On September 29, 2026, OpenAI introduced dots, always-on agents that keep working after you close the chat window. Each dot runs on GPT-6 Astra and has its own cloud computer. It works toward your goals around the clock and messages you when it needs a decision.
The pitch is simple. You stop prompting and start delegating.
What Is a Dot?
A dot is a persistent agent assigned to one person. You name it and shape it. Over time, it learns your preferences and your standards.
OpenAI shared one early-tester story. A dot noticed its owner had never invoiced a publication. It prepared the invoice and sent it after he approved. The dot found the gap and did the work. The human gave the final yes.
How Dots Work
Four mechanics define the product.
A private cloud computer. Each dot gets its own computer and browser. You can open it and inspect the work at any time. Your own laptop stays separate unless you connect it.
Plugins for 4,000+ apps. OpenAI says dots connect to more than 4,000 apps. One dot can work across your whole toolset.
Memory that compounds. Dots learn from your feedback. Your edits carry across the materials they produce.
Proactive research. When you step away, your dot hunts for ways to help. During this phase, it uses read-only tools. It can’t send messages, change app content, or control your browser.
You reach your dot in ChatGPT on desktop, web, and mobile. Slack and Teams work too, and texting is coming. You can also start a voice call.
OpenAI hasn’t published dots’ internals. Most agents in this class run a plan, act, observe cycle, and OpenAI’s description matches that pattern.
Not the First Always-On Agent
Developers already run agents that work overnight. OpenClaw, the open-source agent that takes orders through messaging apps, proved the demand.
Dots take the same idea and host it in OpenAI’s cloud. You trade local control for managed safeguards.
Where Dots Fit in Real Work
OpenAI’s examples share one pattern. The dot runs the loop. The human makes the call.
- Developers: A dot reads customer feedback, builds small fixes, tests them, and returns pull requests with videos.
- Product leads: When scope shifts, the dot revises launch materials.
- Scientists: As new data lands, the dot reruns analyses and flags what needs review.
- Sales leads: The dot checks requirements against product docs and builds a proof of concept.
- Creators: From an interview transcript, the dot drafts clips, show notes, and posts.
The Real Product Is the Leash
Most coverage will focus on the agent. The permission system matters more.
An always-on agent acts while you sleep. So the question shifts from “how smart is it?” to “how far can it go without me?” I call OpenAI’s answer the Leash Test. It’s my framing, not the company’s.
| Layer | Question | What OpenAI built |
|---|---|---|
| Reach | What can the dot touch? | You pick the connected apps and set permissions in ChatGPT |
| Autonomy | What can it do alone? | Built-in rules, plus Custom Rules to allow, block, or require approval |
| Audit | What can you see? | Activity View, plus an inspectable cloud computer |
Dots also run auto-review on actions that could affect your accounts or share information. Some tasks always stay with you. Changing a password is one. OpenAI explains its approach in a dedicated safety post.
This design reflects a wider shift in governance. Teams now focus on authorizing actions before they happen instead of reviewing output afterward. Dots follow that logic.
The read-only rule for proactive research also closes a known gap. Researcher Simon Willison describes a “lethal trifecta” of private data access, untrusted content, and outbound communication. OWASP’s 2026 report puts prompt injection at the center of agent risk. By my reading, blocking outbound messages during background work removes one leg of that trifecta.
The Catch: Review Becomes the Bottleneck
Dots cut the cost of producing work. They don’t cut the cost of checking it.
Imagine ten drafts, ten pull requests, and three invoices waiting each morning. Your scarce resource is now attention. The approval queue becomes the new inbox.
Law firm Mayer Brown warns about alert fatigue and automation bias in human oversight of agents. Both apply here. Governments that deploy agents tend to build fixed human checkpoints into each workflow. Individual users will need the same discipline.
The winners won’t delegate the most. They’ll write the sharpest Custom Rules and read the high-stakes approvals.
Specialist Dots for Organizations
Your dot works for you. Specialist dots work for a company.
Each one gets its own identity, credentials, and system access. The company defines its responsibilities. OpenAI cites early testing in procurement, invoice processing, email marketing, customer support, and commercial contracting.
These start as focused enterprise pilots. OpenAI’s engineers will work with each organization on scope, tools, and review. OpenAI is also working with Microsoft to bring specialist dots into Agent 365.
For IT teams, this makes non-human identity management a daily job. Someone has to decide who certifies a dot’s access.
Availability and Pricing
Dots roll out today to Pro and Business Premium users in eligible markets. Enterprise admins can enable the beta.
Your first dot comes with your plan at no extra cost. The plan adds an allowance for deeper work, with extended limits for the first month. Later, you can add dots and scale each one by speed or monthly workload. Conversations with your dot don’t count against ChatGPT usage limits. Tasks it starts in Codex or ChatGPT Work do.
OpenAI says it doesn’t use Business, Enterprise, or Edu workspace content to improve models by default. Personal plan users can control training use.
What to Watch Next
OpenAI says it envisions teams of dots working together. That raises the stakes. One agent with a clear boundary is manageable. Several agents handing off work will stress every permission model in the market.
AI assistants used to wait for instructions. This one starts without you.
FAQs
Q. What are OpenAI dots?
Always-on AI agents that work on your behalf. Each has its own cloud computer, browser, and connected apps.
Q. What model powers dots?
GPT-6 Astra, according to OpenAI.
Q. Can a dot act without my approval?
Sometimes. Built-in rules decide when it acts alone and when it asks. Custom Rules let you change that. Sensitive tasks, like password changes, always stay with you.
Q. Can a dot use my laptop?
Only if you give permission.
Q. Where can I talk to my dot?
In ChatGPT, Slack, and Teams. Voice calls work too. Texting is coming.
Q. Who gets dots first?
Pro and Business Premium users in eligible markets. Enterprise users join the beta once an admin enables it.
Q. What are specialist dots?
Dots with their own identity and credentials. A company sets them up for defined jobs like procurement or invoice processing.
Related: Who Reads Your ChatGPT Conversations? Inside OpenAI’s Project Lily
