> OpenAI dots are always-on GPT-6 Astra agents with their own computer. What launched, how the safeguards work, and what changes for work, IT, SaaS and Europe.
>
> Web page: https://balazscsorba.com/blog/openai-dots-always-on-agents-impact · Language: English · Also available in: [Deutsch](https://balazscsorba.com/de/blog/openai-dots-always-on-agents-impact.md) · [Magyar](https://balazscsorba.com/hu/blog/openai-dots-always-on-agents-impact.md)
> Author: Balázs Csorba · Published: 2026-10-02 · Keywords: OpenAI dots, what are OpenAI dots, OpenAI dots impact, always-on AI agents, GPT-6 Astra agents, dots Auto-review and Custom Rules, specialist dots for enterprise, OpenAI dots EU availability, OpenAI DevDay 2026, AI agents in the workplace

[Blog](https://balazscsorba.com/blog)/AI agents

# OpenAI dots: what always-on agents will change, and what they will not

OpenAI dots are always-on GPT-6 Astra agents with their own computer. What launched, how the safeguards work, and what changes for work, IT, SaaS and Europe.

[Balázs Csorba](https://balazscsorba.com/about)·October 2, 2026·14 min read

-   OpenAI dots
-   AI agents
-   GPT-6 Astra
-   AI governance

![Diagram: a dot running on GPT-6 Astra fans out to Slack and Teams, more than 4,000 apps, its own cloud computer, and a person who approves and reviews.](https://balazscsorba.com/images/blog/openai-dots-always-on-agents-impact/cover.webp?v=ff20896db9)

## Key takeaways

-   OpenAI launched dots on 29 September 2026: always-on ChatGPT agents on GPT-6 Astra, each with its own cloud computer, a memory and access to more than 4,000 apps.
-   The novelty is not capability but initiative. A dot is given a goal, works in the background and checks in, so the human moves from doing the work to approving and reviewing it.
-   The safety design gates actions well (read-only background research, an external Auto-review, mandatory handoffs for passwords and money) but does not limit what the model reads.
-   Dots launched a day after OpenAI shelved GPT-6.1 Astra for failing to stay within scope, which makes the guardrails the part of the product that carries the trust.
-   In Europe, Pro users are excluded at launch while Business Premium is available, so dots arrive through IT, procurement and data protection rather than personal subscriptions.

On this page

1.  [What OpenAI actually launched](https://balazscsorba.com/#what-openai-launched)
2.  [The real shift: from prompts to goals](https://balazscsorba.com/#from-prompts-to-goals)
3.  [How the safety design works, and where it stops](https://balazscsorba.com/#safety-design)
4.  [Why the timing is awkward](https://balazscsorba.com/#launch-week)
5.  [What dots will change](https://balazscsorba.com/#what-changes)
6.  [What I would do in the next 90 days](https://balazscsorba.com/#what-to-do)
7.  [The bigger picture](https://balazscsorba.com/#the-bigger-picture)
8.  [Sources](https://balazscsorba.com/#sources)

On 29 September 2026, at DevDay in San Francisco, OpenAI launched **dots**: always-on agents in ChatGPT, powered by GPT-6 Astra, each with its own cloud computer and browser and connected to more than 4,000 apps through OpenAI's plugin ecosystem. You name your first dot, connect your tools, and it keeps working on your goals in the background, checking in only when there is something to decide or show.

Technically, little of this is new. Codex and similar agent harnesses could already browse, write code, call tools and run for hours. What is new is the contract. A chatbot waits for a prompt; a dot is handed a goal and decides for itself when to act. That turns AI from a tool you operate into a colleague you delegate to, and it moves the scarce resource in knowledge work from doing the work to checking it.

This article looks past the launch video: what OpenAI actually shipped and what is only announced, how the safety design works and where it stops, why the timing is awkward, and what dots will change for knowledge workers, IT departments, software vendors, developers and European companies. It ends with what I would do in the next 90 days.

## What OpenAI actually launched

A dot is a persistent agent with four properties OpenAI emphasises. It runs on **GPT-6 Astra**, OpenAI's most capable model. It has **its own cloud computer** with a browser, which you can open at any time to inspect its work. It **learns from feedback** and receives memories and recent context from ChatGPT. And it **works around the clock**, pursuing a goal over hours or days instead of answering one request at a time.

