OpenAI has launched a new Data agent for ChatGPT Work, designed to let non-technical staff query company data, build dashboards and take action without writing code or learning an analytics tool.

Announced on 10 September, the agent connects to approved data sources including Amazon Redshift, Datadog, Google BigQuery, Databricks, Snowflake, ClickHouse and MongoDB, as well as documents from Google Drive and SharePoint. OpenAI said it draws on organisations' existing business definitions and metric layers, such as dbt or Databricks Genie Ontology, and enforces the permissions already tied to a user's connected account, including table, row and column-level restrictions. Users can interrogate results with follow-up questions, turn analysis into shareable dashboards, and interact directly with existing BI tools including Omni, Oracle BI, Power BI, Sigma, Tableau and ThoughtSpot.

OpenAI said the underlying capability is already used internally, with nearly all of its product team and more than two-thirds of its go-to-market organisation using data agents to analyse company data themselves. External users in its Alpha programme, including NTT Data and Thermo Fisher, are using the tool to analyse sales and spending and identify reporting errors. Yuji Shono, Head of Global AI Office at NTT Data, said the tool had let non-engineers in sales and corporate functions build and update their own dashboards using plain language, though this reflects the company's own experience rather than independently verified results.

Administrators can install the Data agent through the Plugins directory in ChatGPT Work and control which data connections and user roles are enabled.


Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.
Share this post
The link has been copied!