
I’ve been keeping an eye on ChatGPT Work since OpenAI launched it back in July, and I’ll admit I filed it away as “interesting, not urgent.” That changed last week.
OpenAI’s quietly pushed through a run of updates that turn Work from a handy assistant into something that runs quietly in the background of your business, watching for triggers and acting on them without you asking twice.
The headline change landed on 25 August. Work can now respond to webhooks, meaning it reacts the moment a new Gmail message arrives, a Slack channel gets a mention, or a GitHub pull request changes, and it can do that without a person opening the app first.
You can also share a scheduled task with your whole team, so one person builds it and everyone else gets their own working copy. A few days later, OpenAI added Premium seats for its most active users, and it synced GitHub plugin marketplaces straight into the workspace.
None of this is flashy in the way a new model release is flashy. But if your business runs on Microsoft 365, it’s worth fifteen minutes of your attention, because it changes how AI agents show up in your team’s day whether you’ve planned for it or not.
What Actually Changed, In Plain English
Work has always been able to research something and hand back a finished document, spreadsheet or report. What’s new is that it no longer needs you to start the conversation.
With webhook-triggered tasks, you can set Work to summarise a Gmail thread the moment it lands, draft next steps as soon as a client leaves feedback in Slack, or flag changes to a GitHub pull request.
It watches, and it acts, using whichever connected app permissions the person who set it up already has.
The sharing piece matters just as much. One team member can build a task, share it across the workspace, and everyone else gets to tweak the instructions, connect their own apps and run their own independent copy.
That’s a genuine shift from “I use ChatGPT for my own work” to “our team runs shared AI workflows,” and it’s the kind of change that sneaks past a lot of businesses because it doesn’t come with a big launch announcement.
Where This Sits Next To Copilot
If you’re a Microsoft-first business, you’re probably already running Copilot inside Word, Excel, Outlook and Teams, pulling from your own content through Microsoft Graph. That’s still a different job to what Work does.
Copilot lives inside your Microsoft apps and knows your organisation’s data. Work is built to reach across tools from different vendors in one agent, including ones that might sit well outside your Microsoft tenant.
Here’s the thing though. Most businesses I talk to don’t pick one and ignore the other. Staff use Copilot for the Microsoft side of their day and ChatGPT for research or quick drafting on the side, often without IT ever formally signing off on it.
Work’s new webhook triggers and shared tasks turn that casual habit into something with real reach, because now it’s not just one person tinkering, it’s a task that can run across a whole team automatically.
That’s not a reason to panic. It’s a reason to get deliberate about where each tool sits. If you’ve already worked through what a Microsoft 365 Copilot licence actually gets you, you’ll know the value depends heavily on how clean your underlying content and permissions are.
The same logic applies here, just pointed at a different vendor. An agent that can watch your inbox and act on a shared task is only as safe as the access sitting underneath it.
The Governance Conversation You Can’t Skip
This is where I’d slow down. A shared, webhook-triggered agent that reads Slack and Gmail and acts without someone opening an app first needs the same discipline you’d apply to a new staff member with system access. Who owns the outcome when it drafts a client email automatically?
What happens if a shared task gets copied by someone who shouldn’t have that level of access to a connected inbox?
The open-source world just worked through a version of this exact question. Debian, the Linux project, spent two weeks voting on how its developers should handle AI-assisted contributions. The option that won wasn’t a ban and wasn’t a free pass.
It’s called “Responsible Use of Generative AI,” and it allows AI tools while keeping the human who submits the work fully responsible for its quality, accuracy and legal compliance.
Debian also expects contributors to actually review and test AI-assisted output before it goes anywhere near production, and draws a hard line around sharing confidential project data with third-party AI services without permission.
That’s a genuinely useful template for a business bringing shared, automated agents into daily work. Write down, in plain language, who owns the outcome when a webhook-triggered task drafts a client response or updates a shared file.
Decide what needs a human to approve every single time, and what’s low-risk enough to run on autopilot. And be explicit about what information is allowed anywhere near an external AI tool, because “the automation did it” isn’t much of a defence if something sensitive ends up somewhere it shouldn’t.
