Leadership1 publisher3 min readPublished
Agents That Click: OpenAI Ships Computer Use, And Credential Policy Becomes Your Problem
OpenAI is rolling browser and app control out to customers while Anthropic pushes Claude Cowork. The open question is not capability but which credentials the software gets, and who reviews the log.
The Board Room · Leadership desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- OpenAI now has enough faith in the technology to start rolling out Computer Use tools to customers.
- This year OpenAI launched a Chrome extension that lets ChatGPT take over the browser, created cloud and in-app browsers for ChatGPT to interact with public websites, and added Computer Use to its Codex coding tool.
- The same underlying technology now also lets users have ChatGPT complete tasks on other apps.
- OpenAI president Greg Brockman wrote on X that an April update made the company's technology "no longer just for coders, but for anyone who does computer work."
- Employees who work on the tools told Business Insider that while there is room for improvement, the tools are at an inflection point.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
OpenAI has started rolling out its Computer Use tools to customers, and in the past year it has shipped a Chrome extension that lets ChatGPT take over the browser, cloud and in-app browsers for interacting with public websites, and Computer Use inside its Codex coding tool [1][2]. That is four separate surfaces where software now acts inside systems rather than answering questions about them [15], which makes credentials, scope, and audit an engineering decision rather than a procurement footnote.
Anthropic was first to market with its version in 2024 and is still working on it, and as of May at least 600,000 organizations had tried its Claude Cowork feature, which uses the tool, according to Business Insider [6][7]. OpenAI says its own capabilities have caught up [8], and employees who build the tools told Business Insider that there is room for improvement but that the tools are at an inflection point [5]. Read those two statements together before you plan a rollout: the people shipping it are saying it is good enough to hand work to and not finished.
The mechanics are the part worth reading twice. Previously, per Computer Use manager Ari Weinstein, ChatGPT took a screenshot, analyzed pixels, injected a command, and repeated; now, with a website open, it reads the page's memory structure, accessibility information, and link connections [9]. It still takes screenshots, and users are asked to let ChatGPT record their screen during setup so it can rapidly analyze what is on screen [10]. A tool that reads page internals and records the display is a data-handling question and an access question at the same time, and the two land on different owners in most organizations.
Unattended operation is already the selling point. Cristian Medina Ruiz, a hobbyist coder in the Czech Republic, used Codex with Computer Use to verify a rebuild of the 2013 game SimCity, and now leaves code running and iterating when he is away from the machine: "It does these things even when I'm away" [12]. Weinstein's framing is broader: "Once ChatGPT can use computers and software faster than you or I can, it's going to change the way that you, by default, want to interact with your computer" [13]. Default is the operative word. Defaults are set by whoever configures the extension first, which is usually not the security team.
Three decisions cannot be deferred. Which identity the agent uses, given that a browser takeover inherits whatever the operator is already signed into. Which surfaces are in scope, because OpenAI says the same underlying technology lets ChatGPT complete tasks in other apps, and president Greg Brockman wrote on X that an April update made the technology "no longer just for coders, but for anyone who does computer work" [3][4]. And what a reviewable record of agent actions looks like, since screenshots and page reads are inputs to the model, not an audit trail for you.
Watch whether that 600,000 trial figure converts into standing deployments [7], and whether either vendor ships admin-side scoping and logging as fast as it ships new surfaces. OpenAI declined to give specifics about its latest training data [14]; expect the same reticence about what the agent recorded on the way to finishing a task.