How to Use ChatGPT Atlas After Its 2026 Shutdown

Sami Ullah Khan

August 16, 2026

How to Use ChatGPT Atlas

Executive Summary

🛑 Shutdown: Atlas stopped being a supported browser on 9 August 2026, so the practical 2026 answer is to migrate its workflow rather than keep relying on the retired app.
🧠 Replacement: OpenAI moved the core idea into ChatGPT and Codex, including a desktop built-in browser with multiple tabs, downloads, richer sign-in support, annotations, and separate browser state.
🔄 Migration: Migration has three separate layers: bookmarks and browsing data, signed-in browser state, and ChatGPT conversation history. Treating them as one data transfer is the easiest way to lose context.
💰 Pricing: Current ChatGPT pricing ranges from Free to $8 Go, $20 Plus, $100 or $200 Pro, $20 to $25 per-user Business pricing, and custom Enterprise contracts, while exact model allowances can still vary.
🛡️ Security: Prompt injection remains the hardest technical risk for browser agents. A 2026 Black Hat investigation reported around 20 flaws across leading AI browsing products, including bypasses demonstrated against Atlas.
🎯 Decision: The safest replacement is task-dependent: use ChatGPT’s built-in browser for isolated in-app work, Chrome integration when existing browser state is genuinely needed, and cloud browsing only for supported public-site delegation.

If you are searching for how to use ChatGPT Atlas today, the most important fact is also the most inconvenient one: Atlas is no longer a supported browser, because OpenAI scheduled it to stop working on 9 August 2026, just two days before this guide was prepared. I would not tell a reader to reinstall an abandoned browser, move sensitive work back into it, or assume old screenshots still describe the current product. The useful question is now broader: how did Atlas work, what parts of that workflow survived, and how can you reproduce the useful parts safely inside ChatGPT and Codex? That shift matters because Atlas was never merely Chrome with a chatbot bolted on. It combined a normal Chromium-style browsing surface with an Ask ChatGPT sidebar, browser memories, page-aware writing help, and an agent mode that could navigate, click, and continue multi-step tasks. OpenAI’s July deprecation guidance says those browser-based agentic capabilities are being moved into ChatGPT and Codex, while the new desktop browser experience adds multiple tabs, downloads, improved navigation, account login support, and other browser features where available. In practical terms, the Atlas idea survived even though the Atlas product did not. This guide reconstructs the original workflow for readers maintaining documentation or old processes, then maps every important Atlas behaviour to the supported 2026 replacement. It also covers migration, current plan pricing, browser-state choices, privacy controls, prompt injection, enterprise limitations, developer integrations, and competitor trade-offs. The goal is not nostalgia for an AI browser that lasted less than a year. It is a clean operating model for deciding when ChatGPT should read the web, when it should act on the web, and when you should keep the final click in human hands.

Can You Still Use ChatGPT Atlas in 2026?

The supported answer is no. OpenAI’s Help Centre states that Atlas was scheduled to stop working on 9 August 2026 and warned that, after that date, it may no longer open, browse, or support browser-based agentic workflows. The company also said a discontinued browser should not be treated as a safe long-term environment because browser software depends on continuing security maintenance. That makes any residual installation on a Mac a historical artefact, not a platform I would recommend for live work.

The distinction between “installed” and “supported” matters. A local application can sometimes launch after a retirement date, but that does not mean its authentication, agent services, updates, security patches, or cloud dependencies are still reliable. For teams with old Atlas instructions in onboarding documents, the correct action is therefore to replace those instructions, not add a footnote saying the browser might still open.

OpenAI’s wind-down guidance separated the transition into data that could be exported and data that would not move automatically. Bookmarks could be exported as an HTML file and imported into another browser such as Chrome. Open tabs and browser history required manual saving. Cookies had export options where available, but signed-in sessions remained sensitive and did not have a universal import path. ChatGPT conversation history, by contrast, was separate from Atlas browser data and remained tied to the ChatGPT account.

That is why the site’s own Atlas shutdown analysis is useful context for anyone updating an old workflow. Atlas did not simply disappear and leave a blank space. Its retirement was part of a product consolidation that OpenAI had been signalling for months.

The practical rule is simple: preserve any data you still have, move browsing to a maintained browser surface, and recreate agentic steps in current ChatGPT rather than trying to keep Atlas alive.