If you’ve already thought through what Microsoft’s Project Perception agentic security tools mean for who approves a fix before it touches a live system, you’re already asking the right kind of question. It’s the same conversation, just aimed at a different vendor’s agent.
A Quieter Trend Worth Watching
While OpenAI’s been building agents that live in the cloud and react to your other apps, Perplexity’s taken the opposite path. It’s just launched Portable Computer, an AI agent that runs entirely on local hardware instead of the cloud, built with NVIDIA on their DGX Spark machines.
Work done locally doesn’t cost anything in token fees, and sensitive files never have to leave the device unless you specifically approve sending something to a cloud model for extra reasoning power.
It’s a niche release for now, limited to specific NVIDIA hardware and a Linux setup, with Windows support still coming.
But it’s a sign of where things are heading. As agents get more capable and more automated, some businesses will want the option to run them without any data leaving the building at all.
That’s a data sovereignty and cost conversation that’s only going to get louder as agentic AI becomes something that runs quietly in the background rather than something you deliberately switch on each time.
What To Actually Do This Week
You don’t need to overhaul anything overnight, but a few practical steps will put you ahead of most businesses still treating this as background noise.
Start by mapping where AI agents already sit in your business, including the ones nobody officially approved. List every tool people are using and be honest about where ChatGPT already runs next to Copilot, because you can’t govern what you haven’t acknowledged.
Next, write or tighten your AI usage policy using the Debian approach as a rough template. Keep it simple. AI assistance and automation are fine, humans stay accountable for outcomes, and there are clear boundaries on what data can reach a connected app or a shared task.
Then, if your team is already using shared or webhook-triggered tasks in Work, do an audit of who built them, who’s copied them, and what app permissions each person is using. It’s a five-minute check that closes a lot of risk.
Finally, pick one or two low-risk automated workflows to formalise properly rather than letting them spread informally. Meeting summaries or first-draft client updates are a sensible place to start, because the stakes are low if something needs fixing.
Where This Leaves You
None of this is about picking a winner between Microsoft and OpenAI. It’s about staying deliberate while both keep shipping updates that quietly expand what AI can do without you in the room.
If your business is Microsoft-first, that doesn’t mean ChatGPT stops mattering. It means you need a clear view of where each tool fits, who’s accountable for what it does automatically, and how you’ll know if something’s drifted before it becomes a real problem.
If you want a hand mapping where AI agents already sit in your business and building the governance to match, that’s exactly the kind of assessment we run at CG TECH. Get in touch and we’ll walk through it together.

About the Author
Carlos Garcia is the Founder and Managing Director of CG TECH, where he leads enterprise digital transformation projects across Australia.
With deep experience in business process automation, Microsoft 365, and AI-powered workplace solutions, Carlos has helped businesses in government, healthcare, and enterprise sectors streamline workflows and improve efficiency.
He holds Microsoft certifications in Power Platform and Azure and regularly shares practical guidance on Copilot readiness, data strategy, and AI adoption.

Sources
- ChatGPT Business Release Notes – OpenAI’s official changelog confirming the original July 9 launch of ChatGPT Work and the August updates for webhooks, shared tasks and Premium seats.
- ChatGPT Release Notes – OpenAI’s consumer changelog detailing the 25 August webhook-triggered scheduled tasks and sharing feature.
- Debian Votes To Let Contributors Code With AI – The Register’s report on Debian’s “Responsible Use of Generative AI” resolution.
- Debian Says Yes To Generative AI, But Keeps Humans Accountable – full breakdown of the resolution’s accountability and data-sharing rules.
- Introducing Portable Computer For Local-First AI – Perplexity’s official announcement of its local-first agent built with NVIDIA.
- Beyond The Licence Fee: Preparing Your Business For Microsoft Copilot Success – CG TECH’s guide to Microsoft 365 Copilot licensing in Australia.
- Agentic Security Arrives: Is Your Business Ready To Let AI Fight Back? – CG TECH’s earlier look at Microsoft’s Project Perception.