OpenAI Operator Now Available to All ChatGPT Plus Users Worldwide
OpenAI has completed its global rollout of Operator, its browser-use agent, to all ChatGPT Plus subscribers after a six-month phased launch. The release adds prompt injection safeguards and broader site compatibility.
Original sourceOpenAI's Operator — a browser-use agent that can navigate websites, fill forms, and complete multi-step tasks on a user's behalf — is now accessible to all ChatGPT Plus subscribers globally, completing a phased rollout that began in early 2026. The expansion follows a regional pilot that let OpenAI stress-test the system at scale before opening the floodgates to its full Plus subscriber base.
The global launch ships with two meaningful additions: hardened defenses against prompt injection attacks, a known attack vector where malicious content on a webpage attempts to hijack the agent's instructions, and improved compatibility across a wider range of websites. Both are table-stakes fixes that were conspicuously missing from the early access period and suggest OpenAI took the pilot feedback seriously.
Operator positions OpenAI squarely in the browser automation market alongside tools like Anthropic's computer use API and independent players such as Browserbase and Playwright-based agents. Unlike developer-facing automation tools, Operator is designed for end users who want to delegate repetitive web tasks — booking travel, submitting forms, purchasing items — without writing code or configuring workflows.
The inclusion in the Plus tier rather than a separate paid add-on is a notable distribution decision. With millions of Plus subscribers worldwide, OpenAI is betting that putting a capable browser agent in front of a mass audience will normalize agentic workflows faster than any enterprise-focused rollout could.
Panel Takes
The Skeptic
Reality Check
“The prompt injection fix is the only line item in this announcement I actually care about — shipping a browser agent without it was a liability, not a feature gap. What I want to know is the real-world task completion rate on complex, multi-step workflows after six months of iteration, because 'improved site compatibility' is the kind of phrase that means 'it still fails on anything with a dynamic front-end.' This tool wins if Operator quietly becomes the reason people stay on Plus; it dies if the failure rate is high enough that users stop delegating to it after two bad experiences.”
The Builder
Developer Perspective
“The prompt injection hardening is technically the most interesting part of this launch, but OpenAI hasn't published anything about the implementation — no threat model, no methodology, just 'improved safeguards,' which is marketing copy with a security hat on. The fact that Operator is a closed system with no composable API surface means I can't build on top of it or integrate it into an existing workflow; I'm stuck with whatever UI shell they've wrapped around it. If they opened a task-delegation API with structured outputs, this would actually be interesting to builders — right now it's a consumer product dressed up as infrastructure.”
The Futurist
Big Picture
“The real bet here isn't browser automation — it's that OpenAI wants to become the default delegation layer between humans and the web, and putting Operator in front of every Plus subscriber is the fastest way to accumulate the behavioral data needed to make that bet pay off. The dependency to watch is whether websites begin actively blocking or accommodating AI agents: if major platforms like airlines or retailers implement agent-friendly APIs, Operator wins; if they implement bot detection arms races, the whole category stalls. Six months of phased rollout to a global launch is exactly the timeline you'd expect from a team trying to normalize agent behavior before the web figures out how to push back.”
The Founder
Business & Market
“Bundling Operator into Plus instead of pricing it as a separate SKU is the right call for retention but a missed opportunity for value-based pricing — users who successfully delegate 10 hours of browser tasks a month are getting an absurd deal at $20, and OpenAI is leaving real money on the table. The moat question is uncomfortable: browser automation is not proprietary, and every dollar OpenAI spends hardening Operator against prompt injection is a dollar Anthropic, Google, and a dozen well-funded startups are also spending. The only defensible position here is distribution scale, and they're playing that card correctly by going mass-market first.”