OpenAI Dots: What the Always-On Agents Can and Can't Do

Sam Altman speaking at TED. Photo: Steve Jurvetson / CC BY 2.0 via Wikimedia Commons

Elias Mwewa · · 8 min
OpenAI's dots are always-on AI agents with their own cloud computers. What they do, who can use them, the safety record behind them, and what to watch.
OpenAI launched dots at DevDay on September 29, 2026: always-on AI agents that keep working when you're not in the chat. We're a week late, which gave us time to check what they do, who can use them, and the safety record behind them.
What are OpenAI's dots?
A dot is a personal AI agent, powered by GPT-6 Astra, that runs on its own cloud computer and works toward your goals around the clock. In practice, each dot:
- Has its own cloud computer and browser, separate from your laptop unless you connect it.
- Connects to more than 4,000 apps through plugins.
- Takes requests in ChatGPT, Slack and Microsoft Teams, and learns your preferences over time.
- Does "proactive research" in the background using read-only tools.
Who can use dots, and what do they cost?
Dots are rolling out to ChatGPT Pro and Business Premium, and your first dot is included at no extra cost. That isn't cheap. Pro now comes in three tiers, at $100, $200 and $500 a month, with the $500 tier adding OpenAI's fastest "Ultrafast" mode and the most usage. Business Premium seats cost $125 per user a month, or $100 billed annually. The Free, Go and Plus plans don't include dots, so for most individuals and small teams, dots start at $100 a month.
Enterprise, Edu and Healthcare workspaces get a beta if an admin turns it on. Pro users in the European Economic Area, Switzerland and the UK are excluded for now. Dots aren't available to users under 18, can't yet be created on mobile, and OpenAI hasn't announced prices for additional dots.
What safety controls do dots have?
- Custom Rules let you allow, block, or require approval for specific actions.
- Password changes and money transfers always need your confirmation.
- An auto-review step checks planned actions against your rules, and monitoring can pause a dot.
OpenAI is candid about the limits: its protections reduce prompt-injection attacks (malicious instructions hidden in web pages or emails) but don't eliminate them, and it says dots "can still make mistakes" and that consequential work should be reviewed. Last December, OpenAI wrote that prompt injection is "unlikely to ever be fully 'solved.'"
What went wrong on stage
The launch itself stumbled three times on stage:
- Holly Li called her dot, nicknamed "Dottie," and asked for a summary of the previous night's user testing. It replied "Checking that now," then "Still checking," and never delivered. She moved on, joking that it was having "a slow morning."
- Later in the same demo, she said an earlier error had thrown off the Codex thread her dot was using to build an app, and left the build running.
- Romain Huet tried to drive Codex by voice in a React project, but voice chat wouldn't start and the Codex session disconnected. He restarted the terminal and typed the request instead. About a minute later the app he asked for, a page that picks three attendees for free DevDay 2027 tickets, was running.

Why the timing raises fair questions
Dots arrived in a difficult few weeks for OpenAI's agents:

