A Product Name That Wasn't Supposed to Be Public Yet
References to an unannounced, always-on ChatGPT assistant internally called "o" briefly appeared on OpenAI's own website before being pulled, first spotted by users on X and reported by BleepingComputer on September 27, 2026. The leak lands just two days before OpenAI's DevDay 2026 on September 29 — timing that suggests "o" was staged for a launch announcement rather than accidentally exposed unfinished work.
What makes "o" notable isn't just that it's a new assistant mode. Leaked configuration data lists a display_name of "o" alongside an email_suffix of "-o" — implying the assistant gets its own email identity, not just read access to a user's inbox. Reverse-engineers tracking the leak found the "o" product name and matching email suffix present across 63 language files, consistent with an assistant that's further along in build-out than a passing internal experiment.
What's Known So Far
| Detail | Description |
|---|---|
| Product name | "o" — display name found in leaked OpenAI configuration |
| Access tier | Gated to ChatGPT Pro ($100/month) — excluded from the Plus tier |
| Capability signal | email_suffix: "-o" suggests an assistant-owned email address, not just inbox read access |
| Scope of leak | Found in 63 language locale files, suggesting active, broad build-out |
| Related system | "Aeon" — a separate, internal system for custom workspace agents, reportedly distinct from consumer-facing "o" |
| Official status | OpenAI has not confirmed or denied the feature |
| Timing | Surfaced two days ahead of OpenAI DevDay 2026 (September 29) |
The Pro-only gating is itself a signal: OpenAI has increasingly split its product line between an assistive tier (Plus) and a more autonomous, agentic tier (Pro) — "o" appears to sit firmly in the latter category, alongside other Pro perks like expanded Codex/Work usage and larger memory and storage allowances.
Why an Always-On, Email-Capable Agent Matters for Security Teams
OpenAI has offered no technical detail on how "o" would handle inbound or outbound email, and no security disclosure accompanies this leak — but the shape of the feature itself raises the kind of questions IT and security teams should be tracking before any general availability announcement:
- A standing target for prompt injection. An assistant that autonomously processes incoming email is, by definition, an agent that will read attacker-controlled content as part of its normal operation. Any email sent to an "o"-owned address becomes a potential injection vector, the same class of risk already documented in other agentic-AI email and browsing features.
- A new identity to govern. If "o" has its own email address rather than borrowing the user's, organizations will need policy for what that address can send, on whose authority, and how its outbound messages are distinguished from a human's.
- Precedent for slip-ups. OpenAI's other agentic features have already had data-handling missteps — including AI agents that accidentally uploaded user images to third-party sites — illustrating that agentic capability and careful data handling don't automatically ship together.
None of this means "o" is unsafe by design; OpenAI hasn't published anything about its guardrails because it hasn't officially announced the feature. It does mean that if "o" (or something like it) is unveiled at DevDay, the interesting questions for a security-literate audience will be about inbox isolation, sender authentication, and injection defenses — not just what the assistant can do for a user's productivity.
What to Watch
- OpenAI DevDay 2026 (September 29) — the natural venue for an official unveiling, given the timing of the leak.
- Any published security documentation accompanying a launch — specifically around how "o" authenticates outbound email and isolates content from inbound messages before acting on it.
- Whether "o" and "Aeon" converge into a single agent platform or remain separate consumer vs. workspace product lines.
CosmicBytez Labs will follow up once OpenAI confirms — or denies — the feature.