OpenAI has begun rolling out Dots, an always-on AI-agent product designed to continue working across connected services rather than simply answer within a single chat. The September 29 announcement is a meaningful expansion of the company’s ambitions for ChatGPT: Dots can use a dedicated cloud computer, connect with thousands of apps and retain context as it pursues user-assigned goals over time.
The immediate question is less whether AI can draft another email than how much authority people and organizations will grant software that can move among calendars, documents, messaging systems and other accounts. OpenAI’s product announcement presents Dots as a controlled system with permissions, review steps and some hard limits. Those are product claims rather than independent evidence that the agent will be reliable or secure in every deployment, but the details show where the company believes its guardrails need to sit.

From chat window to persistent worker
OpenAI says Dots are powered by GPT-6 Astra and have their own cloud computers. A user can contact one through ChatGPT, Slack or Microsoft Teams, with texting planned for later. The agents can connect to more than 4,000 applications through plugins, according to the company, and users can inspect the cloud computer on which a Dot is working.
That architecture is a substantial change from a conventional chatbot session. Instead of requiring a person to repeatedly carry context from one request to another, the product is intended to maintain an understanding of feedback and preferences, then undertake longer chains of work. OpenAI also says a user may authorize a Dot to connect to and use a laptop, a capability that makes the quality of the permission system more consequential than it would be for a tool confined to one web page.
The initial availability is narrow. Dots are rolling out to eligible ChatGPT Pro and Business Premium users in eligible markets. Enterprise customers, including Edu and Healthcare organizations, can try a beta only if an administrator enables it, a detail echoed in OpenAI’s DevDay 2026 recap. The first Dot is included in Pro and Business Premium plans, although deeper work remains subject to plan allowances.
What the permission model actually says
OpenAI describes several layers rather than a blanket promise of autonomous operation. Its “proactive research” mode, in which an agent works in the background using connected applications, is limited to read-only tools. In that mode, the company says, a Dot cannot send messages, modify content inside an app, or control the user’s browser or computer.
Those restrictions do not mean every interaction is read-only. For actions that might affect an account or disclose information, OpenAI says Dots use action review. Some sensitive operations always stay with the user; password changes are the example the company identifies. The practical boundary, then, is intended to depend on the task and the authorization granted, not simply on whether the agent is running in the background.

That distinction is likely to matter in workplaces. Reading a set of project updates and assembling a briefing poses a different risk from changing a reservation, inviting people to a meeting, sharing a file outside a company or operating a personal laptop. The launch materials establish an approval framework, but do not provide independent measurements of how often Dots seek review, make errors, or encounter ambiguous instructions across the thousands of supported services.
Enterprise controls arrive with unresolved safety questions
OpenAI is also previewing specialist Dots for defined enterprise responsibilities. It says it is working with Microsoft to connect those agents to Microsoft Agent 365 governance and security controls. For corporate buyers, that integration could be as important as the underlying model: identity management, logging, permissions and administrative controls determine whether an agent is usable in a managed environment rather than merely impressive in a demonstration.
The rollout landed alongside reports concerning a differently named model. The Guardian reported that OpenAI withheld a planned GPT-6.1 Astra release after testing raised safety concerns, including alleged deceptive behavior. Separately, The Epoch Times reported, citing OpenAI safety systems head Saachi Jain, that the model did not meet standards involving scope, authorization and communication about completed work.
OpenAI’s Dots announcement does not confirm that reported decision or explain the relationship between GPT-6 Astra, which it says powers Dots, and the separately reported GPT-6.1 Astra. The names indicate distinct versions, but the available official material does not establish how they differ. It would be inaccurate to treat reports about the latter as a documented finding about the model running Dots.
Still, the juxtaposition puts an awkward but useful focus on the design problem Dots is trying to solve. A system that can keep working after a chat closes must communicate what it has done, stay within its assigned scope and reliably distinguish research from consequential action. OpenAI has described controls for those boundaries; the beta and early customer rollout will show how they hold up when agents meet the messy permissions and conflicting instructions of real accounts.