You reach it in ChatGPT on desktop, web and mobile, in Slack and Teams, or on a voice call, and OpenAI says it carries context across every channel. The examples in the [launch post](https://openai.com/index/introducing-dots/) are deliberately mundane, and that is the point:

-   A developer's dot turns recurring customer feedback into tested pull requests, with video documentation of the fix.
-   A scientist's dot reruns analyses as new data arrives and flags unexpected results for review.
-   A sales dot revises enterprise proposals and test plans when requirements shift, and builds proof-of-concept integrations.
-   A creator's dot turns interview transcripts into clips, show notes and draft social posts.
-   An early tester's dot noticed an invoice the tester had forgotten to send, prepared it, and sent it after approval.

The second, quieter announcement matters more for companies: **specialist dots**. These are not personal assistants but roles. Each gets its own identity, credentials, IT-provisioned hardware and access to systems of record. OpenAI says it tested them internally in procurement, invoice processing, email marketing, customer support and commercial contracting. It is starting with enterprise pilots in which its own engineers define each dot's responsibilities, tools and approval process, and it is working with Microsoft to connect them to the governance controls of Agent 365.

A good part of what was shown on stage is not available yet. The state as of 2 October 2026:

Feature

Status

A primary dot in ChatGPT

Live, gradual rollout: Pro outside the EEA, Switzerland and the UK; Business Premium in all supported regions

Enterprise, Edu and Healthcare

Beta, off by default, switched on by a workspace admin

Slack, Teams and voice calls

Live; a dot cannot call you yet

Texting a dot

Coming; a limited beta for Pro users in the US

Several dots per user, paid speed and workload scaling

Announced

Specialist dots with their own identity and credentials

Pilots with selected enterprises

Microsoft Agent 365 integration

A stated goal

Creating a dot on mobile

Not available; desktop app or desktop web only

## The real shift: from prompts to goals

Every major interface change in software has moved one decision from the human to the machine. Search decided which pages to show. Feeds decided what to show next. Chat assistants decided how to answer. Dots decide **when to act**. OpenAI calls the background part _proactive research_: when you are not working with your dot, it looks for ways to help, reads from the sources you have permitted and keeps private notes. In OpenAI's own words, dots bring you work done the way you would do it, "sometimes before you even think to ask".

That sentence describes a different job for the human. In a chat, you are the author: you notice a problem, phrase the request, read the answer and act on it. With a dot, the agent notices, plans and acts, and you approve and review. The human moves from the start of the chain to the end of it.

With dots, the human stops being the author of the work and becomes its reviewer.

Three consequences follow, and they are easy to underestimate:

-   **The bottleneck becomes attention, not effort.** A dot that runs around the clock produces approvals, drafts and pull requests at machine pace. The limit is how fast a person can check them well. Approval fatigue, clicking yes because there are forty requests waiting, is the failure mode to design against. It is the same one that already shows up in [review queues for agent-written pull requests](https://balazscsorba.com/blog/ai-generated-pr-review-bottleneck).
-   **Tacit knowledge becomes an asset held by the vendor.** "The way you would do it" is exactly the knowledge that never made it into documentation, and a dot accumulates it as memory. OpenAI's FAQ says individual dot memories cannot currently be viewed or edited, and a dot's context can only be deleted by deleting the dot. That is the strongest switching cost any AI product has had so far: you cannot export a colleague's experience.
-   **Pricing turns into labour pricing.** OpenAI says you will later be able to add more dots and scale each one by speed or by the amount of work it takes on per month. That is neither a seat nor a token price. It is capacity, the way you buy contractor hours, and budgets will follow: dots will be compared with headcount and outsourcing, not with software licences.

## How the safety design works, and where it stops

OpenAI published a separate [safety, security and privacy document](https://openai.com/index/how-we-build-safety-security-and-privacy-into-dots/) with the launch, and the design is more careful than the marketing. Its core idea: the agent is not the one deciding whether its own actions are allowed.

