Skip to content
Agents for Humanity
Public draft. All results are preliminary desk assessments against criteria v1.0, updated 27 Sept 2026. No agent has been certified yet. How we assess
Autonomous agenthybridProprietaryDiscontinued

ChatGPT Atlas

OpenAI · chatgpt.com/atlas

Atlas combined a locally installed, proprietary Chromium-based browser with ChatGPT's hosted model, memory and agent services. The agent could not be exported or run independently. OpenAI's shutdown of the product on August 9, 2026 shows that the owner's access depended entirely on the provider. It offered notable controls, including optional browser memories, per-site visibility, a logged-out agent mode and training on browsing off by default, but these operated inside OpenAI's platform.

Strengths
  • Browser memories were optional and could be viewed, archived and deleted
  • Training on web browsing content was off by default
  • Per-site control over ChatGPT page visibility and a logged-out agent mode
  • Agent mode could not access the file system or saved passwords, and paused on sensitive sites
  • Owners could stop the agent at any time
Gaps
  • The product was discontinued by the provider, and the app stopped working on August 9, 2026
  • No export of the agent itself; only bookmarks and pages could be saved
  • Proprietary runtime; agent logic and model are hosted by OpenAI
  • Only OpenAI models; agent mode was gated to paid tiers at launch
  • No owner-verifiable audit log; actions not verifiably attributable to the agent
Evidence

All 34 findings

Final macOS release state before OpenAI discontinued Atlas on August 9, 2026 (launched October 21, 2025). Its browser-agent features moved into the ChatGPT desktop app, a Chrome extension and Codex. Operator was folded into ChatGPT agent in 2025, not into Atlas. Assessed from public documentation only.

Portable · Can you leave, and take the whole agent with you?

0%

Transparent · Can you see everything the agent is, with ordinary tools?

8%
  • T1
    Open storage format

    OpenAI did not document Atlas's local storage format. Chromium conventionally uses SQLite, but whether Atlas state (including browser memories held server-side) was readable without OpenAI software was not verified.

    Unverified
  • T2
    No hidden instructions

    The assistant and agent ran on ChatGPT with system-level instructions that were not visible to the user.

    Fail
  • T3
    No shadow memory

    Browser-memory processing and ChatGPT conversations were handled on OpenAI servers under ChatGPT's retention policies. OpenAI stated that page summaries were deleted within about seven days, but provider-side logs were not fully inspectable by the owner.

    Fail
  • T4
    Complete action history

    Agent-mode sessions appeared in the ChatGPT conversation and browsing history stayed in the browser, but no complete record of agent actions and tool calls was documented as available to the owner or exportable.

    Partial
  • T5
    Readable logic

    Atlas had no owner-authored skills or workflows stored as readable source, and its agent logic was closed source.

    Fail
  • T6
    No third-party influence channel

    Public documentation did not state whether ChatGPT ads appeared in the Atlas sidebar or agent flows. Third-party web content entered the agent's context, and OpenAI acknowledged prompt-injection risk.

    Unverified

Auditable · Can you reconstruct exactly what the agent did?

0%

Verifiable · Can you prove the agent runs what it claims?

0%
  • V1
    Open, reproducible runtime

    Atlas was proprietary software built on the open-source Chromium project; its own code was not released under an OSI-approved license.

    Fail
  • V2
    Active config is inspectable config

    The agent's active configuration included server-side instructions and model settings that the owner could not inspect.

    Fail
  • V3
    Attributable messages

    The agent acted through the owner's browser sessions, and recipients had no way to verify that an action came from this agent under the owner's authority.

    Fail
  • V4
    Independently checkable record

    No action record was offered whose integrity could be checked with open tools that do not depend on OpenAI.

    Fail
  • V5
    Comparable state

    Agent state was split between the local browser and OpenAI servers and was not fully exposed, so the owner could not verify whether it had changed between two points in time.

    Fail

Modifiable · Can you change anything, without asking?

25%

Controllable · Is your word final?

58%
Something wrong or out of date?

Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.

Dispute a finding