OpenAI Operator
DeveloperOpenAI
ReleaseJanuary 23, 2025; 20 months ago (2025-01-23)
SuccessorChatGPT agent
TypeAI agent
Websiteopenai.com/index/introducing-operator/

OpenAI Operator was an AI agent developed by OpenAI, capable of autonomously performing tasks through web browser interactions, including filling forms, placing online orders, scheduling appointments, and other repetitive browser-based tasks.[1][2] It uses OpenAI's advanced models to expand practical automation capabilities for users in daily activities.[3]

Operator was launched on January 23, 2025.[4] Operator was powered by the Computer-using Agent (CUA) model, which combined GPT-4o's visual capabilities with reasoning trained through reinforcement learning. CUA was designed to interact with graphical user interfaces like buttons, menus, and texts. [3] This development was apart of a broader movement toward AI agents that could perform tasks and just generate responses. Operator was described as apart of a shift toward systems that are capable of using web browsers to complete everyday tasks, comparing it to other technology companies that use similar computer use efforts. [2]

Operator was first available to ChatGPT users in the United States. In February 2025, it began to expand across countries like Australia, Brazil, Canada, India, Japan, Singapore, South Korea, and the United Kingdom[5]. In May 2025, OpenAI updated the model powering Operator from the GPT4o version to an o3 version keeping the 4o model for the API. The updated version included the safety training for tasks based on the computer. [6] In July 2025, ChatGPT was announced. This agent contains Operator's browser control capabilities. Operator was retired at the end of August 2025.[3]

ChatGPT agent, which had absorbed Operator's browser-control functionality, was itself removed from ChatGPT in early August 2026 without an advance deprecation notice; OpenAI's help center directed remaining users to ChatGPT Work and to a separate cloud browser feature for browser-based workflows.[7]

Technology and Uses

Operator's main technological feature was its ability to interact with websites through their graphical interfaces. CUA could process screenshots of a computer screen and determine what action should be taken next. It could use mouse and keyboard actions to click buttons, navigate menus, enter information, and scroll through webpages. Unlike software that depends on individual APIs, CUA was designed to interact with the interfaces that people themselves use; at the time this was early in technology stages but has proved to be useful in multiple cases with the creators aiming to extend that reliability to more tasks.[8]  

It was also reported that some websites blocked Operator, while companies including Instacart collaborated with OpenAI around its launch. Using Operator can be compared to using multiple tabs on a browser, users can have this system run several tasks by creating new conversations.This demonstrated that the introduction of computer using agents could affect how users and businesses interacted with websites. [9] The technology therefore represented a development in agentic AI, in which an AI system can carry out a sequence of actions toward a goal rather than simply responding to a prompt with generated text.

Performance and limitations

In benchmark assessments, Operator achieved notable success, scoring 38.1% on OSWorld benchmarks (OS-level tasks) and 58.1% on WebArena benchmarks. [10] Also achieving 87% on WebVoyager. It was also reported that human performance scored 72.4% on OSWorld, providing a comparison that showed a gap between the AI model and human performance regarding computer tasks. The system's performance depended on the complexity of each task. The user's performance was successful due to the real-world environment compared to artificial scenarios. Operator was also successful within the real-world environment like engaging with actual websites, but it struggled with the simulated websites. This performance does drop on complex multi-step tasks revealing limitations that AI agents currently face.  These results suggested that this system's training prioritized practical use over theoretical performance and how the system's performance depended on the complexity of each task.[11]

OpenAI noted that Operator could have difficulty with longer workflows. Creators received feedback during the early development that allowed for improvements regarding accuracy, reliability, and safety. Independent testing was conducted to test limitations. During this testing, it was reported that Operator often needed assistance with answering questions, gaining personal information, and obtaining control of its system when stuck. There were reported events in which the system provided incorrect answers. [12] The limitations provided results that show the Operator was not autonomous. It independently completes parts of a task as users monitor and intervene when necessary. Tasks that involve personal information or actions could result in consequences in the real world.

