One name, two products: what ChatGPT Work actually is
Simon Willison published a hands-on breakdown of ChatGPT Work, the agent OpenAI launched in July to take over whole workflows. Built on Codex technology and powered by GPT-5.6, it acts across apps and files, breaks a goal into steps and keeps at it for hours, and turns out finished docs, sheets, and slides, with scheduled tasks and a plugin directory that connects to workplace tools like Slack, Google Drive, and CRMs. It went out to Plus, Pro, Business, Enterprise, and Edu plans (the X announcement is from the July launch). The confusing part, and what Willison untangles, is that “Work” is two products. Work Cloud runs on OpenAI’s servers and syncs across web, mobile, and desktop. Work Local runs tasks on your own computer inside the new ChatGPT desktop app — the app the Codex app is being merged into, though Codex keeps its own separate view there — and can operate on local files and programs once you grant permission. Willison’s testing found the cloud version ships a full agent stack that plain Chat lacks: a browser tool running a complete Chrome instance, internet-enabled code execution, a persistent workspace folder that survives across sessions, and parallel subagents. He also notes that OpenAI’s own docs stay vague about these mechanisms, and he points at the security shape: an agent that can read your private data, process untrusted web content, and send information out gives an attacker a path — hide instructions in a webpage and the agent may leak what it sees. That is the textbook setup for prompt injection. My read: by building Work on the Codex stack, OpenAI is turning the coding-agent toolkit (sandboxed execution, browsers, long-running tasks) into an office agent for everyone, and the attack surface spreads along with the capability. Before letting it touch local files, check your setup against those three conditions.
Caterpillar brings its mining-automation playbook to enterprise AI
Caterpillar CTO Jaime Mineart told TechCrunch at the Ai4 conference how the heavy-machinery maker is reusing decades of mine automation experience. Field technicians ask the Cat AI assistant by voice for repair procedures, troubleshooting steps, and part identification. Digital twins, virtual models of a job site or production line kept in sync with sensor data and used for simulation and analysis, cover site scanning and manufacturing operations. Internally, AI modernizes legacy code and generates and tests new software. The scale behind it: 1.6 million connected machines worldwide, 16 petabytes of structured data, and a plan to spend $100 million over five years training its 118,000 employees. The transferable lesson is sequencing. Caterpillar’s automation business started in mining, and only after it worked there did the company push into construction sites and quarries, which it describes as far more dynamic environments. Start where conditions are most predictable, then move outward, plus Mineart’s view that the hard part is fitting technology into customer workflows rather than the technology itself. That is a usable template for enterprise AI rollouts.
Research radar
Why continuous diffusion language models are back
Sander Dieleman, a DeepMind research scientist behind visual generation models like Imagen and Veo, published a long piece tracing the history of diffusion-based language modeling (diffusion models generate by adding noise to data and learning to gradually denoise it, the dominant approach in image generation). He is explicit that this is an update on earlier work, not a new method. The mechanics are the interesting part. Language is discrete tokens, and the dominant discrete-diffusion approach corrupts text by masking or swapping tokens; the continuous line instead embeds tokens in a continuous space and adds Gaussian noise. That line went quiet after 2023 and is reviving now because flow-map methods make step distillation practical: training a model to get to a finished sample in just a few denoising steps, in theory even one, which pays off in sampling speed and in post-training. If you track alternatives to autoregressive architectures, this is a field map drawn by an insider.
Today in one line: The coding-agent stack is becoming the general office agent. Capability is generalizing, and so is the prompt-injection attack surface.