OpenAI

Deep Research Now Connects to Any MCP and Trusted Sites

OpenAI's Feb 10, 2026 Deep Research overhaul: connect any MCP app, restrict searches to trusted sites, edit the plan, steer mid-run, now on GPT-5.2. Research agents move to a controlled data layer.

Deep Research Now Connects to Any MCP and Trusted Sites — article cover

On February 10, 2026, OpenAI shipped a pointed overhaul of Deep Research in ChatGPT. The update note on the official page is blunt: deep research can now connect to “any MCP or app” and restrict web searches to trusted sites, focusing research on authenticated, industry-standard sources. The Decoder reported the same day that the feature also moved onto the new GPT-5.2 — replacing the o3 and o4-mini models that had powered it since the 2025 launch.

For developers and knowledge workers, this is more than a UI refresh. The data sources for a research agent are shifting from “the open web” to “the connectors and sites you designate,” and MCP is now formally an input surface for a built-in ChatGPT capability.

What Actually Changed

Combining the official update note with the ChatGPT release notes, four concrete changes shipped:

  • Deep Research can connect to any MCP server or app, pulling data from tools and services you have already authorized
  • Web searches can be restricted to specific websites, collapsing the source set to domains you trust
  • Progress is tracked in real time; you can interrupt with follow-up prompts, new sources, or a change of direction mid-run
  • A redesigned sidebar entry point, a fullscreen report view, and the ability to create and edit the research plan before it starts

The release notes also spell out the rollout: Plus and Pro users got it throughout the day, with Free and Go users following in the coming days.

Why Trusted Sources Are the Point

Deep Research’s core promise has always been multi-step search across large volumes of pages, synthesized into a long report. Open-web search has two structural problems: source quality is uncontrollable, and content behind logins is invisible.

Restricting search to specific sites lets users define the corpus boundary themselves — a legal team can query only regulator domains, an engineer only official docs and issue trackers. MCP apps supply the other half: data in company wikis, databases, and internal tools can now feed the research flow directly. The release notes state the goal plainly: producing “more accurate, credible reports with greater control.”

The Decoder’s caveat is worth keeping: web access reduces hallucination rates but does not eliminate them, and longer reports accumulate more risk. Constraining sources improves input quality; it is not a guarantee of output quality.

MCP Went From Community Protocol to Product Default

Anthropic introduced the Model Context Protocol in November 2024. When OpenAI adopted it in March 2025, most people still filed it under developer-ecosystem concerns. This update marks a turning point: MCP is no longer just an API-level connector option — it is the standard input for ChatGPT’s flagship research capability.

The practical effects on the MCP ecosystem cut two ways. First, any service exposing a remote MCP server now has a new class of end users: not developers, but people doing research. Second, Deep Research’s role is changing — from a report generator that searches the public web into an engine that synthesizes your authorized data and designated sources. The same product line was folded into Agent mode in July 2025 and gained a lightweight version in April 2025; this update continues that trajectory, making the research agent a resident mode of ChatGPT rather than a standalone feature.

What It Means for Real Workflows

Three observations. First, editable research plans and mid-run steering put human-in-the-loop control inside the agent’s execution loop — correcting course at minute five beats a twenty-minute wait for a report that went sideways. Second, source restriction makes Deep Research viable for compliance- and legal-sensitive work for the first time; those teams could never let an agent loose on the open web. Third, connector trust boundaries become a real security responsibility: someone has to audit what each connected MCP server can read.

The same day, OpenAI also quietly refreshed the response style of GPT-5.2 Instant — both entries landed in the February 10 release notes. Base model and research agent upgraded in the same batch is a cadence worth watching.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

FOUND_THIS_USEFUL?

Support more practical AI articles, tutorials, and build notes.

BUY_ME_A_COFFEE
SHAREXEMAIL