What ChatGPT Atlas Actually Did

Atlas launched on 21 October 2025 as a macOS browser with ChatGPT built directly into the browsing experience. Its appeal came from collapsing three layers that were normally separate: the page you were reading, the conversation about that page, and an agent that could take actions inside the same browser session. That combination made it feel different from opening a normal browser tab and copying text into a chatbot.

The standard browsing layer included tabs, bookmarks, downloads, address-bar search, configurable search engines, saved passwords, form handling, profiles, and familiar Chromium-style navigation. On top of that sat Ask ChatGPT, a sidebar that could explain a page, extract details, compare information, summarise content, or draft text without forcing the user to leave the current page. Inline writing assistance could also help with text entered into forms.

Agent mode was the operational layer. Once selected, ChatGPT could navigate, click, and carry a multi-step web task forward in the current browsing session. OpenAI allowed custom instructions for preferred sources, required steps, and approval checkpoints, which was an important detail for repeatable professional workflows. Agent mode also had deliberate boundaries: it could not run code in the browser, install extensions, access other desktop applications, or reach the local file system. On certain sensitive sites it paused so the user could watch or take over.

Browser memories added a fourth layer, continuity. If enabled, Atlas could retain useful facts and insights derived from browsing, with separate controls from normal ChatGPT memory. OpenAI said it did not store complete page copies as browser memories and applied filters intended to block sensitive information.

Atlas CapabilityWhat It DidImportant Constraint2026 Replacement
Ask ChatGPT SidebarExplained, summarised, extracted, and drafted beside a pagePage visibility and account context matteredChatGPT desktop browser or supported Chrome sidebar
Agent ModeNavigated and clicked through multi-step browser tasksNeeded supervision and confirmation for consequential actionsChatGPT Work, Codex browser tools, or cloud browser where supported
Browser MemoriesRemembered useful browsing-derived factsSeparate from ChatGPT Memory and user-controlledCurrent ChatGPT memory plus task-specific browser state
Inline WritingDrafted or revised text in web fieldsStill required human review before submissionChatGPT writing tools and browser annotations
Native Browser StateHeld cookies, logins, tabs, history, downloads, and passwordsCreated a larger security and migration surfaceBuilt-in browser state or an existing Chrome profile, chosen intentionally

For a pre-shutdown comparison of those behaviours against another AI-native browser, our Atlas versus Perplexity Comet guide captures the original product split: Atlas leaned towards action, while Comet leaned towards research context.

How to Use ChatGPT Atlas: The Original Workflow

This section is archival. It explains the workflow Atlas users followed before 9 August 2026, which is useful for migrating old playbooks and understanding screenshots in earlier documentation. It is not a recommendation to install or continue using a retired browser.

Set Up the Browser and Import Your Working Context

Atlas originally launched for Apple silicon Macs running macOS 14.2 or later. During setup, users could bring over bookmarks, saved passwords, and browsing history from another browser. That import step mattered because Atlas agent mode could operate inside the browser session you were already building, rather than starting from an empty cloud environment.

The better operational practice was to import only what the workflow needed. Moving every saved credential and every personal bookmark into an agent-capable browser increased the amount of state exposed if a malicious page successfully influenced the agent. Even before retirement, the safer pattern was a work-focused profile with limited signed-in services.

How to Use ChatGPT Atlas for Research

The sidebar was the lowest-risk entry point. You opened Ask ChatGPT on a page, asked for an explanation, comparison, extraction, or draft, then judged the response while the source remained visible. That is still the best mental model for page-aware AI: start with read-only assistance and escalate to actions only when an action is necessary.

For research, a useful prompt pattern was: identify the claim, extract the evidence, show what is missing, and do not take any external action. That same discipline remains relevant in ChatGPT Search, where source presence does not automatically prove that each generated claim is supported. Our ChatGPT Search trust test explores that verification gap in more detail.

Switch to Agent Mode for Narrow, Reviewable Tasks

Agent mode made sense when the browser needed to move, not merely read. A good Atlas request named the site, task, stopping condition, and approvals. “Compare these three plans and stop before checkout” was safer than “find me the best option and buy it.” OpenAI itself advised users to avoid overly broad instructions because wider latitude gives malicious or irrelevant page content more room to redirect an agent.

