What happened
- OpenAI announced ChatGPT Work on July 9, 2026, and has been iterating on the product since. At the end of August, developer Simon Willison published a review of what it actually does.
- Willison distinguishes two different things under the same name: one that runs in the cloud, accessible from chatgpt.com and the mobile apps, and another that runs on the computer through the desktop app.
- The cloud version can read connected private data, process untrusted web pages, run code with internet access, control a browser and carry out external actions.
- That combination closes all three sides of what Willison calls the lethal trifecta: access to private data, exposure to untrusted content and a way to send information out to an attacker.
Why it matters
- Prompt injection isn’t a bug that gets patched. It stems from the fact that the model can’t tell an instruction from its user apart from an instruction written inside the document it was asked to read. With all three sides closed, any page can dictate actions.
- For a team that connects the assistant to email and the shared folder, the risk isn’t in what the team writes but in what the assistant reads on its behalf. A file sent by a third party is untrusted content by definition, just like a document uploaded to a chat to be summarized.
- The known mitigation is architectural, not a matter of configuration: separating what accesses private data from what processes external material. No checkbox in the settings does that.
The number
3 conditions. Private data, untrusted content and the ability to communicate externally. The risk appears when all three come together. With two, the attack doesn’t complete the circuit.
Context
Willison coined the term prompt injection in 2022 and described the lethal trifecta in June 2025. Since then he has documented cases in ChatGPT, Google Bard, Amazon Q, GitHub Copilot Chat, Microsoft Copilot, Slack, Mistral’s Le Chat and Claude’s iOS app, among others. The problem doesn’t belong to one brand; it belongs to the way these systems are built.
What’s next
- OpenAI doesn’t publish ChatGPT Work’s system prompts. Public documentation of its behavior is produced by independent researchers.
- There is no defense recognized as complete. Current approaches limit capabilities instead of detecting attacks.
- OpenAI has announced no changes to the scope of the product’s permissions.
Bottom line
The same week this architecture was documented, Anthropic warned that an attacker was getting into Claude accounts with stolen cookies. Two different routes to the same destination: the permission that had already been granted.


