Before you begin

No previous experience required unless you choose a coding exercise. Use an account you are allowed to access; features vary by product and region.

What you will learn

  • Explain what computer use adds to an AI agent.
  • Distinguish an origin approval from a goal approval.
  • Keep authentication separate from ordinary model messages.
  • Verify outcomes instead of trusting an accepted action.

What OpenAI added

OpenAI's API changelog says computer use was added to the Agents API on September 29, 2026. The documentation describes an OpenAI-hosted browser session in which an agent can view pages and interact with them. This is developer infrastructure, not a switch that gives every ChatGPT conversation control of your computer.

The documented flow is: create a browser session, send a task, handle requests to visit new website origins, handle sign-in separately when required, verify the result, review saved activity and delete the session. This article explains that flow on paper; it does not create a browser session or test an agent.

Approve a destination, not unlimited permission

An origin is the scheme, host and port that identify a website destination, such as https://example.edu. When an agent wants to navigate to a new origin, the application can ask a human to approve, deny or cancel. That prompt should show the exact destination. Approving one origin is not approval for every site or every possible action.

The task goal and the navigation decision are different layers. 'Find the scholarship deadline' describes the desired outcome. 'Allow navigation to https://university.example' is a specific permission. A safe interface keeps those separate so the user can reject a suspicious redirect even when the overall goal sounds reasonable.

OpenAI's guide notes that a 202 response means the approval decision was accepted by the service; it does not prove that navigation succeeded. You must still inspect the next state and verify the final answer. Accepted instruction, completed action and correct result are three different claims.

Treat sign-in as a separate security event

The documentation describes a dedicated sign-in approval. It says credentials are omitted from model input and session history during the authentication flow. That boundary matters: passwords, one-time codes and recovery information should not be typed into ordinary chat messages or ordinary tool calls.

Applications still need careful handling. Email addresses and other account details can be sensitive. Mask them in displays, keep them out of logs and analytics, and avoid saving them in general activity views. Give only authorized users access to a session.

A screenshot may reveal names, messages, addresses or account information even when credentials themselves are protected. Treat screenshots as sensitive records. Do not copy them into public bug reports or broad analytics, and remove a session when the work is complete according to your retention rules.

Practise with a four-decision scenario

Imagine an agent researching a public scholarship. It first requests the official university origin. Approve only after checking the spelling and secure connection. It then redirects to a look-alike domain with an extra letter. Deny that request. The public deadline should not require an unknown destination.

Next, the site asks for sign-in. If the task is only to read public information, cancel rather than expanding access. If sign-in is genuinely required in a future authorized workflow, use the dedicated authentication step, not a normal prompt. Finally, if the agent reaches an application submission or payment button, stop: research did not include submitting or purchasing.

Verify the result against the official page. Record the exact source URL and deadline text, then check whether the agent answered the assigned question without performing extra actions. A completed click sequence is not evidence that the extracted fact is correct.

Terms and next step

AI agent: software that uses a model and tools to carry out multiple steps. Computer use: a tool that lets an agent interpret and interact with an interface. Origin: a website's scheme, host and port. Authentication: proving account identity. Least privilege: granting only the access needed for the task. Audit trail: a record of actions and decisions.

Next, read 'AI Reasoning, Tools, Agents, and Automation' for the larger system model, then 'How to Verify AI Answers and Detect Mistakes' before trying any browser automation.

Try this prompt

This is a suggested exercise, not a tested guarantee of any model’s output.

You are reviewing a proposed browser-agent action on paper. Goal: find the public scholarship deadline on the official university website. For each event, answer approve, deny, cancel or stop, and explain why: (1) visit the correctly spelled HTTPS university origin; (2) follow a redirect to a look-alike domain with one extra letter; (3) sign in even though the deadline is public; (4) submit an application. Keep origin permission, authentication and task scope separate. Do not browse or enter credentials.

Mini project & challenge

  1. Draw three columns labeled goal, requested permission and evidence after the action.
  2. Review the four scenario events and write approve, deny, cancel or stop for each.
  3. Underline the exact website origin rather than relying on a familiar-looking page title.
  4. List information a screenshot could reveal and mark which items must stay out of logs.
  5. Write a final verification checklist: source URL, quoted deadline, no submission and no unexpected origin.
  6. Challenge: design an additional approval point for downloading a file and explain how you would verify its type and source before opening it.

Common mistakes

  • Treating a safe-sounding goal as permission for every action: approve exact steps and destinations.
  • Putting passwords or one-time codes into normal prompts: use a dedicated authentication flow.
  • Assuming an accepted approval means the page loaded successfully: inspect the next state.
  • Ignoring screenshots and logs: they may contain sensitive account or personal information.

Check your understanding

  1. When did OpenAI add computer use to the Agents API changelog?
  2. Does this feature automatically give every ChatGPT conversation computer control?
  3. What is a website origin?
  4. What three choices can an origin approval request present?
  5. Does a 202 response prove navigation succeeded?
  6. Where should credentials not be entered?
  7. Why can screenshots be sensitive?
  8. What should happen at a look-alike domain in the exercise?
  9. Why stop at an application submission button?
  10. What should be verified after the agent finishes?
Show answers
  1. September 29, 2026.
  2. No; the documented feature is developer infrastructure in the Agents API.
  3. The scheme, host and port that identify a destination.
  4. Approve, deny or cancel.
  5. No; it only indicates that the approval decision was accepted.
  6. Ordinary model messages or ordinary tool calls.
  7. They may reveal names, messages, addresses or account information.
  8. Deny the navigation request.
  9. The authorized task was research, not submission.
  10. The official source, extracted fact, completed scope and absence of unauthorized actions.

In short

Computer-using agents need boundaries at every layer. Approve exact origins, keep sign-in separate, protect screenshots and logs, stop when the task expands and verify the final result against the official source.

Continue the Understand AI course →

Sources & review notes

  1. OpenAI API changelog

    Computer-use addition dated September 29, 2026; checked October 1.

  2. OpenAI Agents API computer use guide

    Workflow, origin approvals, sign-in handling and data-sensitivity guidance checked October 1. This lesson is a paper exercise and does not claim a hands-on product test.

Product information was checked on 2026-10-01. This is a selected beginner guide, not an exhaustive archive of every announcement. Recheck access, pricing and compatibility before relying on a current product detail. Supplied screenshots remain unreplicated claims.