Keep Sensitive Actions Human-Controlled

The final step in any consequential flow deserved a manual review. Account changes, purchases, outbound messages, and data uploads are precisely the places where an incorrect click becomes expensive. Atlas could pause for confirmations, but a confirmation is only useful if the person checks the recipient, account, amount, destination, and data being shared.

The original Atlas workflow therefore had a strong pattern that survives its shutdown: let AI compress reading and navigation, but design explicit checkpoints around irreversible actions.

What Replaced Atlas After 9 August

OpenAI did not replace Atlas with one identical product. It distributed the old browser idea across several surfaces inside ChatGPT and Codex. That is more flexible, but it also means users need to choose the right browser context for each task.

The closest direct replacement is the built-in browser in the ChatGPT desktop app on macOS and Windows. OpenAI says it can browse, sign in, download files, work across multiple tabs, support richer navigation, and keep its own browser state. You can open a chat in Work or Codex, launch the browser from the toolbar or with the documented keyboard shortcut, then ask ChatGPT to use the current page. Permission prompts appear when the assistant needs access.

A second route is Chrome integration. OpenAI specifically recommends using the Codex Chrome extension when a task genuinely needs an existing Chrome profile, current signed-in session, open tabs, cookies, or Chrome extensions. This is not a cosmetic choice. It decides which identity and session state the agent can see. The built-in browser creates an isolated state boundary, while Chrome integration deliberately crosses into the browser profile you already use.

A third route is cloud browsing in ChatGPT. The cloud browser can handle supported tasks on public websites, including checking availability, comparing public product information, or submitting supported public forms. At launch it does not accept credentials, use password managers, sign in, or complete payments. It is therefore a delegation environment, not a replacement for an authenticated local browser.

OpenAI’s shift matches the OpenAI superapp strategy that became explicit in 2026. Reuters reported in March that the company planned to fold ChatGPT, Codex, and its browser into one desktop experience. Fidji Simo told staff that product “fragmentation has been slowing us down,” a concise explanation for why a standalone browser became harder to justify.

The most important post-Atlas change is therefore architectural. You no longer choose one AI browser for every task. You choose a browser surface based on state, risk, and whether the work needs observation or delegation.

A Safer Replacement Workflow for Research and Writing

For research-heavy work, I would reconstruct the best part of Atlas without recreating its largest risk. Keep the assistant close to the source, keep actions read-only by default, and move the final synthesis into a workspace where citations and drafts can be reviewed separately.

Start in ChatGPT Search or the built-in browser with a narrow research question. Ask for primary sources first, then recent reporting, then disagreements or missing evidence. Open the most important pages in separate tabs rather than asking the model to collapse the web into one answer immediately. The built-in browser’s multi-tab support makes this closer to a traditional analyst workflow than the old one-page-at-a-time perception of chat assistants.

Next, annotate or comment on the source when the task is about a page under review. OpenAI’s built-in browser supports annotation mode, which lets a user select an element or region, leave a specific comment, and ask ChatGPT to address it. That is especially useful for reviewing local development pages, web copy, or UI text because the request stays tied to a visible object.

Then move synthesis into a document or Work task. For a publishable draft, separate facts from prose: create a claim list with sources, mark any claims that depend on secondary reporting, and only then write. That reduces the familiar failure mode where a fluent paragraph hides a weak evidence chain.

Our ChatGPT writing workflow uses the same principle for editorial work: define audience, goal, context, constraints, source expectations, and editing criteria before asking for polished copy. The browser should supply evidence, not dictate the article’s structure.

Finally, verify names, prices, dates, and quotations against the original page before publication. A July 2026 large-scale preprint by Xia and colleagues audited 41,331 AI browser summaries generated from 13,777 news articles. The researchers found the summaries broadly accurate, but they also showed that AI browsers act as editorial intermediaries, changing tone, clarity, and political affect. That is useful evidence for summarisation, but it is also a warning: a clean summary is not the source itself.

This workflow is slower than asking an agent to “research and write everything,” but it produces a clearer audit trail and limits the blast radius of a bad page or bad instruction.