Safety and privacy

OpenAI emphasized privacy and safety measures within Operator, including stringent data protection protocols and built-in safety checks designed to prevent unauthorized sensitive actions or information misuse.[3]Safety concerns were created due to the systems ability to take actions on the behalf of users instead of just generating information. OpenAI's System Card identified tasks deemed harmful, model mistakes, and prompt injection as certain risk areas. OpenAI ran external testing along with other safety evaluations before releasing the system. Prompt Injection was relevant because Operator could encounter instructions within websites. A traditional chatbot did not have built-in safety checks to prevent misleading instructions for users to act upon. [13]

Operator was designed to request user confirmation before certain actions with external consequences. TechCrunch reported that the system could ask users to confirm actions like submitting an order or sending an email. Users would have control of their browser during these actions. Privacy was another concern due to the access that Operator had to personal information while users navigated websites. Independent tests reported that this system required the user to enter information like their name, email address, and phone number instead of unrestricted access. [14]

Operator was trained to limit tasks that include bank transactions or any high-stakes decision making. The moderation systems within Operator would issue warnings to users or revoke access after repeated violations along with review processes to find and address the misuse.[13]

Creators published guidelines that provide examples for violations to clarify:[13]

  • Engaging in illegal activity such as violating the privacy of others, depicting harm against children, and solicit illegal goods.
  • Intentionally scam, deceive, and use Operator to impersonate another person without their consent.
  • To engage in a regulated activity and not abiding by the laws pertaining to the activity like stock trading or investment transactions.
  • Creating or distributing harmful content to sexualize children, and bully or harass others.

Operator refuses around 97% of tasks within an internal evaluation set, which includes scenarios where a harmful prompt may appear at the beginning of the conversation or in the middle of a conversation. Operator refuses more harmful prompts within a test than the GPT-4o. [13]

Operator's capabilities are new along with the risks and mitigation approaches that the creators have installed with the expectation for this system to evolve while receiving user feedback and enhancing safety. The development of Operator contributed to OpenAI's broader work with AI agents. The browser interaction capabilities were incorporated into ChatGPT. [13]

Availability

Initially, Operator was only available to ChatGPT Pro subscribers in the U.S., with plans for broader availability to Plus, Team, and Enterprise users in the future.[10]

References

  1. ^ Lin, Belle (2025-01-23). "OpenAI's 'Operator' Agent Can Buy Groceries, File Expense Reports". Wall Street Journal. ISSN 0099-9660. Retrieved 2025-03-31.
  2. ^ a b Knight, Will (2025-01-23). "OpenAI's Operator Lets ChatGPT Use the Web for You". Wired. ISSN 1059-1028. Retrieved 2025-07-31.
  3. ^ a b c d "Introducing Operator". OpenAI Blog. 2025-02-01. Retrieved 2025-03-08.
  4. ^ Metz, Cade (2025-01-23). "OpenAI Unveils A.I. Agent That Can Use Websites on Its Own". The New York Times. ISSN 0362-4331. Retrieved 2025-03-31.
  5. ^ Ha, Anthony (2026-10-03). "OpenAI safety employee resigns, claiming the company's 'culture is broken'". TechCrunch. Retrieved 2026-10-05.
  6. ^ "Addendum to OpenAI o3 and o4-mini system card: OpenAI o3 Operator". OpenAI. Retrieved 2026-10-05.
  7. ^ "ChatGPT agent". OpenAI Help Center. Retrieved 2026-08-27.
  8. ^ "Computer-Using Agent". OpenAI. Retrieved 2026-10-05.
  9. ^ "Introducing Operator". OpenAI. Retrieved 2026-10-05.
  10. ^ a b McFarland, Alex (2025-01-24). "What You Need to Know About OpenAI's Operator". Unite.AI. Retrieved 2025-03-31.
  11. ^ McFarland, Alex (2025-01-24). "What You Need to Know About OpenAI's Operator". Unite.AI. Retrieved 2026-10-05.
  12. ^ Zeff, Maxwell (2025-02-04). "OpenAI's Operator agent helped me move, but I had to help it, too". TechCrunch. Retrieved 2026-10-05.
  13. ^ a b c d e "Operator System Card". OpenAI. Retrieved 2026-10-05.
  14. ^ Zeff, Maxwell (2025-01-23). "OpenAI launches Operator, an AI agent that performs tasks autonomously". TechCrunch. Retrieved 2026-10-05.