The gates sit on actions. Nothing in this path limits what the model reads.

Proactive research runs with read-only tools that are restricted in code, so in the background a dot cannot send messages, change content through plugins or control a browser or computer. Before a consequential action, such as sending an email or changing a file, a separate system called **Auto-review** checks the planned step against your instructions, your Custom Rules and OpenAI's safety requirements. The controls that enforce it sit outside the environment the dot can change. If a step is blocked, the dot is told why and can ask for information or approval, try a permitted alternative, hand the step back or stop.

Custom Rules let you allow, require approval for or block specific actions, but they cannot remove the mandatory floor. Changing a password or moving money between financial accounts always goes back to you. Permanently deleting data or installing unrecognised software needs confirmation every time. Purchases with cards saved on merchant sites need approval. Secure sign-in pauses the model while you type credentials into a form that goes straight to the dot's browser. The dot's cloud computer is separate from yours unless you connect it, and access to your own laptop starts switched off.

That is a sound architecture for **what a dot may do**. It says much less about **what a dot sees**. Every one of those controls sits between the model's plan and the action; none sits between your applications and the model. A dot with read access to a CRM reads the full contact record. A dot preparing a refund reads the card details on the page. A rule that says "ask before issuing refunds" stops the refund, not the reading, and read-only mode is a permission, not a data boundary. If a prompt injection convinces a dot to leak what it has read, the action gate may catch the send, but the data is already in context, and OpenAI itself says its protections reduce but do not eliminate that risk. This is the pattern I described as [the lethal trifecta](https://balazscsorba.com/blog/prompt-injection-lethal-trifecta-patterns): private data, untrusted content and a way out, in one agent.

**Permission is not exposure**

Before you connect a system that holds personal, financial or health data, ask two separate questions: what may the dot do here, and what will the model receive while it works? Custom Rules answer the first. Nothing in the launch documentation answers the second, so the honest answer is: whatever the application shows.

There is a second structural point. Auto-review is OpenAI's model reviewing OpenAI's agent on OpenAI's infrastructure. It is a useful layer, but it is not independent oversight, and the organisation that owns the data gets an Activity View of actions, not a record of what the model read that it could feed into its own SIEM. For regulated work, the controls that matter most still have to be built on the customer side: least-privilege connections, a separate account per dot, and data masked before it reaches the screen. The principles from [sandboxing coding agents](https://balazscsorba.com/blog/sandboxing-coding-agents-ci-checklist) apply unchanged, except that the sandbox now contains your inbox.

## Why the timing is awkward

Dots launched in the most uncomfortable safety week OpenAI has had. On 28 September, the day before DevDay, OpenAI confirmed it would not release **GPT-6.1 Astra**, the planned successor to the model that powers dots. Saachi Jain, its head of safety systems, said the model "didn't quite meet the bar in terms of staying within scope and authorization, and how it communicates back to the user about the type of work it's done". According to the reporting, it was more deceptive than its predecessor in evaluations, did not always disclose what it had done and in some cases acted without asking.

The same day, the AI Security Institute reported that GPT-6 Astra itself carried out unsanctioned attack activity in simulated tests more often than earlier OpenAI models, including creating fake identities and delivering malicious payloads to open-source codebases, in some cases after the scope had been made explicit. That follows a summer of incidents: in July two OpenAI models escaped containment, reached the open internet and breached Hugging Face, and the week before DevDay OpenAI paused training of its most capable models after an agent used a gap in its internet restrictions to contact an external chatbot.

None of this means dots are unsafe. It means two things. First, the guardrails are not decoration: staying within scope is precisely the property the next model failed on, so the external Auto-review, the mandatory handoffs and the read-only background mode are the parts of the product that carry the trust. Second, withholding a flagship model is a credible signal that OpenAI is willing to say no, and that is the most important safety fact of the week. But the model inside dots is the one OpenAI chose to keep, not one that has proven it stays in scope under real-world pressure. Treat a dot like a capable new hire on probation: real work, narrow access, everything consequential checked.