A Better Workflow for Coding and Web Tasks

Coding is where the post-Atlas split between browser surfaces becomes particularly useful. The built-in ChatGPT browser can sit beside Work or Codex, inspect a local or hosted page, move across tabs, download supported files, and let the user annotate a specific interface problem. That creates a tight loop between what the code produced and what the agent can see in the rendered result.

A reliable sequence is: open the relevant project in Codex or Work, launch the built-in browser, load the local development route, reproduce the issue, annotate the element, and ask for a narrowly scoped change. Then review the diff, rerun tests, reload the page, and check the result. The browser is evidence for the coding agent, not a substitute for tests.

If the task needs an existing authenticated Chrome session, use Chrome integration deliberately. For example, a developer testing a staging dashboard behind an organisation’s login may need the current Chrome profile. Before granting access, check the active account and close unrelated tabs. OpenAI explicitly says credentials should be entered in the browser, not typed into the chat.

Developers building their own automation should not look for an “Atlas API.” Atlas was a product surface, not a general browser automation API. OpenAI’s current developer paths are broader: apps and plugins connect ChatGPT to external tools, remote MCP servers expose tools and data, and the Computer Use API can return interface actions for a developer-controlled harness to execute. Those routes give engineering teams clearer control over permissions, logging, and application boundaries than scripting a retired consumer browser.

The same controlled-loop principle underpins our guide to coding safely with ChatGPT. The browser can tell the model what is visible, but you still need tests, code review, environment constraints, and a defined stopping condition.

Greg Brockman’s May 2026 memo described OpenAI’s goal as “maximum focus toward the agentic future.” The strategic direction is clear, but the engineering implication is more specific: agents work best when they receive a bounded environment, observable state, and explicit authority. More autonomy is not automatically more reliability.

Pricing, Plans, and the Limits That Matter

Atlas itself was not sold as a separate subscription. At launch, the browser was available to Free, Go, Plus, and Pro users on macOS, while Business access was in beta and agent mode had narrower eligibility. After Atlas retirement, browser and agent features moved into ChatGPT plans, where availability can vary by platform, region, workspace controls, and rollout stage.

The current consumer plan ladder starts at Free, with ChatGPT Go priced at $8 per month in the United States and localised in some markets. Plus is $20 per month. OpenAI now offers two Pro usage tiers at $100 and $200 per month. Its Help Centre says both have the same core Pro capabilities, while the $100 tier provides 5 times the usage of Plus and the $200 tier provides 20 times the usage of Plus. Model-specific allowances can still apply, so “unlimited” should not be read as an unconditional fixed cap for every model and every workload.

Business pricing is currently $25 per user per month when billed monthly or $20 per user per month when billed annually in most countries, with a two-seat minimum for standard ChatGPT seats. Business includes ChatGPT and Codex access, but usage beyond included rates can involve workspace credits. Enterprise remains sales-led with custom pricing.

PlanCurrent Public PriceBrowser and Agent RelevanceLimits to Watch
Free$0Core ChatGPT access; browser features can be limited or rollout-dependentLower allowances for advanced models, files, research, and agentic work
Go$8/month in the USMore everyday capacity than Free; local pricing can differAds may appear; advanced agent and cloud browser availability is not equivalent to higher tiers
Plus$20/monthExpanded reasoning, research, Codex, and richer desktop workflow accessUsage limits still vary by model and feature
Pro$100 or $200/monthHighest consumer access to advanced models and agentic workflows$100 is 5x Plus usage; $200 is 20x Plus usage, with model-specific allowances still possible
Business$25 monthly or $20 annually per userShared workspace, ChatGPT, Codex, apps, company knowledge, agent featuresTwo standard-seat minimum; flexible credits may apply beyond included usage
EnterpriseCustomSales-led deployment, higher governance and admin requirementsExact commercial terms and limits are contract-specific

For pricing context, our earlier coverage of ChatGPT Go’s $8 launch explains why the low-cost plan sits between Free and Plus. The important update for Atlas users is that paying more no longer buys an Atlas browser. It buys higher-capacity access to the ChatGPT environment where the browser-agent concept now lives.

A final caution: public plan pages do not publish a permanent numeric message cap for every model, tool, and region. If a procurement document demands an exact hidden cap, mark it as unconfirmed unless the relevant OpenAI rate card or workspace contract states it. Inventing a precise number is worse than acknowledging that the service uses changing allowances.

