To use ChatGPT agents, open a chat on a paid plan, select agent mode from the tools menu (or type /agent), and describe a task with a clear finish line — the agent then works in its own virtual computer, browsing sites, filling spreadsheets, and building files while you watch or step away. That one sentence is the whole trick; the rest of this guide is making it work well.
Short answer: Turn on agent mode from the tools dropdown in any chat (paid plans), then give it one complete task with a deliverable: "Research these 5 competitors and build a comparison spreadsheet." The agent browses, clicks, and creates files on its own, asking permission before anything consequential. Start with low-stakes tasks — your monthly agent messages are limited.

I use ChatGPT's agent for real work most weeks — research roundups, price checks across a dozen sites, first-draft spreadsheets — and the difference between people who get value from it and people who give up is almost never the tool. It is how the task is framed. Here is the honest, current guide: how to switch it on, what to hand it, what to keep for yourself, and the limits nobody mentions until you hit them.
What ChatGPT agents actually are
A ChatGPT agent is not a smarter chat reply. When you run agent mode, ChatGPT gets its own virtual computer with a browser: it can visit websites, click buttons, fill forms, download and create files, run code, and chain those steps together for many minutes without you steering. OpenAI launched this as "ChatGPT agent" in July 2025, merging its earlier browsing (Operator) and deep-research tools into one mode, per OpenAI’s announcement.
Two things separate it from normal ChatGPT. First, it acts — it does not just tell you how to do something, it goes and does it. Second, it checks in: before anything consequential (submitting a form, making a purchase, sending anything), it stops and asks you to confirm, and you can watch its screen or take over the browser at any point.
How to turn on agent mode
- Open ChatGPT on a paid plan (Plus, Pro, Team, or a business plan) — agent mode is not on the free tier. If you are on free, my guide to what the free plan can still do covers your options.
- Start a new chat and open the tools menu (the sliders/plus icon in the composer).
- Choose Agent mode — or just type
/agentin the message box. - Describe the task and the deliverable, then send. A small window shows the agent's virtual screen as it works.
- Stay reachable: the agent pauses to ask permission before consequential steps, and you can click take over to do a step yourself (like a login) without handing it your password in chat.
That is genuinely all the setup there is. The skill is in step 4.
The task framing that actually works
In my testing, the same request phrased two ways produces a night-and-day difference. Agents fail on vague missions and shine on scoped deliverables.
Weak: "Help me research AI writing tools." Strong: "Visit the pricing pages of Jasper, Copy.ai, and Writesonic. Build a spreadsheet with columns for plan name, monthly price, annual price, free trial, and word/credit limits. Flag anything unclear instead of guessing."
The strong version works because it has the three parts every agent task needs:
| Part | What it looks like | Why it matters |
|---|---|---|
| Scope | "these 3 sites", "top 10 results" | stops endless wandering |
| Deliverable | "a spreadsheet with these columns" | gives it a finish line |
| Rules | "flag, don't guess", "ask before submitting" | prevents confident nonsense |
What to hand an agent (and what to keep)
Agents earn their time on tasks that are boring, structured, and web-based: comparing prices across many sites, turning research into a spreadsheet or slide deck, monitoring product pages, compiling contact lists from public pages, or preparing a report from several sources. On a coding project, the same idea applies inside your editor — that is a different tool category, covered in my ChatGPT alternatives for coding guide.
Keep for yourself: anything involving payments beyond trivial amounts, logins to sensitive accounts, judgment calls with real consequences, and final fact-checking. The agent is a capable intern, not a signatory. OpenAI itself blocks or gates the riskiest actions, and you should treat every number an agent brings back the way you treat any web research — verify before you rely on it. That habit matters double here because an agent's mistake looks polished: it arrives formatted in a tidy spreadsheet.
The limits nobody tells you about
- Monthly message caps. Agent tasks are metered separately and the caps are real (at launch: 400 agent messages/month on Pro, 40 on Plus — confirm current numbers on the pricing page). One sprawling task can burn several messages of back-and-forth, so scope tightly.
- Speed. An agent task takes minutes, not seconds. Fifteen minutes for a solid competitive-research spreadsheet is normal — still faster than the hour it would take you.
- Logged-in sites. The agent handles public pages well; paywalled or logged-in content needs you to take over the browser for the login step, or a connector where available.
- CAPTCHAs and bot walls. Some sites block automated browsing entirely. A good agent run notes what it could not reach instead of pretending — and the well-framed prompt ("flag, don't guess") makes that more likely.
- It inherits your plan's model quality. Garbage in the task framing still means garbage out, no matter how patient the agent is.
Five copy-paste starter tasks
- "Compare the current pricing of [3–5 tools in your niche]. Build a spreadsheet: plan, monthly price, annual price, free tier yes/no, one standout limitation each. Cite the URL for every row."
- "Find the 10 most recent reviews of [product] across the web, extract the 3 most repeated complaints and 3 most repeated compliments, and give me a one-page summary."
- "Plan a 3-day work trip to [city] under $[budget]: shortlist 3 hotels near [area] with prices, and build an hour-by-hour itinerary in a document."
- "Go through [public dataset/report URL] and turn the key figures into a 5-slide deck with one chart per slide."
- "Check these 6 product pages weekly-style: list current price, stock status, and any promo, in a table I can paste into Sheets."
Writers get a special note: agents are great at gathering material, but for the drafting itself a dedicated writing tool usually beats agent mode — my ranked best AI writing tools guide covers those, and the Jasper review covers the strongest brand-voice option. Teachers, the same logic: the classroom suites in my best AI tools for teachers guide solve school tasks more directly than a general agent.
Safety settings worth two minutes
Give the agent its own boundaries the way you would a new assistant. Confirm every consequential action rather than pre-approving categories. Use take over mode for logins instead of typing credentials into the chat. Do not connect data sources (email, drive) until a few low-stakes tasks have earned your trust. And end tasks with "list anything you were unsure about" — in my testing that one line surfaces the exact rows I need to double-check, which is where agent work goes from impressive demo to dependable output.
My verdict on agent mode in 2026
ChatGPT agents are past the demo phase: for scoped research-and-compile tasks they reliably return an hour of work for fifteen minutes of waiting. They are still the wrong tool for judgment calls, sensitive accounts, and final drafts. Learn the task-framing pattern — scope, deliverable, rules — spend your first five agent messages on low-stakes tasks, and you will know exactly where it fits in your week. That is how to use ChatGPT agents without wasting a single message of the monthly cap.
Frequently Asked Questions
How do I turn on ChatGPT agent mode?
Open a chat on a paid plan, click the tools menu in the composer, and pick Agent mode — or type /agent. Describe the task with a clear deliverable and send. The agent works in a visible virtual browser and asks permission before consequential steps.
Can free users use ChatGPT agents?
No — agent mode requires a paid plan (Plus and up), and agent messages have their own monthly caps. Free users still get a capable chat model; see our guide to using ChatGPT for free for what the no-cost tier includes.
What can a ChatGPT agent actually do?
It browses websites, clicks and fills forms, downloads and creates files (spreadsheets, documents, slides), runs code, and chains those steps for many minutes on its own. It cannot get past logins without your help, struggles with bot-blocked sites, and pauses for your confirmation before consequential actions.
Are ChatGPT agents safe to use?
Reasonably, if you keep the guardrails: confirm each consequential action, use take-over mode for logins instead of sharing credentials, avoid payment tasks, and verify important numbers it brings back. Treat it like a capable intern whose work you spot-check.