What Are OpenAI Dots? The Complete Guide to Always-On AI Agents
OpenAI's dots are always-on GPT-6 Astra agents with their own cloud computers. What Are OpenAI Dots? The Complete Guide to Always-On AI Agents
By Dillip Chowdary • Sep 29, 2026 • Source: OpenAI
OpenAI's dots are the biggest bet from DevDay 2026: always-on agents that live in ChatGPT, run on their own sandboxed cloud computers, and keep working toward your goals around the clock — including when you are not talking to them. Powered by GPT-6 Astra and able to connect to more than 4,000 apps, a dot is designed to be less like a chatbot and more like a capable colleague: you hand it responsibilities, it works through them, messages you with progress, and hands back the decisions that need your judgment.
This guide pulls together everything OpenAI has published across the launch announcement, the dots safety paper, and its help documentation, plus early hands-on coverage: what a dot actually is, how the machinery works, what you can realistically delegate today, the control system that keeps it on a leash, exact setup steps, and where availability, pricing, and the roadmap stand.
What exactly is a dot?
A dot is a persistent agent attached to your ChatGPT account — not a conversation, but an entity that survives between conversations. It has a name and a handle (by default @yourname-dot), an avatar you pick from available characters — or a pet it can generate for you — and its own memory. You can message it in ChatGPT on desktop, web, and mobile, reach it in Slack, and in a limited US beta, text it from your phone. It can also hop on voice calls when you want to talk something through, though at launch it cannot initiate calls to you.
The defining difference from ChatGPT is initiative and continuity. A regular conversation ends when you close it; a dot keeps context for as long as it exists, receives and contributes to your ChatGPT memories, learns your preferences from feedback, and works on multiple projects in parallel while you keep tossing it new ones — no juggling threads, no re-explaining. TechCrunch called the launch avatar-forward and bubbly; underneath the pet picker is the most aggressive productization of long-horizon agent research any lab has shipped.
How a dot works under the hood
Every dot gets its own cloud computer — a sandboxed workspace running a maintained Linux system with a Chrome browser — where it browses, analyzes information, creates files, and runs tools. You can open that computer at any time and watch. The sandbox does real security work: code and tools are restricted inside the workspace, each user's environment is isolated from others, and the systems that coordinate a dot's work and enforce its safeguards live outside anything the dot can touch — so a mistake, or a malicious instruction it encounters, cannot switch off its own checks.
Credentials get special handling. For supported sign-ins, the model is literally paused while you complete a secure login form; your password goes directly to the browser environment without ever entering the model's context. Saved passwords flow through a dedicated encrypted credential service the same way, so a dot can work inside accounts you have authorized while the secret itself stays invisible to the model — though OpenAI is explicit that a password you paste into a chat or document gets no such protection. Optionally, you can connect your own computer from the desktop app: access starts off, requires an explicit Allow, is revocable at any time, and unlocks local files, local coding tools, Work and Codex tasks, and even your local browser when the dot's cloud browser is blocked by a site.
What you can actually do with a dot
The launch material and help docs sketch the delegation surface concretely. Recurring operations: ask it to review your calendar every morning and brief you, run scheduled checks, or set reminders — scheduled tasks live in the dot's profile under Scheduled, alongside In progress and Completed. Research: it follows developing stories and prepares drafts, gathers options for a trip, or digs through connected sources; a newsletter draft tracking a story over days is OpenAI's own example. Communication: connect your personal email and it can draft and, with approval, send; OpenAI's favorite launch anecdote is the early tester whose dot noticed an un-invoiced publication, pulled the details from the email thread, drafted the invoice, and sent the PDF after he approved it.

For technical work, dots compose with the rest of the stack: they can create and manage Codex tasks — including in Codex cloud environments you have set up — turn a design into a working app, or investigate a bug the moment it appears in Slack, all patterns OpenAI says are daily reality internally. Dots can even complete purchases using cards you have already saved on a merchant's site, gated behind your approval. Attach files or photos with the + button mid-conversation and the dot works with them like any collaborator would.
Proactive research: help before you ask
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
The feature that makes 'always-on' literal is proactive research: when you are not engaged, your dot scans the apps you have connected, looking for ways to be useful — a changed travel plan, an unanswered thread — and saves private notes to itself. OpenAI enforces the boundary in code, not just policy: proactive research tools are read-only and cannot send messages, change content in connected apps, or control a browser or computer. Anything the dot wants to do about a finding must cross back into active work, where the normal action rules apply.
The training story here is nuanced and worth knowing. OpenAI does not train models directly on background research threads or the notes they produce. But if your dot later brings a note into an eligible conversation — its Lisbon research surfacing when you ask for trip help — that surfaced context may be used for training depending on your settings. Business, Enterprise, and Edu workspace content is excluded from training by default; personal plans control this with the 'Improve the model for everyone' toggle.