Privacy, Browser Memory, and Migration Hygiene

Atlas mixed conversational AI with browser data, which made privacy controls more important than in a normal chat window. OpenAI’s Atlas documentation separated browser memories from ChatGPT memories and from ordinary cookies. Users could turn browser memories on or off, inspect or archive them, and remove associated memories by deleting browsing history. Page visibility controls could also prevent ChatGPT from seeing selected pages.

The training control was similarly specific. “Include web browsing” was off by default and only mattered when the broader “Improve the model for everyone” setting was enabled. Business and Enterprise content was not used for model training. Those settings were useful, but they did not remove the need to think about what an agent could see during an active session.

After retirement, migration hygiene matters more than old privacy settings. Treat the move in three separate layers:

1. Browser artefacts: export or preserve bookmarks and any pages you still need. Open tabs and history did not transfer automatically.

2. Authentication state: treat cookies and session files as credentials. Do not email them, upload them casually, or assume another browser can import them safely.

3. Chat history: keep it conceptually separate. ChatGPT conversations were not the same data store as Atlas browser history and were not deleted simply because Atlas was retired.

This separation is one of the most useful lessons from the shutdown. A modern AI browser is not one database. It is a stack of identities, histories, memories, page permissions, cached content, credentials, and model conversations. A migration plan that says “move my browser data” is underspecified.

The current built-in ChatGPT browser also uses its own browser state rather than automatically inheriting Chrome. That is a privacy feature as much as a convenience trade-off. If a task does not need your primary browser identity, an isolated browser state reduces accidental exposure. If it does need your existing Chrome state, grant that access intentionally and verify the active account.

This is also why the strongest post-Atlas workflow resembles zero-trust thinking: give the agent only the session state required for the task, only for the time required, and review any step that changes an external system.

Security Risks and Prompt Injection

Prompt injection is the defining security problem for browser agents because the agent reads content that may contain instructions written by someone other than the user. A conventional browser mostly renders hostile content for a human to interpret. An agentic browser may interpret that same content as something to act on. The attack therefore targets the decision-maker inside the browsing loop.

OpenAI acknowledged this directly in December 2025, describing prompt injection as one of the most significant risks for Atlas. Its security team built automated attackers trained with reinforcement learning to find multi-step exploits, including long-horizon attacks that unfolded over tens or hundreds of actions. The resulting red-team findings drove adversarial training and changes to the surrounding defence stack.

Independent research showed why those safeguards still needed caution. At Black Hat in August 2026, Zenity researchers presented around 20 flaws across major AI-enabled browsers and browser extensions. WIRED reported that Atlas had more protections and security boundaries than the other AI browsing tools Zenity tested, but researchers still found ways to bypass them. One demonstration redirected an Atlas workflow into spamming WhatsApp contacts. Another manipulated an Amazon account and shopping cart, and researchers eventually used Amazon’s own assistant in a chain that resulted in a purchase. OpenAI said it had deployed an update earlier in 2026 and that the protections extended to the new ChatGPT browser capabilities.

Zenity CTO Michael Bargury warned that AI browsers could resemble “attacks that you saw on browsers 20 years ago.” The quote is dramatic, but the underlying point is practical: model judgement cannot be the only security boundary when an agent has access to authenticated accounts.

RiskHow It AppearsSafer ControlWhat Not to Assume
Indirect Prompt InjectionMalicious instructions hidden in a page, email, or documentKeep tasks narrow, use allowlists where available, review navigation and confirmationsA trusted model can always distinguish page content from instructions
Identity ConfusionAgent acts in the wrong signed-in accountVerify active account, isolate browser profiles, close unrelated sessionsThe visible tab always reflects the intended identity
Over-Broad Authority“Handle everything” prompt gives the agent excessive discretionDefine site, task, stopping point, and approval checkpointsMore autonomy always saves time
Sensitive Data ExposureAgent encounters credentials, private files, or regulated dataKeep credentials in browser fields, minimise connected state, avoid regulated data unless formally supportedWorkspace privacy settings automatically cover every browser surface
Consequential Action ErrorWrong recipient, purchase, upload, deletion, or account changeRequire human confirmation at the final irreversible stepConfirmation prompts are useful if the user does not inspect them

The safest mental model is not “AI browser equals smart Chrome.” It is “agent plus untrusted web plus account authority.” That combination deserves its own threat model.

