OpenAI’s ChatGPT Work is now available on both Windows and macOS desktop, turning the ChatGPT client into a place where users can hand off long-running, multi-step jobs instead of merely prompting for an answer. The July 9 launch combines a new Work mode with the existing Codex developer experience, adds ChatGPT Sites for lightweight web applications, and arrives alongside a PowerPoint add-in that can create and revise editable decks inside Microsoft PowerPoint.
The important correction to the initial coverage is that ChatGPT Work is not a standalone “enterprise AI employee” product limited to macOS, nor has Codex been folded into the same workspace. OpenAI’s own product documentation describes Work, regular Chat, and Codex as distinct experiences inside the desktop application. Work is available across Windows and macOS desktop plans; Codex remains a separate view dedicated to coding, local folders, terminals, repositories, testing, and code review.
That distinction will matter to Windows shops. The product OpenAI is selling is a broad work-execution layer that can use connected apps, cloud files, and—in the desktop client, with permission—local files and desktop applications. But it is also a collection of separately governed capabilities with separate rollout states, permission models, and costs. Treating it as one switch that turns ChatGPT into an autonomous employee is a good way to create an unmanaged data and billing problem.
OpenAI detailed the rollout in its ChatGPT release notes, while TechRadar separately reported that the company is positioning Work across finance, analysis, engineering, and other knowledge-work functions.
ChatGPT Work is intended for jobs that would be awkward in ordinary chat: researching a subject across connected sources, drafting a report, analyzing information, producing a spreadsheet or presentation, or building a lightweight site. It can break a task into steps, remain on a project for hours, and run Scheduled Tasks once, repeatedly, after a trigger, or while monitoring for changes.
The background execution is real, but the phrase “runs when the laptop is closed” needs a boundary. OpenAI says Work running on the web or mobile is cloud-based and synchronizes across web, mobile, and desktop. Those cloud tasks can continue after a user walks away. Local desktop access is different: users must open a local folder or project and grant permission to the files required, while locally held files and outputs stay on that computer unless the user explicitly moves or shares them.
For an IT department, that creates two different review paths. A cloud task may draw on connected SaaS services and continue without a workstation remaining online. A desktop task that receives local access introduces endpoint file exposure and application-control questions. The same user-facing “Work” label therefore covers materially different data paths.
OpenAI also says users can inspect progress, answer questions, alter direction, and approve important actions. That is useful, but it is not the same as a centrally designed approval workflow. Organizations should test what qualifies as an “important action” for each connected app before allowing Work to interact with production systems, customer records, shared mailboxes, or repositories containing deployment credentials.
The practical point is straightforward: Work can automate the preparation and movement of information, but it does not transfer accountability for a false report, an erroneous update, or an unauthorized action. The person and organization that enabled the connection still own the result.
That is more than interface trivia. Development agents have different security consequences from document-generation agents. Codex can interact with local folders, repositories, terminals, developer tools, tests, and commands; Work is framed around research, analysis, deliverables, apps, files, and recurring work. A single generic policy for “ChatGPT” is unlikely to give security teams enough control over both.
Windows developers should also note that Work’s availability is broader than the web rollout. OpenAI says Work is available to all plans in the macOS and Windows desktop applications, while web and mobile access is limited to Plus, Pro, Business, Enterprise, and Edu. The July 9 release notes further said that Pro, Enterprise, and Edu users would receive web and mobile access first, with Plus and Business following.
Availability does not equal enabled access in a managed tenant. OpenAI’s Enterprise administration guidance calls out separate decisions around which members use Work and Codex, what roles get which permissions, which apps are available, and which model is the default. Enterprise and Edu also received a two-week preview period in which Work was off by default, with admins able to opt out before automatic enablement.
That is the control point administrators should use. Do not deploy the desktop application and infer that the feature’s business use is already approved. Separate policy groups for Work, Codex, connected apps, and public Sites will be easier to defend than an all-or-nothing decision after employees have already linked corporate sources.
The original account is right that this reduces the distance between an idea and a usable internal tool. But “without a development pipeline” should not be mistaken for “without an operational pipeline.” OpenAI documents limitations around frameworks, private networks, databases, background services, and hosting patterns. A generated Site may be appropriate for a departmental dashboard or prototype, while still being unsuitable for a business-critical application that needs established identity management, retention policies, monitoring, disaster recovery, accessibility checks, change control, and a support owner.
OpenAI also lists the categories of information a Site can involve: prompts, instructions, conversation context, uploaded or referenced files, code, generated artifacts, hosted URLs, access settings, storage, metadata, logs, and operational data used to host, secure, debug, or enforce policy. That is a significantly wider record than a static web page.
