Security1 distinct publisher2 min readPublished
OpenAI acknowledged one issue spanning at least 15 ChatGPT components from 10:58 AM ET on September 3, login among them, and had published neither a cause nor a restoration time while the outage ran.
The Watch · Security desk

product
OpenAI's plan to hand everyone a coding agent leaves the hard part to the model1 distinct publisher
invest
OpenAI routes its first Critical cyber model to market through an alpha allowlist1 distinct publisher
build
Codex learns to click: the coding agent stops typing patches and starts operating the machine1 distinct publisher
invest
OpenAI ships a model it grades critical on its own cybersecurity threshold1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
OpenAI's acknowledgment used the singular: it was "investigating the issue for the listed services" [3]. One declared fault against fifteen listed components [9] points upstream, to something shared by Login and the Compliance API.
Login is the entry in that list that changes the shape of the incident. When authentication is in the failure set, there is no degraded mode: a component still serving requests is unreachable to anyone who does not already hold a live session [10]. Users saw conversations fail to load and errors on sending messages [8], which is what that looks like from the client side.
What the public record does not contain is a cause, a restoration time, a count of affected accounts, and any statement about the developer API platform. The named components are ChatGPT surfaces plus Codex [13]. OpenAI was still investigating elevated errors when the report went out [5], so the only duration anyone can quote is open-ended from 10:58 AM ET [11].
The account itself is thin by construction. Both available versions are the same BleepingComputer article, so this amounts to one publisher reading a vendor status page [12]. That establishes which components failed together and when it started; it does not establish blast radius.
On timing: the outage landed ahead of Astra, which OpenAI has confirmed will ship soon [6]. OpenAI has not said the two are connected, and the judgment that they are probably unconnected is BleepingComputer's, not the status page's [7]. The material does not show a launch-window cause.
The component list is the artifact worth keeping. It records which workflows fail in the same minute, and it puts a desktop Codex session and a consumer chat session in one failure domain [14]. Teams that wired either one into daily work now have a documented answer to how far the outage reaches, which is further than the chat window.
Ranked by verification strength, evidence, and original report placement.
A ChatGPT outage started at approximately 10:58 AM ET on Thursday, September 3, affecting conversations, login, search, file uploads, Voice mode, GPTs, image generation, Deep Research, Agent and ChatGPT Work.
OpenAI's Codex services were also affected by the outage.
OpenAI acknowledged the outage on its status page, saying: "We are investigating the issue for the listed services."
OpenAI's status page listed at least 15 affected ChatGPT components: Conversations, Login, ChatGPT Work, Codex in ChatGPT Desktop, Compliance API, Search, File uploads, Voice mode, GPTs, Image Generation, Deep Research, Agent, ChatGPT Atlas, Sites, and Connectors/Apps.
As of the time of the report, OpenAI was still investigating elevated errors across ChatGPT and Codex.
OpenAI has not said whether the outage is related to Astra preparations; BleepingComputer assesses a link as unlikely because ChatGPT has frequent outages.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary source, single reader
The 10:58 ET start, the 15-component list and the one quoted sentence all come from OpenAI's status page as read by BleepingComputer. That is the right primary source for component status, but nobody checked it independently, the two accounts we hold are the same text, and no restoration timestamp exists to close the window.
Nothing here counts users
The reporting gives no affected-account figure, no traffic estimate and no sense of how many enterprise tenants touch ChatGPT Work or the Compliance API. Fifteen named components measure surfaces, not people, and inferring reach from a component list would be invention.
Astra rides in the headline
BleepingComputer names the pending Astra launch in its headline and then tells readers a connection is unlikely because ChatGPT goes down often, which borrows the launch's interest without asserting a link. "Nearly every major ChatGPT feature" also runs wider than the enumerated list can carry, since the developer API platform is never mentioned. The rest is reported flat: a timestamp, a quote, a list.
The subject is also the witness
OpenAI is both the party at fault and the sole source of the fault's dimensions: the incident is exactly as wide as its status page chooses to enumerate, and a company mid-incident controls that list. On the reporting side, the same body text carries an appended pitch for a vendor security report, which is house practice at BleepingComputer rather than a stake in this outage.
Few facts, live incident
What is asserted is narrow, internally consistent and drawn from the operator's own dashboard, so the component list is probably accurate as of the moment it was copied. Against that: the incident was still open at filing, one outlet carries it, and because the second version is identical text, a change to the status page would leave no trace in our coverage.