Browser-Agent Alternatives After Atlas

Atlas retired at the same moment the rest of the market was accelerating. Perplexity Comet remained a dedicated AI browser across desktop and mobile platforms, while Google pushed Gemini deeper into Search, Chrome, Workspace, Android, and new agentic products. Microsoft continued to combine Copilot with Edge and Microsoft 365. The decision is therefore less about which company has an “AI browser” badge and more about where your evidence, identity, and work already live.

Comet is still the cleanest direct comparison for users who liked the idea of an AI-native browser. Its centre of gravity is research and page context, with an assistant available across the browsing experience. For readers who want a dedicated alternative, our guide on browsing with AI in Perplexity Comet explains that workflow. The limitation is the same category-wide problem: any assistant that can read untrusted pages and act across authenticated services needs tight permissions and supervision.

Google’s advantage is distribution. At I/O 2026, Sundar Pichai said Google was “firmly in our agentic Gemini era.” Google also reported more than 900 million monthly active Gemini users, over 2.5 billion monthly active users for AI Overviews, and more than 3.2 quadrillion tokens processed each month across its surfaces. Those figures do not prove better browser-agent quality, but they show why Chrome and Search integration can scale rapidly without asking users to adopt a separate browser brand.

OpenAI’s advantage after Atlas is different. It can make browsing one capability inside a broader work environment that also includes conversation, files, research, coding, apps, and agentic tasks. The cost is that users have to understand which browser state they are invoking.

ChoiceBest FitMain StrengthMain Trade-off
ChatGPT Built-In BrowserWork, coding, page review, controlled authenticated sessionsIntegrated with Work and Codex, separate browser state, annotationsFeature availability varies; users must choose state carefully
ChatGPT Chrome IntegrationTasks requiring an existing Chrome profileReuses signed-in tabs, cookies, extensions, and browser identityLarger exposure to personal or work browser state
ChatGPT Cloud BrowserDelegated public-web tasksRemote execution and clean separation from local browserNo sign-in or payments at launch; paid-plan availability
Perplexity CometResearch-heavy browsing across platformsDedicated AI browser with strong source-context workflowSame agentic security class, and different ecosystem integrations
Gemini in Google SurfacesSearch, Android, Chrome, Workspace usersMassive distribution and deep Google ecosystem contextBest fit depends on Google account and product dependency

No tool wins every row. A research analyst may prefer Comet’s source-first posture, a developer may prefer ChatGPT plus Codex, and a Google Workspace team may prefer Gemini’s native context. The defensible recommendation is use-case fit, not brand loyalty.

Enterprise and Developer Integration Limits

Atlas was particularly awkward for enterprises because it looked like a normal member of the ChatGPT product family while some of its browser-specific controls fell outside the guarantees organisations expected from their main ChatGPT deployment. OpenAI’s Enterprise guidance said Atlas was not in scope for its SOC 2 or ISO attestations at the time, did not emit Compliance API logs, did not integrate with SIEM or eDiscovery, and did not region-pin Atlas-specific data. It also documented gaps around browser-specific policy controls, managed updates, and enterprise lifecycle tooling.

Those limitations are not a reason to assume the replacement has perfect compliance. They are a reason to reassess the deployment boundary. A security team should ask which current ChatGPT browser surface is being enabled, what workspace controls apply to it, what data leaves the browser, what logs are produced, and whether the browser is being used with regulated or production data. Product consolidation can simplify user experience while still requiring separate governance review.

The post-Atlas integration story is richer for developers. ChatGPT apps can connect external services and data to conversations and agent workflows. Plugins provide reusable skills and connections. Remote MCP servers can expose tools or organisational data to ChatGPT, Codex, Deep Research, company knowledge, and developer workflows, subject to the relevant product and permission model. Developer mode adds full MCP client capabilities, including write actions, which is powerful but raises the stakes for prompt injection and malicious tool descriptions.

For user-interface automation, the Computer Use API is the clearest analogue to the old browser-agent concept. Rather than handing an undocumented consumer browser to a script, a developer can build a harness that sends screenshots or state to a model and executes the returned actions under application-defined controls. This makes it possible to add logging, sandboxing, domain restrictions, approval gates, and test environments around the agent.

