NEWS

OpenAI's Leaked 'o' Assistant Points to an Always-On, Email-Capable AI Agent

Leaked references show OpenAI testing 'o,' a Pro-tier always-on assistant with its own email identity — raising fresh agentic-AI risk.

Dylan H.

News Desk

September 27, 2026
4 min read
OpenAI's Leaked 'o' Assistant Points to an Always-On, Email-Capable AI Agent

A Product Name That Wasn't Supposed to Be Public Yet

References to an unannounced, always-on ChatGPT assistant internally called "o" briefly appeared on OpenAI's own website before being pulled, first spotted by users on X and reported by BleepingComputer on September 27, 2026. The leak lands just two days before OpenAI's DevDay 2026 on September 29 — timing that suggests "o" was staged for a launch announcement rather than accidentally exposed unfinished work.

What makes "o" notable isn't just that it's a new assistant mode. Leaked configuration data lists a display_name of "o" alongside an email_suffix of "-o" — implying the assistant gets its own email identity, not just read access to a user's inbox. Reverse-engineers tracking the leak found the "o" product name and matching email suffix present across 63 language files, consistent with an assistant that's further along in build-out than a passing internal experiment.


What's Known So Far

DetailDescription
Product name"o" — display name found in leaked OpenAI configuration
Access tierGated to ChatGPT Pro ($100/month) — excluded from the Plus tier
Capability signalemail_suffix: "-o" suggests an assistant-owned email address, not just inbox read access
Scope of leakFound in 63 language locale files, suggesting active, broad build-out
Related system"Aeon" — a separate, internal system for custom workspace agents, reportedly distinct from consumer-facing "o"
Official statusOpenAI has not confirmed or denied the feature
TimingSurfaced two days ahead of OpenAI DevDay 2026 (September 29)

The Pro-only gating is itself a signal: OpenAI has increasingly split its product line between an assistive tier (Plus) and a more autonomous, agentic tier (Pro) — "o" appears to sit firmly in the latter category, alongside other Pro perks like expanded Codex/Work usage and larger memory and storage allowances.


Why an Always-On, Email-Capable Agent Matters for Security Teams

OpenAI has offered no technical detail on how "o" would handle inbound or outbound email, and no security disclosure accompanies this leak — but the shape of the feature itself raises the kind of questions IT and security teams should be tracking before any general availability announcement:

  • A standing target for prompt injection. An assistant that autonomously processes incoming email is, by definition, an agent that will read attacker-controlled content as part of its normal operation. Any email sent to an "o"-owned address becomes a potential injection vector, the same class of risk already documented in other agentic-AI email and browsing features.
  • A new identity to govern. If "o" has its own email address rather than borrowing the user's, organizations will need policy for what that address can send, on whose authority, and how its outbound messages are distinguished from a human's.
  • Precedent for slip-ups. OpenAI's other agentic features have already had data-handling missteps — including AI agents that accidentally uploaded user images to third-party sites — illustrating that agentic capability and careful data handling don't automatically ship together.

None of this means "o" is unsafe by design; OpenAI hasn't published anything about its guardrails because it hasn't officially announced the feature. It does mean that if "o" (or something like it) is unveiled at DevDay, the interesting questions for a security-literate audience will be about inbox isolation, sender authentication, and injection defenses — not just what the assistant can do for a user's productivity.


What to Watch

  1. OpenAI DevDay 2026 (September 29) — the natural venue for an official unveiling, given the timing of the leak.
  2. Any published security documentation accompanying a launch — specifically around how "o" authenticates outbound email and isolates content from inbound messages before acting on it.
  3. Whether "o" and "Aeon" converge into a single agent platform or remain separate consumer vs. workspace product lines.

CosmicBytez Labs will follow up once OpenAI confirms — or denies — the feature.


Sources