OpenAI Dots: What the Always-On Agent Can Access, Do, and Cost

OpenAI’s Dots agent can work around the clock across apps and computers. Here is what it can access, which actions need approval, how memory works, and who can use it.
OpenAI knot logo on a black background
Image: OpenAI logo via Wikimedia Commons, public domain.

OpenAI launched Dots on Tuesday as an always-on agent that can keep working between conversations, use a dedicated cloud computer and act through connected apps. The product began rolling out at the company’s DevDay 2026 event alongside ChatGPT Space, GPT-6.1 Sol, a new $500 monthly plan and a broader set of cloud-agent tools.

The practical change is larger than giving ChatGPT a new interface. A dot can monitor permitted information, remember ongoing work, schedule repeat tasks and use websites or software without waiting for a fresh prompt. It can also connect to a user’s own computer, but that option starts disabled. OpenAI is initially including one dot with eligible Pro and Business Premium subscriptions; Enterprise customers can enable a beta.

That wider reach also makes permissions, memory and review controls central to the product. A dot may see material in email, files and connected apps, and OpenAI’s own guidance warns that disconnecting an app does not erase information the agent has already obtained. Deleting that retained context requires resetting the dot.

What OpenAI Dots can do

Each dot runs on GPT-6 Astra and gets a cloud-based Linux environment with a browser, files and tools. OpenAI says the product can connect through its plugin ecosystem to more than 4,000 apps. Users can talk to it in ChatGPT, Slack and Microsoft Teams, while text messaging is beginning as a limited U.S. beta for some Pro subscribers.

The company’s examples span software development, project launches, research and administrative work. A dot can watch incoming customer feedback, prepare and test a code fix, then return a pull request for review. It can update an analysis when new data arrives, revise launch materials after product requirements change or prepare an invoice and wait for approval before sending it.

Users can inspect the agent’s cloud computer while it works. They can also queue several projects, check in-progress, scheduled and completed tasks, or pause the agent. Recurring instructions can cover straightforward monitoring jobs, such as checking a calendar each morning or watching for changes in a project.

Local-computer access is separate. A user must enable it through the desktop app and can later revoke it. Once connected, a dot can work with local files, start ChatGPT Work or Codex tasks, use installed skills and fall back to the local browser if its cloud browser cannot reach a service. That is useful, but it materially expands the information and software within the agent’s reach.

Background research is read-only, but follow-up work may not be

Dots can conduct what OpenAI calls “proactive research” without a new message. In that mode, the agent can inspect information from permitted sources and save private notes about possible next steps. OpenAI says those background tools are restricted in code to read-only access: they cannot send a message, modify an app, or control a browser or desktop.

The restriction applies to the research task, not necessarily to everything the dot may later do with its findings. If the agent decides a follow-up would help, that action goes through the normal permission and review system. Users should therefore separate two questions: what the dot can quietly observe and what it can change after observation.

OpenAI’s security explanation also identifies indirect prompt injection as a risk. An email, webpage or document could contain instructions intended to redirect the agent or induce it to disclose information. The company says it combines model safeguards, restricted tools, monitoring and a separate action-checking system, but it does not claim the problem is eliminated.

Which actions require approval

Dots use built-in action rules plus user-defined Custom Rules. A user can allow a category of action, require approval, block it or hand it back to the human. OpenAI keeps some requirements outside those preferences.

  • Purchases: A dot can use a card already stored with a merchant, but the purchase requires approval.
  • Permanent deletion and unfamiliar software: Permanently deleting data, installing or running software from an unrecognized source, and granting new security-sensitive access require confirmation each time.
  • Passwords and money transfers: The dot may assist with surrounding work but must hand password changes and transfers between financial accounts back to the user.
  • Sharing sensitive information: The system requires increasingly specific authorization as the data becomes more sensitive. OpenAI’s example says health information must be tied to a named recipient.

Before an action such as sending email or changing a file runs, an independent system called Auto-review checks the proposed step against the user’s request, Custom Rules and mandatory safety requirements. The enforcement layer sits outside the dot’s editable environment. If it blocks a step, the agent can request more context, seek approval, try a permitted alternative or stop.