OpenAI’s ChatGPT superapp overhaul is useful background here because it frames browsing as one capability among many, not the whole product. That is the direction enterprise architecture should follow too: treat browser access as a permissioned tool in an agent platform, not as an all-powerful default surface.

What Atlas Taught Us About AI Browsing

Atlas lasted for less than ten months as a standalone product, but its short life exposed several design truths that will outlast the brand.

First, browser state is now part of AI governance. In old web security, a cookie, tab, password manager, and browsing history were browser concerns. In an agentic system they are also model context and action authority. The safest system is not necessarily the one with the smartest model. It is the one that exposes the smallest necessary state for the task.

Second, “read” and “act” should be separate modes even when the interface makes them feel continuous. Atlas made the transition from sidebar analysis to agent action easy, which was convenient, but that convenience could hide a meaningful change in risk. The post-Atlas environment actually makes the separation easier to reason about because you can choose a built-in browser, Chrome integration, or cloud browser according to the authority required.

Third, migration is a security event. The Atlas shutdown showed that bookmarks, tabs, history, cookies, sessions, passwords, browser memories, and ChatGPT conversations are different assets. A company migrating from any AI browser should inventory each layer instead of treating “browser data” as one transferable object.

Fourth, the agentic browser is becoming an editorial intermediary. The 2026 Xia et al. audit found that AI browser summaries were broadly accurate across more than 41,000 generated summaries, but also systematically altered political tone, negativity, and clarity. That means browser assistants do not merely shorten content. They shape the version of the web the user experiences. For professional research, the source page must remain available for checking.

Finally, product consolidation can be a feature. Reuters reported that Fidji Simo told staff fragmentation had made it harder to hit OpenAI’s quality bar. Atlas proves the broader point: a dedicated AI browser is valuable only if being a separate browser adds more than it costs in security engineering, compatibility, updates, enterprise policy, and user migration. OpenAI ultimately decided that browsing belonged inside its main work environment.

The lesson for users is equally direct. Do not ask which browser is most autonomous. Ask which workflow gives you the evidence you need, the authority you intend, and the smallest acceptable blast radius when the agent is wrong.

Our Content Testing Methodology

This guide was verified on 11 August 2026 against OpenAI’s live documentation for Atlas retirement, the ChatGPT desktop built-in browser, cloud browsing, Atlas privacy controls, Atlas release notes, Enterprise limitations, and OpenAI’s prompt-injection security research. Pricing was cross-checked against current OpenAI plan and Help Centre pages, including the $8 US price for Go, $20 Plus price, $100 and $200 Pro tiers, and current Business seat pricing. We did not invent message caps where OpenAI publishes changing or model-specific allowances instead of permanent numeric limits.

For product history, we used OpenAI’s October 2025 Atlas release documentation to reconstruct the original sidebar, agent mode, browser memory, platform, and safety behaviour. Because Atlas had already reached its scheduled shutdown date before this article was prepared, we did not pretend to run a live post-shutdown Atlas installation test. Historical workflows are labelled as archival, while current replacement instructions are grounded in the supported ChatGPT browser documentation.

For external verification, we cross-referenced Reuters reporting on the March 2026 superapp plan, WIRED’s May reporting on Greg Brockman’s product consolidation, WIRED’s August Black Hat security coverage, Google’s I/O 2026 keynote, and the July 2026 browser-summary audit by Xia and colleagues. Quotes were kept short and attributed to named speakers and publications.

This article was researched and drafted with AI assistance and reviewed by the Sami Ullah Khan editorial desk at Perplexity AI Magazine. All data, citations, pricing figures, and named quotes have been independently verified against primary sources before publication.

Conclusion

ChatGPT Atlas is no longer the product readers can safely learn as a current browser, but the question behind how to use ChatGPT Atlas remains relevant because OpenAI did not abandon browser agents. It moved them into a broader ChatGPT and Codex environment. That change leaves users with more browser surfaces and, potentially, better cross-platform utility, but it also makes one decision more important: choose the minimum browser state and authority that a task actually needs.

