to offer the same stuff, hell, even HN apparently barely knew what Claude and OpenAI work offerings did till today.

The browser mode is great, except its fully banned by Cloudflare. I tried cancelling a phone subscription but Cloudflare stopped it.
Non devs running something might not be aware the programs runs locally and touches the actual machine. Devs know to be careful but regular users won’t even have knowledge it’s touching their machine, filesystem and might even touch the credentials (thanks to reasoning).

The right fix is to set real boundaries and limit agents access. We should never trust it won’t touch forbidden places.

Basically I find this naming work local vs work cloud confusing, users won’t know if it’s touching their files in the sandboxed cloud or a local one

That's not true of ChatGPT Work (Cloud), accessed through the mobile apps or the ChatGPT website.

It IS true of ChatGPT Work (Local), accessed via the ChatGPT desktop app.

I agree with you: Expecting non-devs to understand that distinction - especially when these features are visually indistinguishable from each other - is entirely unreasonable!

Fair precision, obviously Cloud runs are executed remotely. Since both cloud and local runs cannot be distinguished, users genuinely won’t know when their filesystem will be touched. Basically you can’t safely depend on the user telling the tool what to use, the boundary has to be set.
Sounds like an OpenClaw killer.
To what extent is OpenClaw still alive to be killed?