OpenAI's Dots Are Always-On Agents With Their Own Cloud Computer. Here's What They Can Do, What They Hand Back to You, and What Isn't Clear Yet
Dots keep working between conversations across more than 4,000 apps. The launch details that matter most are the limits: read-only background research, human takeover for passwords and money, and rules you set yourself.
TL;DR
OpenAI launched Dots on September 29, 2026 at DevDay: always-on agents, powered by GPT-6 Astra, that each run on their own cloud computer and browser and connect to more than 4,000 apps. They are rolling out to ChatGPT Pro, Business Premium, and Enterprise users, and you get one Dot for now. Conversations with a Dot don't count against ChatGPT usage limits, but tasks it starts in Codex or ChatGPT Work do. Background work is read-only, changing a password or moving money always goes back to you, and OpenAI says its protections against prompt injection reduce the risk but don't eliminate it.
OpenAI's own announcement pages returned an access error when we tried to load them, so the launch details below come from The Verge, MacRumors, and OpenTools, plus a DEV Community write-up that cites OpenAI's Help Center. Where a detail comes only from one of those, we say so.
What a Dot is
A Dot is meant to be an ongoing assistant rather than a chat session. According to The Verge, each Dot is powered by GPT-6 Astra, has its own cloud computer with a web browser, and can reach more than 4,000 supported apps. You message it in a text-message-style interface, or hop on a voice call from ChatGPT on web, desktop, or mobile. It can also connect to Slack and Microsoft Teams and carry context across them. Once you give it a task it messages you with updates and questions, and you can open its cloud computer to watch or step in. Texting is listed as coming soon.
Who gets it, and what counts against your limits
- Rolling out from September 29 to ChatGPT Pro, Business Premium, and Enterprise, in select markets. Per the DEV Community write-up of the Help Center, Pro excludes the EEA, Switzerland, and the UK, and Enterprise, Edu, and Healthcare workspaces get an admin-enabled beta.
- One Dot per eligible user for now, at no extra cost. OpenAI says you will later be able to add more Dots and scale each one's speed or monthly work.
- Conversations with a Dot don't count toward ChatGPT usage limits. Tasks a Dot starts in Codex or ChatGPT Work still count, per OpenTools.
- Setup happens on desktop (the ChatGPT desktop app, or chatgpt.com/dots on desktop); after that you can use the mobile app.
- OpenAI's CFO Sarah Friar told CNBC the vision is to bring Dots to the whole consumer base, according to The Verge.
What it will and won't do on its own
| Situation | What the Dot does | Source |
|---|---|---|
| You're away; background research | Read-only over your connected apps. It can't send messages, change content, or control a browser or computer. Custom Rules can't lift this. | OpenTools; DEV Community |
| A task that needs action | Follows your Custom Rules: act without asking, act if pre-approved, ask first, or hand off to you | DEV Community; The Verge |
| Before an action with side effects | An automatic review checks it against your instructions, rules, and safety requirements | The Verge; OpenTools |
| Changing a password or transferring money | You take over and complete it | DEV Community; OpenTools |
| Purchases with a saved card | Needs your approval, which can be given in advance if it specifically covers the purchase | DEV Community |
| Signing in to a supported site | You enter credentials in a secure form that doesn't expose them to the model | DEV Community; OpenTools |
OpenAI says Dots use "built-in rules for when to act independently", and you can add your own. The same Help Center material says local computer access is optional and starts off, and that the protections against prompt injection "help reduce the risk" but "do not eliminate it".
What the launch doesn't settle
- Real-world reliability. OpenAI's examples include a developer asking a Dot to build and test updates from customer feedback, and OpenAI says its engineers use Dots to fix dozens of bugs a day (per OfficeChai's liveblog of the keynote). These are OpenAI's own descriptions, not independent completion rates.
- Memory control. According to the DEV Community summary, you can't view, edit, or delete individual memories; you can pause a Dot or reset it, which deletes conversations, saved memories, and scheduled tasks.
- The limit on deeper work. OpenTools notes OpenAI hasn't published a simple entitlement for how much work a Dot can do; limits are extended during the first launch month.
- Specialist Dots. OpenAI is testing role-based Dots for organisations (it named accounting, email marketing, legal analysis, and ticket resolution on stage), which remain focused pilots.
- Safety in the wild. The Verge notes that rival Meta's Muse has drawn safety concerns, including one user who said it gave out their address. OpenAI points to its review and rules system as its answer.
What this means if you're choosing an agent
If you already pay for Pro or Business Premium, the first Dot is free to try, and the useful test is narrow: give it one bounded responsibility, connect the fewest apps it needs, and read its first completed task in the activity view before widening access. Teams on Enterprise need an admin to turn it on. If you want agents on your own infrastructure instead, the control-plane approach in OpenClaw Enterprise, also announced this week, is aimed at that case.
Sources
- The Verge: OpenAI launches Dots, its Muse competitor (Sep 29, 2026)
- MacRumors: OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
- OpenTools: OpenAI Dots are always-on agents. Their most important launch feature is the control boundary
- DEV Community: OpenAI dots, explained from the docs: the permission model of an always-on agent
- OfficeChai: Liveblog, OpenAI Announces Always-On AI Agents Named Dots
AI Industry Reporter
Priya covers model releases, industry announcements, and the gap between what labs claim and what independent evaluators actually find. She reads the primary source - the paper, the system card, the benchmark org's own statement - before writing a word.
More on AI Automation & Agents
OpenClaw Enterprise Is Free and Open Source, but It's for Pilots Only. What Works Today, and What the Docs Say Is Unfinished
Priya Nair · 5 min
H Company's Holo4 Scores 61.7% on OSWorld 2.0 With a 27B Model. The Weights Are Not Free for Commercial Use.
Priya Nair · 5 min
Manus 2.0 Launches Cascade, Studio, and Cue, an App That Gives Personal Agents Their Own Phone Numbers and Wallets
Priya Nair · 5 min