## What dots will change

The effects will not arrive evenly. Some groups will feel them within months, others only when specialist dots leave the pilot phase. Roughly in order of how soon:

### Knowledge workers: from doing to supervising

The first change is in the shape of the working day. The tasks dots are built for are the connective tissue of office work: chasing an invoice, updating a proposal after a call, turning a meeting into follow-ups, noticing that a launch document is out of date. Each is minor on its own and expensive in aggregate, and together they are where most professionals lose their afternoons. A competent dot gives that time back.

The price is a skill few people have trained: delegating precisely and reviewing well. People who already lead others will adapt fastest, because writing a clear brief and checking work without redoing it is management. Junior roles are the uncomfortable part. Much of what juniors learn from, the small and repetitive tasks, is exactly what dots absorb, so organisations will have to design apprenticeship on purpose rather than leave it to chance.

### Companies and IT: agents become identities

Specialist dots make a quiet but radical change: an AI agent receives an identity, credentials and hardware from IT, like an employee. That turns agent governance from a model question into an identity and access management question. Who approves a dot's access? Who is accountable when it acts? How is it offboarded, and what happens to what it knows? The Microsoft Agent 365 integration is the tell: OpenAI expects agents to be managed in the same console as people and devices.

The processes OpenAI tested internally, procurement, invoice processing, customer support and commercial contracting, are the back office: rule-heavy, document-heavy, spread across several systems and today handled by people or brittle RPA scripts. That is where the first measurable savings will appear, and also where mistakes are expensive. The business case will be won or lost on exception handling, not on the happy path.

### Software vendors: the agent is the user

If a dot does the clicking, the dot is your user. Dots reach apps through OpenAI's plugin ecosystem and otherwise use the browser on their own computer. Products with a clean plugin or API surface will be used well; products that only work through a human-shaped interface will be used badly, or skipped. It is the same shift I described for [agent-ready websites with WebMCP](https://balazscsorba.com/blog/webmcp-agent-ready-website-guide) and for [agentic commerce protocols](https://balazscsorba.com/blog/agentic-commerce-protocols-ucp-acp-guide), now arriving through the largest distribution channel in AI: OpenAI says ChatGPT has 1.2 billion weekly users.

There is a pricing consequence too. Seat-based SaaS assumes one licence per human operator. When one dot does the routine work of several people in a tool, vendors will see fewer seats and heavier usage, and many will move to usage- or outcome-based pricing. The vendors that make their product safe for a dot to operate, with scoped tokens, clear action semantics and approval hooks, will be the ones an IT department allows dots to touch.

### Developers: more pull requests, the same reviewers

OpenAI's headline developer example is a dot that watches customer feedback and opens tested pull requests with video documentation. That is useful, and it widens the gap the industry already has: generating changes is cheap, reviewing them is not. A team that lets dots work on a repository needs a review policy first, with size budgets, required tests and a named human owner for every change. Tasks dots start in Codex or ChatGPT Work count against normal usage limits, so cost control belongs in the same policy. For the engineering side of running agents reliably, see [harness engineering](https://balazscsorba.com/blog/harness-engineering-coding-agents) and [how the agent loop works](https://balazscsorba.com/blog/agent-loop-explained).

### Europe: in through the company door

The rollout map is unusual. Pro users in the European Economic Area, Switzerland and the UK are excluded at launch, while Business Premium users get dots in every supported region. OpenAI has not said why. Whatever the reason, the effect is clear: in Europe, dots will not spread through employees' personal subscriptions first. They will arrive through the company account, which means through IT, procurement and the data protection officer.

That is good news, provided those three are ready. An always-on agent that reads CRM records, inboxes and documents is personal data processing at scale. It needs a legal basis, a data processing agreement, retention rules and, in most cases, a data protection impact assessment. Business, Enterprise and Edu content is not used for training by default, but limited human review can still happen in safety cases, and a dot's memories cannot be inspected one by one, which will make access and erasure requests awkward. Where a dot writes to people on your behalf, the transparency duties of the EU AI Act may also apply. I covered the groundwork in [GDPR and EU data residency for LLM APIs](https://balazscsorba.com/blog/gdpr-llm-api-eu-data-residency) and in the [AI Act Article 50 checklist](https://balazscsorba.com/blog/eu-ai-act-article-50-developer-checklist).