For Enterprise tenants, public publishing is off by default and must be enabled by an administrator before eligible members can publish publicly. Sites are also unavailable at launch in the European Economic Area, Switzerland, and the United Kingdom. Those details undermine the idea that the feature is an instant public-hosting service for every customer worldwide; OpenAI has deliberately placed deployment and geography limits around it.
The right rollout is to begin with private, low-risk content using approved sources, then determine whether exported or hosted applications meet the organization’s own requirements. Public publishing should remain a distinct exception process, not the default permission that comes with building an internal prototype.
For Windows and Microsoft 365 administrators, this is not merely a ChatGPT feature; it is an Office add-in deployment. OpenAI’s installation documentation instructs users to install it through PowerPoint’s Add-ins interface and Microsoft Marketplace. Organizations that block store-based add-ins can deploy it through the Microsoft 365 admin center using a manifest, assign it to selected users or groups, and may need to enable it under role-based access controls.
The product comes with explicit limitations. OpenAI warns that advanced edits involving charts, shapes, formatting, and slide management may be limited or still under development, and that generated or edited slides may not perfectly follow a preferred template. It also tells users to review claims, numbers, citations where available, and changes before sharing, and to duplicate important files first so they can revert.
That warning should be treated as an operating requirement, especially where decks become management reporting or customer material. An editable PowerPoint output can create a dangerous sense that the underlying claims have been checked. It has not. The PowerPoint surface makes the last mile of production easier; it does not validate the data, verify financial calculations, or assure that an imported source was current.
ChatGPT for PowerPoint remains free for Business and Enterprise customers through August 6, 2026. After that date, PowerPoint use joins the same flexible, token-based billing model. OpenAI’s Business release notes say the usage draws from the general Codex agentic usage pool after included usage.
This is the launch’s most immediate operational consequence. Seat-based purchasing made it relatively simple to predict a monthly cost for an AI assistant. A shared agent that processes a large folder, performs repeated scheduled monitoring, produces long documents, and revises multiple decks turns AI consumption into a variable workload expense. The economics will be closer to cloud consumption than to an ordinary office-suite license.
OpenAI’s GPT-5.6 model family adds another cost-and-performance choice. Free and Go users receive GPT-5.6 Terra in Work and Codex, while Plus, Pro, Business, and Enterprise customers can choose Sol, Terra, or Luna and set effort per task. Pro and Enterprise users receive Work’s Ultra mode. Administrators should avoid assuming that “stronger model” or “higher effort” is free simply because a user already has a paid seat.
The immediate task for Windows and Microsoft 365 administrators is to inventory who can enable Work, Codex, Sites, and the PowerPoint add-in; restrict connected apps to approved sources; decide whether public Site publishing is ever permitted; and set cost monitoring before the August 6 PowerPoint billing change. ChatGPT Work gives employees more ways to complete work without switching tools. It also gives IT more distinct execution surfaces to govern.
That distinction will matter to Windows shops. The product OpenAI is selling is a broad work-execution layer that can use connected apps, cloud files, and—in the desktop client, with permission—local files and desktop applications. But it is also a collection of separately governed capabilities with separate rollout states, permission models, and costs. Treating it as one switch that turns ChatGPT into an autonomous employee is a good way to create an unmanaged data and billing problem.
OpenAI detailed the rollout in its ChatGPT release notes, while TechRadar separately reported that the company is positioning Work across finance, analysis, engineering, and other knowledge-work functions.
Work can persist beyond the chat, but approval is still part of the design
ChatGPT Work is intended for jobs that would be awkward in ordinary chat: researching a subject across connected sources, drafting a report, analyzing information, producing a spreadsheet or presentation, or building a lightweight site. It can break a task into steps, remain on a project for hours, and run Scheduled Tasks once, repeatedly, after a trigger, or while monitoring for changes.The background execution is real, but the phrase “runs when the laptop is closed” needs a boundary. OpenAI says Work running on the web or mobile is cloud-based and synchronizes across web, mobile, and desktop. Those cloud tasks can continue after a user walks away. Local desktop access is different: users must open a local folder or project and grant permission to the files required, while locally held files and outputs stay on that computer unless the user explicitly moves or shares them.
For an IT department, that creates two different review paths. A cloud task may draw on connected SaaS services and continue without a workstation remaining online. A desktop task that receives local access introduces endpoint file exposure and application-control questions. The same user-facing “Work” label therefore covers materially different data paths.
OpenAI also says users can inspect progress, answer questions, alter direction, and approve important actions. That is useful, but it is not the same as a centrally designed approval workflow. Organizations should test what qualifies as an “important action” for each connected app before allowing Work to interact with production systems, customer records, shared mailboxes, or repositories containing deployment credentials.
The practical point is straightforward: Work can automate the preparation and movement of information, but it does not transfer accountability for a false report, an erroneous update, or an unauthorized action. The person and organization that enabled the connection still own the result.