- September 28: OpenAI cancelled the planned release of GPT-6.1 Astra after it performed poorly on alignment tests, including higher deception and pushing beyond a task's scope without permission. Dots run on the earlier GPT-6 Astra.
- September 24: Australia said an OpenAI agent, during internal testing in June, got into a government Medicare portal and accessed non-public data. OpenAI says it found no evidence that patient records were accessed. Prime Minister Anthony Albanese criticised the roughly three-month delay in telling Canberra.
- July: during internal cybersecurity evaluations, OpenAI models escaped their isolation and gained root access to a Hugging Face server. OpenAI published a report and tightened its controls.
To be fair to OpenAI, these incidents involved internal research models, not dots, and the company disclosed them and pulled a model that didn't meet its bar. But they show the exact behaviour that agent controls are meant to contain: systems that keep pushing toward a goal past the limits they were given. Sam Altman has said he agrees "we need to pace the frontier."
Should you use a dot?
Dots look most useful for repeatable work you can check: drafting invoices for approval, keeping research digests current, updating documents as plans change. Be more careful with anything that touches money, passwords, customer data or regulated information. Start with approval required for actions that leave the dot's computer, connect only the apps it needs, and review its output before it counts.
My read: dots are a real step toward AI that works alongside you, released by a company that is, by its own account, still learning how to keep agents within bounds. Use them, but keep your hand on the rules.
For my own work, I already get most of what dots promise from Claude. Claude Code runs on my computer and in the cloud, and the Chrome extension lets it work in my browser, so I act more as director than doer. I plan and research each task with Claude first, set the rules, and choose which tabs and apps it can reach. That control also helps limit prompt-injection risk, though Anthropic says the risk isn't zero. Then I let it work: research, writing, coding, even shopping, though I approve anything it buys. Several chats run at once, each with its own helper agents, and they pause only when they need me. I often go to sleep with Claude working and wake up to finished work, and since Opus 5.5 arrived, there's far less back-and-forth.
Dots' reach into more than 4,000 apps is useful. But Meta's Muse (launched September 8) and xAI's Grok Bot (released as a beta in August) already offered agents with their own cloud computers, and to me this launch felt rushed to keep pace, which may be part of why the demos stumbled. That's my impression, not a claim about what happened inside OpenAI. Plenty of people will get real value from dots. Some of us already have what we need: I trust Anthropic's approach, and a Claude Max plan, at $100 or $200 a month, covers most of what I'd hand a dot, so I don't need another $100 to $500 a month on top. Want me to show you how I set this up? Leave a comment.
Quick answers
Are OpenAI dots free? No. The first dot is included with ChatGPT Pro ($100, $200 or $500 a month) and Business Premium ($125 per user a month, or $100 billed annually). Free, Go and Plus plans don't include dots.
Are dots available in Europe or the UK? Not on Pro yet: the EEA, Switzerland and the UK are excluded for now. OpenAI hasn't announced the same limit for Business Premium, so check with your workspace admin.
Do dots train on my data? Business, Enterprise and Edu content isn't used for training by default. On personal plans it depends on your "Improve the model for everyone" setting, and proactive research isn't used for direct training.
Sources
Primary sources
- OpenAI: Introducing dots, Sep 29, 2026
- OpenAI: DevDay 2026 keynote livestream, Sep 29, 2026
- OpenAI: The Hugging Face incident and the road ahead, Aug 26, 2026
- OpenAI Help Center: About ChatGPT Pro tiers
- OpenAI Help Center: ChatGPT Business – Overview
- Claude Help Center: Use Claude in Chrome safely
Reporting
- The Next Web: OpenAI launches dots, always-on AI agents with their own cloud computers, Sep 29, 2026
- Unite.AI: OpenAI Rolls Out Dots Agents Powered by GPT-6 Astra in ChatGPT, Sep 29, 2026
- TechCrunch: OpenAI says AI browsers may always be vulnerable to prompt injection attacks, Dec 22, 2025
- Simon Willison: OpenAI DevDay 2026 live blog, Sep 29, 2026
- Futurism: New OpenAI Product Fails Spectacularly During Live On-Stage Demo, Sep 30, 2026
- 9to5Google: OpenAI cancels GPT-6.1 Astra release over misbehavior & safety concerns, Sep 28, 2026
- Al Jazeera: Australia says OpenAI agent hacked Medicare portal, Sep 24, 2026
- ITV News: Musk and ChatGPT CEO back calls to 'slow down' development of AI, Sep 13, 2026
- Axios: Meta debuts Muse, its long-planned personal AI agent, Sep 8, 2026
- iPhone in Canada: xAI Debuts 'Grok Bot' AI Teammates You Can Give Real Work To, Aug 12, 2026
Photos
- Cover, Sam Altman speaking at TED: Steve Jurvetson, CC BY 2.0, via Wikimedia Commons
- Parliament House, Canberra: Thennicke, CC BY-SA 4.0, via Wikimedia Commons
- Stage screenshots: OpenAI DevDay 2026 livestream
Find the words from this article
Tap or drag across the letters, or type them. Enter checks a word.
4 letters
5 letters
6 letters
7 letters
Comments 0