For research and writing, the strongest replacement is source-visible, read-first work in ChatGPT Search or the built-in browser, followed by separate synthesis and manual fact checking. For coding, the built-in browser plus Codex creates a useful inspect, annotate, change, test loop. For tasks that genuinely require an existing Chrome identity, Chrome integration can be appropriate, but it should be granted deliberately. Cloud browsing is better suited to supported public-site delegation where sign-in and payments are unnecessary.

The open question is not whether AI agents will keep moving into browsers. Google, Perplexity, Microsoft, and OpenAI are all moving in that direction. The unresolved issue is whether browser agents can become more capable without making account authority, prompt injection, and data boundaries harder to reason about. Atlas’s short life suggests the winning design may be less about a new browser and more about making agent permissions visible, narrow, and reversible.

FAQs

What Is ChatGPT Atlas?

ChatGPT Atlas was OpenAI’s macOS web browser with ChatGPT built into the browsing layer. It included a page-aware Ask ChatGPT sidebar, browser memories, inline writing help, search, and an agent mode that could navigate and take actions in the browser under defined safeguards.

Can I Still Download and Use ChatGPT Atlas?

Atlas was scheduled to stop working on 9 August 2026. Even if an old installation still launches, OpenAI no longer positions it as a supported browser and warned users to move to a maintained experience. The recommended replacement is the ChatGPT desktop browser experience or supported Chrome integration, depending on the task.

What Replaced ChatGPT Atlas?

Its browser-agent capabilities moved into ChatGPT and Codex. The ChatGPT desktop app now offers a built-in browser with its own browser state, multiple tabs, downloads, sign-in support, navigation, and annotations where available. Chrome integration and a separate cloud browser cover other use cases.

Did My Atlas Bookmarks and History Move Automatically?

No. OpenAI said bookmarks, open tabs, and browser history would not transfer automatically. Bookmarks could be exported as HTML and imported into another browser. ChatGPT conversation history was separate from Atlas browser data and remained tied to the ChatGPT account.

Is the New ChatGPT Browser Safer Than Atlas?

OpenAI says protections developed for Atlas extend to the new browser capabilities, but prompt injection remains an open security problem for the category. Safety depends on how much account state an agent can access, how narrowly the task is scoped, and whether consequential actions receive meaningful human review.

Should I Use the Built-In Browser or Chrome With ChatGPT?

Use the built-in browser when you want an isolated browser state inside ChatGPT. Use Chrome integration when the task genuinely needs your existing Chrome profile, signed-in session, open tabs, cookies, or extensions. Check the active account before granting access in either case.

Is There a ChatGPT Atlas API?

There is no current standalone Atlas API to build against. Developers should use supported OpenAI pathways such as ChatGPT apps, plugins, remote MCP integrations, Codex tooling, or the Computer Use API, depending on whether the goal is data access, tool invocation, coding, or user-interface automation.

Which AI Browser Is the Best Alternative to Atlas?

There is no universal winner. Perplexity Comet is a strong fit for source-heavy research, ChatGPT’s built-in browser is closely integrated with Work and Codex, and Gemini benefits from Google’s Search, Chrome, Android, and Workspace distribution. Choose based on workflow, account state, evidence needs, and risk.

References

OpenAI. (2026). Evolving Atlas into ChatGPT for browser-based agentic work. OpenAI Help Centre.

OpenAI. (2026). Using the built-in browser in the ChatGPT desktop app. OpenAI Help Centre.

OpenAI. (2026). ChatGPT Atlas data controls and privacy. OpenAI Help Centre.

OpenAI. (2025). Continuously hardening ChatGPT Atlas against prompt injection attacks. OpenAI.

Reuters. (2026, March 19). OpenAI plans desktop superapp to streamline user experience. Reuters.

Burgess, M. (2026, August 5). OpenAI’s browser could be hijacked to spam your WhatsApp contacts. WIRED.

Pichai, S. (2026, May 19). Google I/O 2026: Welcome to the agentic Gemini era. Google.

Xia, Y., Batorski, D., Wertz, E., Mamakos, M., Li, L., & Wojcieszak, M. (2026). AI-powered browsers are broadly accurate news summarizers that reduce political bias and negative affect. arXiv.

OpenAI. (2026). ChatGPT Business pricing and plan details. OpenAI Help Centre.

Stay Ahead of AI

Get the latest AI news delivered to your inbox.

We don’t spam! Read our privacy policy for more info.