Codex is still separate, which is good news for development controls
The supplied description correctly identifies a deeper Codex integration in the desktop app, including parallel task management and GitHub-oriented workflows. It overstates the product unification. OpenAI’s support documentation explicitly says Codex remains a separate desktop view, with its own history and unchanged technical workflows, rather than becoming a tab inside every Work project.That is more than interface trivia. Development agents have different security consequences from document-generation agents. Codex can interact with local folders, repositories, terminals, developer tools, tests, and commands; Work is framed around research, analysis, deliverables, apps, files, and recurring work. A single generic policy for “ChatGPT” is unlikely to give security teams enough control over both.
Windows developers should also note that Work’s availability is broader than the web rollout. OpenAI says Work is available to all plans in the macOS and Windows desktop applications, while web and mobile access is limited to Plus, Pro, Business, Enterprise, and Edu. The July 9 release notes further said that Pro, Enterprise, and Edu users would receive web and mobile access first, with Plus and Business following.
Availability does not equal enabled access in a managed tenant. OpenAI’s Enterprise administration guidance calls out separate decisions around which members use Work and Codex, what roles get which permissions, which apps are available, and which model is the default. Enterprise and Edu also received a two-week preview period in which Work was off by default, with admins able to opt out before automatic enablement.
That is the control point administrators should use. Do not deploy the desktop application and infer that the feature’s business use is already approved. Separate policy groups for Work, Codex, connected apps, and public Sites will be easier to defend than an all-or-nothing decision after employees have already linked corporate sources.
Sites are hosted applications, not simply generated HTML
ChatGPT Sites is the part of the launch most likely to bypass normal application-development habits. OpenAI describes it as a public beta for creating, previewing, publishing, sharing, and managing interactive sites and lightweight web apps from Work on the web, or Work and Codex in the desktop client. Dashboards, trackers, reports, prototypes, and internal tools are obvious targets.The original account is right that this reduces the distance between an idea and a usable internal tool. But “without a development pipeline” should not be mistaken for “without an operational pipeline.” OpenAI documents limitations around frameworks, private networks, databases, background services, and hosting patterns. A generated Site may be appropriate for a departmental dashboard or prototype, while still being unsuitable for a business-critical application that needs established identity management, retention policies, monitoring, disaster recovery, accessibility checks, change control, and a support owner.
OpenAI also lists the categories of information a Site can involve: prompts, instructions, conversation context, uploaded or referenced files, code, generated artifacts, hosted URLs, access settings, storage, metadata, logs, and operational data used to host, secure, debug, or enforce policy. That is a significantly wider record than a static web page.
For Enterprise tenants, public publishing is off by default and must be enabled by an administrator before eligible members can publish publicly. Sites are also unavailable at launch in the European Economic Area, Switzerland, and the United Kingdom. Those details undermine the idea that the feature is an instant public-hosting service for every customer worldwide; OpenAI has deliberately placed deployment and geography limits around it.
The right rollout is to begin with private, low-risk content using approved sources, then determine whether exported or hosted applications meet the organization’s own requirements. Public publishing should remain a distinct exception process, not the default permission that comes with building an internal prototype.
PowerPoint integration has a real Microsoft 365 deployment story
ChatGPT for PowerPoint is generally available and lives in a sidebar inside Microsoft PowerPoint. It can generate a draft from source material, revise an existing deck, explain the story and structure, and use reusable Skills, templates, connected apps, and approved data sources where those are enabled.For Windows and Microsoft 365 administrators, this is not merely a ChatGPT feature; it is an Office add-in deployment. OpenAI’s installation documentation instructs users to install it through PowerPoint’s Add-ins interface and Microsoft Marketplace. Organizations that block store-based add-ins can deploy it through the Microsoft 365 admin center using a manifest, assign it to selected users or groups, and may need to enable it under role-based access controls.
The product comes with explicit limitations. OpenAI warns that advanced edits involving charts, shapes, formatting, and slide management may be limited or still under development, and that generated or edited slides may not perfectly follow a preferred template. It also tells users to review claims, numbers, citations where available, and changes before sharing, and to duplicate important files first so they can revert.
That warning should be treated as an operating requirement, especially where decks become management reporting or customer material. An editable PowerPoint output can create a dangerous sense that the underlying claims have been checked. It has not. The PowerPoint surface makes the last mile of production easier; it does not validate the data, verify financial calculations, or assure that an imported source was current.
Token pricing turns agent use into a budgeted service
OpenAI moved Workspace Agent runs to token-based pricing on July 6. Its rate card says that Work, Excel/Sheets, and eventually PowerPoint consume credits based on input tokens, cached input tokens, and output tokens, so there is no fixed cost per task. Complexity, prompt size, cache use, and output length all change the charge.ChatGPT for PowerPoint remains free for Business and Enterprise customers through August 6, 2026. After that date, PowerPoint use joins the same flexible, token-based billing model. OpenAI’s Business release notes say the usage draws from the general Codex agentic usage pool after included usage.
