ChatGPT Atlas
OpenAI · chatgpt.com/atlas
Atlas combined a locally installed, proprietary Chromium-based browser with ChatGPT's hosted model, memory and agent services. The agent could not be exported or run independently. OpenAI's shutdown of the product on August 9, 2026 shows that the owner's access depended entirely on the provider. It offered notable controls, including optional browser memories, per-site visibility, a logged-out agent mode and training on browsing off by default, but these operated inside OpenAI's platform.
- Browser memories were optional and could be viewed, archived and deleted
- Training on web browsing content was off by default
- Per-site control over ChatGPT page visibility and a logged-out agent mode
- Agent mode could not access the file system or saved passwords, and paused on sensitive sites
- Owners could stop the agent at any time
- The product was discontinued by the provider, and the app stopped working on August 9, 2026
- No export of the agent itself; only bookmarks and pages could be saved
- Proprietary runtime; agent logic and model are hosted by OpenAI
- Only OpenAI models; agent mode was gated to paid tiers at launch
- No owner-verifiable audit log; actions not verifiably attributable to the agent
All 34 findings
Final macOS release state before OpenAI discontinued Atlas on August 9, 2026 (launched October 21, 2025). Its browser-agent features moved into the ChatGPT desktop app, a Chrome extension and Codex. Operator was folded into ChatGPT agent in 2025, not into Atlas. Assessed from public documentation only.
Portable · Can you leave, and take the whole agent with you?
0%- P1Round-trip portability
Incomplete, delayed and not restorable: before the August 2026 shutdown only bookmarks, pages and ChatGPT chats (via the emailed export) could be saved, and no import restored the Atlas agent, its browser memories or configuration.
Fail - P2Complete export
No export captured browser memories, agent configuration or agent logic; only bookmarks, pages and ChatGPT chat history could be saved, so most of what defined the agent stayed with OpenAI.
Fail - P3Independent execution
Atlas was proprietary software built on Chromium, and its assistant and agent features required OpenAI's servers; no open-source runtime can execute the agent.
Fail - P4Identity continuity
The agent's identity was the OpenAI account, and nothing let sites or other parties verify its continuity outside OpenAI.
Fail - P5No kill switch
OpenAI discontinued Atlas, and it stopped working on August 9, 2026, about 30 days after the announcement. This shows the provider could unilaterally end the agent's operation.
Fail - P6Capability independence
The sidebar assistant, browser memories and agent mode all ran on OpenAI's hosted models and services, and none of them worked with another model provider.
Fail
Transparent · Can you see everything the agent is, with ordinary tools?
8%- T1Open storage format
OpenAI did not document Atlas's local storage format. Chromium conventionally uses SQLite, but whether Atlas state (including browser memories held server-side) was readable without OpenAI software was not verified.
Unverified - T2No hidden instructions
The assistant and agent ran on ChatGPT with system-level instructions that were not visible to the user.
Fail - T3No shadow memory
Browser-memory processing and ChatGPT conversations were handled on OpenAI servers under ChatGPT's retention policies. OpenAI stated that page summaries were deleted within about seven days, but provider-side logs were not fully inspectable by the owner.
Fail - T4Complete action history
Agent-mode sessions appeared in the ChatGPT conversation and browsing history stayed in the browser, but no complete record of agent actions and tool calls was documented as available to the owner or exportable.
Partial - T5Readable logic
Atlas had no owner-authored skills or workflows stored as readable source, and its agent logic was closed source.
Fail - T6No third-party influence channel
Public documentation did not state whether ChatGPT ads appeared in the Atlas sidebar or agent flows. Third-party web content entered the agent's context, and OpenAI acknowledged prompt-injection risk.
Unverified
Auditable · Can you reconstruct exactly what the agent did?
0%- A1No unrecorded actions
OpenAI did not document whether every consequential agent action was durably recorded, or whether an action was blocked when it could not be recorded.
Unverified - A2Tamper evidence
Browsing history and chats, the owner-visible record, could be deleted without a detectable trace, and no tamper-evident record of agent actions was documented.
Fail - A3Separation from the audited
OpenAI did not document whether the agent could alter or delete records of its own actions.
Unverified - A4Readable with ordinary tools
It is not documented whether agent-mode action records were readable with general-purpose tools beyond the chat transcripts included in the ChatGPT export.
Unverified - A5Corroborated interactions
No documented record let Atlas's agent and other agents or services match their logs of an exchange.
Fail
Verifiable · Can you prove the agent runs what it claims?
0%- V1Open, reproducible runtime
Atlas was proprietary software built on the open-source Chromium project; its own code was not released under an OSI-approved license.
Fail - V2Active config is inspectable config
The agent's active configuration included server-side instructions and model settings that the owner could not inspect.
Fail - V3Attributable messages
The agent acted through the owner's browser sessions, and recipients had no way to verify that an action came from this agent under the owner's authority.
Fail - V4Independently checkable record
No action record was offered whose integrity could be checked with open tools that do not depend on OpenAI.
Fail - V5Comparable state
Agent state was split between the local browser and OpenAI servers and was not fully exposed, so the owner could not verify whether it had changed between two points in time.
Fail
Modifiable · Can you change anything, without asking?
25%- M1Instructions
ChatGPT custom instructions applied to the Atlas sidebar and agent, but the system-level instructions could not be read or rewritten.
Partial - M2Memory
Browser memories were optional and could be viewed, archived or deleted, and deleting browsing history deleted the associated browser memories. Direct editing of individual memory items was not documented.
Partial - M3Logic
Owners could not change the agent's executable logic, and Atlas offered no user-defined skills or workflows.
Fail - M4Tools and permissions
Owners could control per-site ChatGPT page visibility and choose logged-in or logged-out agent mode. By design, the agent could not access the file system, saved passwords or autofill, and owners could not add their own tools to the agent.
Partial - M5Model choice
Only OpenAI models were available, and local or third-party models could not be used.
Fail - M6No gatekeeping
Agent mode was limited to Plus, Pro and Business plans at launch, so a core capability depended on a paid tier.
Fail
Controllable · Is your word final?
58%- C1Communication boundaries
Owners could block ChatGPT from specific sites and run the agent logged out, which limited its reach, but could not define which recipients, peers or channels it could contact, and enforcement below the model was not documented.
Partial - C2Approval gates
Agent mode paused for user oversight on sensitive sites such as financial institutions and asked for confirmation before consequential actions. Owners could not configure which actions required approval.
Partial - C3Immediate halt
Owners could stop agent mode at any time from the browser interface.
Pass - C4Data sovereignty
Using browsing content for training was off by default ('Include web browsing' opt-in). Page content shared with ChatGPT and all chats were still processed on OpenAI servers, and chats followed ChatGPT's default-on training setting.
Partial - C5Credential custody
Site sessions used by logged-in agent mode lived in the local browser profile, and the agent could not access saved passwords. The OpenAI account and any ChatGPT connectors remained under provider custody, and credentials did not travel with an agent.
Partial - C6Full deletion
Owners could delete browsing history, which removed associated browser memories, and could delete their ChatGPT account under the 30-day deletion policy. OpenAI's public notice did not specify how server-side Atlas data was handled after discontinuation.
Partial
Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.