OpenAI Dots Bring Always-On AI Agents to ChatGPT

OpenAI Dots AI agent working through a cloud computer and connected apps.

OpenAI has launched dots, a new class of always-on AI agents designed to take responsibility for ongoing tasks rather than simply respond to individual prompts. Powered by GPT-6 Astra, each dot gets its own cloud computer and can work through connected apps, continue tasks between conversations and conduct background research on a user’s behalf.

OpenAI announced dots on September 29, 2026, alongside a detailed explanation of the safety, security and privacy systems built around the agents. The company describes dots as agents that can adapt as circumstances change, continue making progress when a user is not actively interacting with them, and return results for review when human judgment is needed.

Quick Summary

  • OpenAI Dots are persistent AI agents designed to handle ongoing tasks.
  • Dots are powered by GPT-6 Astra, OpenAI’s model for demanding computer-based work.
  • Each dot gets its own cloud computer and browser for browsing, research, file creation and tool use.
  • Users can connect selected apps and define what a dot can do independently.
  • Dots can perform background research and scheduled work without continuous user prompting.
  • OpenAI has added controls such as Custom Rules, approvals, monitoring and Auto-review.
  • Sensitive operations such as certain financial transfers and password changes are handed back to the user.
  • OpenAI specifically addresses prompt injection and security risks associated with persistent agents.
  • Dots are rolling out to Pro and Business Premium users in eligible markets, with Enterprise/Edu/Healthcare beta access under administrator control.

What Are OpenAI Dots?

Dots are persistent AI agents built on GPT-6 Astra. Each dot operates with its own cloud computer and browser, giving it an environment where it can browse, analyze information, create files and run tools.

Users choose which apps a dot can access and define what it is allowed to do independently. OpenAI says dots can work through multiple steps, adapt when circumstances change and maintain context over time.

That makes the product different from a conventional ChatGPT conversation. Instead of asking the model to complete one task at a time, users can give a dot an ongoing objective and allow it to continue working between interactions.

OpenAI’s documentation also says dots can research in the background and suggest ways to help even when the user has not submitted a new question. Scheduled and recurring work can also be managed through the dot’s profile.

GPT-6 Astra Powers the Agents

The underlying model for dots is GPT-6 Astra, which OpenAI introduced as its most capable model for demanding work.

Astra is designed for computer use, browsing, software engineering, research and professional workflows. OpenAI says the model is trained to better understand user intent, stay within the scope of a request and ask focused questions when missing information could materially change the outcome.

For dots, those capabilities are combined with a persistent agent environment.

This distinction matters because an agent that operates for longer periods faces different problems from a model responding to a single prompt. It may encounter new information, changing permissions, malicious instructions or situations where the original task no longer applies.

OpenAI’s safety research specifically evaluates dots for these persistent-work scenarios rather than relying solely on the underlying model’s standalone safety evaluations.

Cloud Computers and Connected Apps

A major part of the dots architecture is that each agent receives its own cloud computer.

The computer provides the environment in which a dot can browse, create files, analyze information and run tools. OpenAI says the workspace is sandboxed and separated from systems responsible for coordinating the agent and enforcing safety controls. This is intended to prevent a dot from modifying the safeguards that govern its own operation.

Users can connect the applications and accounts they choose. OpenAI’s broader plugin ecosystem gives dots access to more than 4,000 apps, according to reporting on the launch, expanding the range of software an agent can work with.

Importantly, connecting a user’s personal computer is optional. OpenAI says a dot can operate entirely within its own cloud workspace, while users can separately authorize access to their computer when a task requires local files or tools.

This creates a separation between the agent’s normal working environment and the user’s personal device.

Dots Can Work in the Background

One of the defining features of dots is persistence.

OpenAI says dots can continue making progress in their cloud workspaces when the user is not actively engaged. They can also conduct what OpenAI calls proactive research, using permitted connected sources to gather information and save private notes for the dot.

The background research system has important restrictions. OpenAI says those research tasks use read-only tools and cannot directly send messages, change content in connected applications or control a browser or desktop. Any later action has to pass through the normal permissions and safety mechanisms.

The result is an AI assistant that can continue monitoring and researching a task without being continuously prompted, while still separating background information gathering from more consequential actions.

User Controls Are Central to the Design

Because dots can take actions rather than simply generate text, OpenAI has built additional controls around them.

Users can choose connected apps, establish custom rules and determine when an agent should proceed independently or ask for authorization. OpenAI says some actions always require confirmation, including permanent data deletion, installing or running software from an unrecognized source, and granting certain security-sensitive access.

Some particularly sensitive actions are handed back to the user entirely. For example, OpenAI says dots can assist with tasks surrounding financial transfers or password changes but must hand those sensitive steps back to the user. Purchases made using previously saved payment methods also require approval.

OpenAI has also introduced Auto-review, a separate safety system that evaluates certain planned actions against the user’s instructions, custom rules and safety requirements before they are executed.

If Auto-review blocks an action, the dot receives the reason and can ask for clarification, seek approval, attempt a permitted alternative or stop. The system enforcing these checks is kept outside the environment the dot can modify.

Security and Prompt Injection Remain Key Challenges

OpenAI’s announcement places considerable emphasis on the security risks created by persistent AI agents.

A dot may encounter instructions embedded in webpages, emails or documents that attempt to manipulate its behavior. OpenAI identifies this as prompt injection and says dots use a combination of model safeguards, tool restrictions, action checks and monitoring to reduce the risk that malicious content results in an unwanted action.

The company also says it conducted red-team testing specifically against persistent dots. Its published evaluations examined scenarios involving malicious emails, unauthorized data disclosure and changing permissions.

OpenAI reports that its testing found no scored attack successes in certain large-scale simulated prompt-injection evaluations, while also acknowledging that dots can still make mistakes and that protections will continue to be improved.

That caveat is significant. Giving an AI agent more autonomy increases the consequences of mistakes compared with a conventional conversational system, which is why OpenAI has built confirmation policies and monitoring directly into the dots architecture.

Availability of OpenAI Dots

OpenAI’s current Help Center documentation says dots are rolling out to ChatGPT Pro and Business Premium users in eligible markets. Enterprise users, including Edu and Healthcare workspaces, can access a beta when their workspace administrator enables it.

The first dot is included with Pro and Business Premium at no additional charge, although deeper work is subject to the plan’s usage allowances. OpenAI says additional dots and expanded scaling options are planned for the future.

For now, dots can be created through ChatGPT on desktop, while mobile access can be used after a dot has been created where supported. OpenAI says users can manage scheduled work and review ongoing or completed tasks through the dot’s interface.

The introduction of dots pushes ChatGPT further toward a persistent AI agent platform. Instead of treating each conversation as an isolated request, OpenAI is building a system in which an agent can maintain context, operate its own computer, use authorized software and continue working toward a goal over time.

The technical challenge now extends beyond how capable GPT-6 Astra is at producing an answer. It also involves ensuring that an AI agent knows what it is authorized to do, recognizes when circumstances have changed and gives control back to the user when a decision carries meaningful consequences. OpenAI’s dots safety architecture is designed around that distinction.

Also Read –

GPT-6 Astra: Features, Capabilities, Performance & What’s New?

Source

How we build safety, security, and privacy into dots

Introducing dots

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top