This is the launch’s most immediate operational consequence. Seat-based purchasing made it relatively simple to predict a monthly cost for an AI assistant. A shared agent that processes a large folder, performs repeated scheduled monitoring, produces long documents, and revises multiple decks turns AI consumption into a variable workload expense. The economics will be closer to cloud consumption than to an ordinary office-suite license.
OpenAI’s GPT-5.6 model family adds another cost-and-performance choice. Free and Go users receive GPT-5.6 Terra in Work and Codex, while Plus, Pro, Business, and Enterprise customers can choose Sol, Terra, or Luna and set effort per task. Pro and Enterprise users receive Work’s Ultra mode. Administrators should avoid assuming that “stronger model” or “higher effort” is free simply because a user already has a paid seat.
The immediate task for Windows and Microsoft 365 administrators is to inventory who can enable Work, Codex, Sites, and the PowerPoint add-in; restrict connected apps to approved sources; decide whether public Site publishing is ever permitted; and set cost monitoring before the August 6 PowerPoint billing change. ChatGPT Work gives employees more ways to complete work without switching tools. It also gives IT more distinct execution surfaces to govern.
References
- Primary source: secnews.gr
Published: 2026-08-02T16:00:00+00:00
OpenAI ChatGPT Work: New Enterprise AI Agent - SecNews.gr
OpenAI ChatGPT Work brings AI agents running enterprise workflows to the cloud, with Codex built-in and Hosted Sites functionality.www.secnews.gr - Related coverage: help.openai.com
ChatGPT Work and Codex | OpenAI Help Center
Use Chat or Work in ChatGPT, or switch to Codex for software development.
help.openai.com
- Related coverage: help.openai.com
ChatGPT — Release Notes | OpenAI Help Center
A changelog of the latest updates and release notes for ChatGPT
help.openai.com
- Related coverage: openai.com
ChatGPT is now a partner for your most ambitious work | OpenAI
ChatGPT Work is an agent that can take action across your apps and files, stay with a project for hours if needed, and turn a goal into finished work.openai.com - Related coverage: openai.com
How to use ChatGPT Work for everyday tasks | OpenAI
Explore practical ChatGPT Work use cases to automate tasks, create deliverables, and turn real inputs into outputs across tools, files, and workflows.openai.com
- Related coverage: techtimes.com
ChatGPT for PowerPoint Goes GA: Enterprise Teams Have Until August 6 to Audit Costs
ChatGPT for PowerPoint went generally available for Business workspaces on July 6, 2026, with a free window closing August 6. Enterprise token billing mirrors Workspace Agents: output tokens cost sixwww.techtimes.com - Related coverage: deploymentsafety.openai.com
- Related coverage: techradar.com
OpenAI’s next ChatGPT-5.6 upgrade may be too powerful to launch like a normal app update | TechRadar
There’s going to be a staggered rollout, starting Thursdaywww.techradar.com - Related coverage: edunewsletter.openai.com
Introducing ChatGPT Work. A More Capable ChatGPT for Education
Introducing ChatGPT Work, a new way for faculty and staff to carry out longer, multi-step work across approved files, connected apps, and the web.edunewsletter.openai.com - Related coverage: cdn.openai.com
- Related coverage: cdn.openai.com
- Related coverage: techradar.com
OpenAI unveils ChatGPT Work, an AI tool capable of handling workloads across finance, data analytics, engineering, and more | TechRadar
ChatGPT Work is a new agentic interface within ChatGPTwww.techradar.com - Related coverage: axios.com
Exclusive: OpenAI wants to be a scientific research partner
AI is increasingly being used as a research collaborator for mathematicians and scientists.www.axios.com
- Related coverage: theatlantic.com
OpenAI Is Opening the Door to Government Spying - The Atlantic
Whether it means to or notwww.theatlantic.com
- Related coverage: windowscentral.com
Microsoft AI chief confirms plan to ditch OpenAI | Windows Central
Google Deepmind co-founder and Microsoft AI lead Mustafa Suleyman suggests that the big tech firm is moving away from OpenAI reliance, as the latter's financials look increasingly dire.www.windowscentral.com - Related coverage: axios.com
OpenAI execs' memos reject the claims in Elon Musk's new lawsuit
OpenAI says it is independent, committed to tis mission, and hasn't achieved AGI.www.axios.com
- Related coverage: help-lb.openai.com
Creating and editing documents, spreadsheets, and presentations with ChatGPT Work | OpenAI Help Center
Create editable files from instructions, source material, or an existing template.
help-lb.openai.com