The control system: Custom Rules, Auto-review and handbacks
Dots ship with tiered defaults for action. The most sensitive steps — changing a password, transferring money between accounts — are never delegated: the dot hands them back to you, and no rule can change that. A second tier requires confirmation each time: permanently deleting data, installing software from an unrecognized source, granting new security-sensitive access. Sharing personal information is graduated by sensitivity — health data always requires a named recipient ('share my medical history with Dr. Thompson'), while less sensitive details like an email address default to requiring a class of recipient ('any airline'). Custom Rules let you tune everything else across four behaviors: take action without asking, take action if pre-approved, ask before acting, or hand off entirely — and your dot can help draft rules but needs your approval to change them.
Before consequential actions run, a separate system called Auto-review checks the planned step against your instructions, your rules, and OpenAI's safety requirements — for an email, that means checking the recipient and content for a wrong address or something you did not mean to share. Blocked steps bounce back to the dot with the reason, and it can seek clarification, try a permitted alternative, or stop; your approval cannot override core requirements. Above all of it sits live safety monitoring that watches for behavior like acting outside instructions — including prompt-injection attempts hidden in webpages and emails — and can pause the work with a warning for you to review. Activity View shows every ongoing and delegated task, and the ••• menu on the dot's profile offers Pause and a full Reset.
Setting up your first dot, step by step
Creation is desktop-only for now: use the ChatGPT desktop app (Windows included) or desktop web, follow the onboarding, name your dot, and pick its look. Connect apps under Customize → Plugins — permissions are shared with your existing ChatGPT, ChatGPT Work, and Codex plugin settings, so anything you have already connected is available within the permissions you granted. Messaging channels like Slack, and the texting beta where offered, are wired up from desktop. After creation, you can talk to your dot from the ChatGPT mobile app, but you cannot create one on mobile, and mobile web is not supported. Dots are not available to users under 18.
Two memory behaviors are worth configuring consciously. Your dot receives memories and recent conversation context from ChatGPT, and its conversations feed ChatGPT memory in return — turning Memory off stops the sharing but does not claw back what the dot already knows. And a dot's own accumulated context cannot be viewed or edited item by item: the only way to clear it is Reset, which deletes the dot, its conversations, saved memories, and scheduled tasks — while files, Codex threads, and ChatGPT conversations it created survive separately. Its context never retains credentials, images, or screenshots.
Availability, pricing and current limits
Rollout started September 29 and reaches accounts gradually over days. Pro subscribers get dots in markets excluding the European Economic Area, Switzerland, and the UK; Business Premium covers all supported ChatGPT regions; Enterprise, Edu, and Healthcare workspaces get a beta that admins must enable — it ships off by default. Your first dot is included in a Pro or Business Premium plan at no extra cost, and for the first month dots usage does not count toward plan allowances at all, with per-plan usage terms to be announced after that window. Two metering details matter: dot conversations do not count against ChatGPT usage limits even after the window, but Codex and ChatGPT Work tasks a dot starts count as usual.
Launch-day gaps to plan around: no standalone email address for your dot (it borrows your connected account), no outbound calls from the dot, texting is a limited third-party-powered beta for US Pro users only, and OpenAI warns plainly that dots still make mistakes and consequential work needs review — mistakes it may be able to undo, like recalling an email or reverting a document edit, but not always.
Where dots go next
OpenAI's stated trajectory: teams of dots working together on your behalf, the ability to add more dots, and scaling each dot by speed or total monthly work — Engadget's launch coverage highlighted multi-dot control as the explicit next step. For organizations, specialist dots are already in preview: agents with their own identities and credentials, IT-provisioned hardware, and deep systems-of-record integrations, piloted hand-in-hand with OpenAI's engineers and manageable through Microsoft Agent 365's governance controls. The competitive framing writes itself — press coverage cast dots as OpenAI's answer to Meta's popular Muse agent — but the deeper contest is over which lab turns long-horizon agent research into trusted infrastructure first.
The honest posture for week one: connect low-stakes apps, leave the approval defaults on, watch Activity View, and let the dot earn scope. OpenAI built an unusually thorough leash — read-only background research, out-of-reach safeguards, mandatory handbacks — and the free-usage month is the sandbox period to learn what an always-on colleague is actually worth to you.
Developer Action Items
- ☐ Diff the official changelog for OpenAI / ChatGPT / Linux before you bump — APIs, defaults, and removed flags only.
- ☐ Install through the vendor's documented channel in staging; keep a one-command rollback and time-box the canary.
- ☐ Grep your repo for old flag names, lockfile pins, and plugin versions that the notes mark as breaking.
- ☐ Prefer the first patch cut over the day-zero tag unless you have a reason to be on the leading edge.
- ☐ If OpenAI did not name a region, plan, or SKU, screenshot the official availability line before you promise it to users.
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
OpenAI Dots: Always-On AI Agents With Their Own Cloud Computer
Read →
OpenAI DevDay 2026: Dots Agents, GPT-6.1 Sol, Codex and 20+ Launches
Read →
GPT-6.1 Sol: OpenAI's Near-Astra Model at One-Fifth the Price
Read →
OpenAI Codex Adds Cloud Environments, Voice CLI and Code Review
Read →
Today's Tech Pulse briefing
Full briefing →
Advertisement