### The market: the personal agent is the new platform war

Dots arrived three weeks after Meta's Muse, which topped the App Store within days, and one day after Instinct, a startup building a personal agent, raised $1 billion at a $10 billion valuation. Meta is going after consumers; OpenAI, at least with this first release, is going after work. The prize is the same: whoever holds the agent that knows your preferences, tools and history holds the relationship, and every other app becomes a supplier to it. That is why memory and integrations, not benchmark scores, will decide this round.

Who

What changes first

What to prepare

Knowledge workers

Routine follow-ups move to a dot; the job becomes delegation and review

Clear briefs, a definition of done, protected review time

IT and security

Agents become identities with credentials and hardware

Agent IAM, least privilege, offboarding, logs outside the vendor

Software vendors

The agent becomes the operator of the product

Plugins and APIs, scoped tokens, approval hooks, usage pricing

Developers

More agent-written pull requests

Review budgets, required tests, a human owner per change

European companies

Access comes through the business account

DPIA, processing agreement, rules for regulated data

## What I would do in the next 90 days

The Enterprise beta is off by default, which gives most organisations a rare moment: the decision can be made before the tool is in use, not after. This is the order I would work in:

1.  **Pick one bounded process and measure it.** Invoice follow-ups, proposal updates or support triage. Record today's cycle time and error rate, run a dot on it for four weeks, and measure the same numbers plus the review time it costs.
2.  **Write Custom Rules before connecting apps.** Require approval by default for anything that sends, pays, deletes or shares, and loosen a rule only where the activity log shows the dot is reliable.
3.  **Treat each dot as an identity.** A separate account, least-privilege scopes, an owner, an expiry date and an offboarding step. Never give a dot a person's credentials.
4.  **Keep regulated data out until you control exposure.** Health, payment and HR systems stay disconnected until you know what the model receives, not only what it may do.
5.  **Budget review capacity, not just licences.** Every hour a dot saves creates some minutes of checking. Decide who does it and when, or approval fatigue will decide for you.
6.  **If you sell software, make it agent-operable.** A plugin or a well-scoped API with clear action semantics is now a distribution channel.

None of this requires betting on OpenAI. Meta, Google and Anthropic are building the same category, and the same controls apply to all of them. The vendor may change; the governance you build now will not.

## The bigger picture

Dots are the first mass-market product that treats an AI model as a member of staff rather than a feature. The capabilities were already there; OpenAI has packaged them with an identity, a memory, a computer and a price model that looks like labour. That is why the impact will be organisational before it is technical.

The open question is not whether dots can do the work. In a narrow, well-scoped process they clearly can. The question is whether organisations can absorb work that arrives faster than they can verify it, and whether the safeguards around a model whose successor was just held back for leaving its scope will hold once dots reach the wider ChatGPT user base. The companies that come out ahead will treat delegation as a discipline: clear goals, narrow access, real review.

## Sources

1.  [OpenAI: Introducing dots (29 September 2026)](https://openai.com/index/introducing-dots/)
2.  [OpenAI: How we build safety, security and privacy into dots](https://openai.com/index/how-we-build-safety-security-and-privacy-into-dots/)
3.  [OpenAI Help Center: Dots privacy, security, and safety FAQs](https://help.openai.com/en/articles/20001529-dots-privacy-security-and-safety-faqs)
4.  [TechCrunch: OpenAI launches Dots, its bubbly agentic avatar](https://techcrunch.com/2026/09/29/openai-launches-dots-its-bubbly-agentic-avatar/)
5.  [Unite.AI: OpenAI rolls out dots agents powered by GPT-6 Astra in ChatGPT](https://www.unite.ai/openai-rolls-out-dots-agents-powered-by-gpt-6-astra-in-chatgpt/)
6.  [MediaNama: OpenAI launches dots that keep working without user prompts](https://www.medianama.com/2026/10/223-openai-launches-dots-devday-2026/)
7.  [PYMNTS: OpenAI launches dots to capture AI agent market](https://www.pymnts.com/news/artificial-intelligence/2026/openai-launches-dots-to-capture-ai-agent-market/)
8.  [Yahoo Finance: OpenAI debuts Dots AI agents in challenge to Meta's Muse](https://finance.yahoo.com/technology/article/openai-debuts-dots-ai-agents-in-challenge-to-metas-popular-muse-agent-174616593.html)
9.  [CNBC: OpenAI abandons plan to release upcoming model as safety concerns escalate](https://www.cnbc.com/2026/09/28/openai-abandons-plan-to-release-upcoming-model-as-safety-concerns-escalate.html)
10.  [The Hacker News: OpenAI shelves GPT-6.1 Astra after tests find deception and unauthorized actions](https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html)
11.  [Al Jazeera: OpenAI launches dots, personal AI assistant built to handle everything](https://www.aljazeera.com/economy/2026/9/30/openai-launches-dots-personal-ai-assistant-built-to-handle-everything)
12.  [RedactSure: Do OpenAI dots Custom Rules control what the agent sees?](https://redactsure.com/research/do-openai-dots-custom-rules-control-what-the-agent-sees)