This design reduces the chance that a mistaken interpretation becomes an external action, but it still depends on users setting narrow access and reviewing consequential work. OpenAI explicitly cautions that dots can make mistakes even when following rules.

Memory and app access deserve an early audit

A dot receives existing ChatGPT memories and can create its own memories from conversations and connected apps. It can also proactively review connected information. According to the Dots setup guide, disconnecting an app stops future access but does not delete information already collected. Resetting the dot deletes its conversations, memories and scheduled tasks.

For Business, Enterprise and Edu workspaces, OpenAI does not use customer content to train models by default. Personal-plan users control training through the “Improve the model for everyone” setting. Background-research threads and private notes are not used directly for training, but information pulled from those notes into an eligible conversation may be used when that setting is enabled.

A sensible first deployment is therefore deliberately narrow: connect one low-risk source, define a small recurring task, review the Activity View and inspect what the agent remembers before adding email, cloud storage or local-computer access. Organizations should also decide who owns app approvals, Custom Rules and incident review before a dot begins operating across shared systems.

Who can use Dots, and what it costs

Dots are rolling out gradually. OpenAI Pro users can get them in markets outside the European Economic Area, Switzerland and the United Kingdom. Business Premium users have access across supported ChatGPT regions, while Enterprise users can try the beta after an administrator enables it. OpenAI says it is off by default for Enterprise.

The first dot is included with eligible Pro and Business Premium plans. For the first month, dot usage does not count against eligible Pro, Business and Enterprise allowances; OpenAI has not yet published the longer-term usage terms. Ordinary conversations with a dot do not count against ChatGPT limits, but ChatGPT Work or Codex jobs launched by the dot consume the usual allowance.

OpenAI also introduced three Pro price points: $100, $200 and $500 per month. The new Pro 500 tier includes the highest allowance and GPT-6 Astra Ultrafast. Existing eligible Pro 200 subscribers can retain their previous allowance through October 29, 2026, while some new Pro 200 subscriptions receive a lower allowance at the same price.

ChatGPT Space gives agents shared working material

ChatGPT Space is the companion workspace for pages, uploaded files and collaborative material. Pro, Business and Enterprise users can create and edit pages on the web and desktop app. Mobile currently supports finding, reading and sharing pages, but not editing. Slides and Sheets are listed as coming soon.

Pages can contain text, charts, trackers and interactive tools. People with edit access can collaborate in real time and ask their own ChatGPT instance to change the content. File permissions require care: uploading a file to a page makes it available under that page’s access rules, while linking to an external file does not grant access to the source. Material copied from a restricted source into a shared page becomes visible to everyone who can view the page.

Space does not replace ChatGPT Projects. OpenAI’s help documentation says Projects continue to organize chats, files and project instructions, while Space replaces Library for accounts that receive it.

GPT-6.1 Sol is the lower-cost engine for agent workloads

OpenAI’s other major DevDay release, GPT-6.1 Sol, is available in ChatGPT Work, Codex and the API, but not yet in ordinary Chat. API pricing is $2 per million input tokens, $0.10 per million cached input tokens and $10 per million output tokens. OpenAI positions it as near-Astra performance on coding, computer use and professional tasks at one-fifth of Astra’s standard token price.

The cached-input discount is particularly relevant to agents that repeatedly reuse instructions, tool descriptions and project context. OpenAI reports gains over the previous Sol model on software engineering, document analysis, multi-step business workflows and computer use. Those are company-run or cited benchmark results rather than independent evidence of reliability in a reader’s own environment, so teams should test the model on representative tasks and measure both error rates and total cost.

OpenAI’s full DevDay recap lists more than 20 announcements, including cloud Codex environments, scheduled repository scans, computer use in the Agents API, plugin extensions and a limited-preview Decisions API. Dots is the release with the broadest immediate impact because it combines persistent memory, continuing work and external action in a consumer-facing product. The setup decision should begin with permissions and retention, not the agent’s avatar.

Sources: OpenAI Dots announcement, OpenAI safety and privacy guide, OpenAI Help Center, GPT-6.1 Sol announcement, ChatGPT Pro tiers, Associated Press and Axios.

Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post
NVIDIA Open Agent Safety Platform graphic featuring OpenShell

NVIDIA’s Open Agent Safety Platform Moves Guardrails Outside the Model

Related Posts