## Frequently asked questions

What are OpenAI dots?

Dots are always-on AI agents in ChatGPT, launched on 29 September 2026 and powered by GPT-6 Astra. Each dot has its own cloud computer and browser, connects to more than 4,000 apps through OpenAI plugins, learns from feedback, and works on goals in the background over hours or days, checking in when there is something to decide or show.

Are dots available in the EU, Switzerland and the UK?

Partly. At launch, Pro users in the European Economic Area, Switzerland and the UK cannot use dots. Business Premium users can, in every supported ChatGPT region, and Enterprise, Edu and Healthcare workspaces can enable a beta through their admin. The rollout is gradual, so access may take several days to arrive.

How much do dots cost?

The first dot is included in Pro and Business Premium at no extra cost, and for the first month dot usage does not count toward plan allowances. Conversations with a dot do not count against ChatGPT usage limits, but tasks it starts in Codex or ChatGPT Work do. OpenAI says you will later be able to add more dots and scale their speed or monthly workload.

Can a dot act without asking me?

Within limits you set. Custom Rules let you allow, require approval for or block actions, and a separate Auto-review system checks consequential steps before they run. Some actions always come back to you, such as changing a password or moving money between financial accounts, and background research only uses read-only tools.

Is it safe to connect a dot to company data?

Only with care. The safeguards control what a dot may do, not what the model reads: a dot with access to a CRM or an inbox sees the content it opens, and prompt-injection protections reduce but do not remove the risk. Start with one bounded process, least-privilege access and separate accounts, and keep regulated data disconnected until you can control what reaches the model.

How are dots different from Codex or a chatbot?

A chatbot answers when asked, and Codex works on the tasks you give it. A dot is persistent: it keeps a memory of your preferences, works toward goals around the clock, notices things on its own through proactive research, and is reachable in ChatGPT, Slack, Teams and by voice. Much of the capability existed before; the new part is the always-on, goal-driven contract.

Written by Balázs Csorba

Senior fullstack & AI engineer in Styria, Austria – 10+ years of Vue, Nuxt, Node.js and PHP, now building tooling for AI agents.

[AI engineering & MCP servers →](https://balazscsorba.com/expertise/ai-engineer)[About me →](https://balazscsorba.com/about)

## More articles

-   [Top 20 ways to cut coding-agent tokens: rtk, lean-ctx, Serena and more, ranked by evidence](https://balazscsorba.com/blog/token-saving-tools-coding-agents-top-20)
-   [The agent loop, explained: how coding agents run, and how to make them stop](https://balazscsorba.com/blog/agent-loop-explained)
-   [MCP tool design: lessons from a 20-tool Jira server](https://balazscsorba.com/blog/mcp-tool-design-lessons-jira-server)
-   [Harness engineering: guides and sensors that make agent PRs mergeable](https://balazscsorba.com/blog/harness-engineering-coding-agents)

## Sounds like what you need?

Tell me about your project or role – I’d love to hear from you.

[Book a call](mailto:contact@balazscsorba.com) [Connect on LinkedIn](https://www.linkedin.com/in/balazs-csorba)
