Most AI tools still wait for you to ask them to do something. You open ChatGPT, explain what you need, get an answer or hand over a task, and come back when you need something else. OpenAI Dots change that relationship. Introduced at DevDay on 29 September 2026, Dots are always-on AI agents powered by GPT-6 Astra. 

They have their own cloud computers, can connect to more than 4,000 apps through plugins and, most importantly, can keep working towards ongoing goals between conversations. That last part is what separates Dots from the ChatGPT most people already know. You aren't simply giving an AI a bigger task. 

em360tech image

You're giving it something closer to an ongoing responsibility, which raises an obvious question: what does an AI agent actually do when you're not talking to it?

What Are OpenAI Dots?

An OpenAI Dot is a persistent AI agent in ChatGPT that can remember context, use connected tools and continue working towards a goal without needing you to start a new conversation every time. Each Dot has its own cloud computer, browser and access to the apps you choose to connect. 

Think about the difference between asking ChatGPT to analyse this month's customer feedback and giving a Dot responsibility for keeping track of customer feedback over time. The first has a clear beginning and end. The second changes as new information arrives, which means the work doesn't really finish. OpenAI gives similar examples. 

A Dot could keep a sales proposal updated as customer requirements change, investigate a newly reported bug or prepare content when new source material arrives. It can also contact its owner with progress updates, questions or decisions that need human judgement. Users can communicate with Dots through ChatGPT, Slack and Microsoft Teams. 

That persistence is the important part. But “always-on” can also sound rather more autonomous than Dots currently are.

How Do OpenAI Dots Work?

A Dot keeps the context around the work you've given it, rather than treating every interaction as a separate request. You can add new tasks while others are still running, and the agent can decide what needs to happen next as circumstances change. When you're not actively working with it, the Dot can also conduct what OpenAI calls “proactive research”. 

It can check information from connected apps and use what it finds to identify useful work without waiting for another prompt. There is an important limit here. During proactive research, the tools available to the Dot are read-only. 

It can't send someone a message, change information inside a connected app or take control of a browser or computer simply because it decided something needed doing. Its own cloud computer is also separate from your laptop. You can explicitly allow a Dot to connect to your local computer, files and tools, but creating one doesn't automatically give it that access. 

Plugin permissions are shared across Dots, ChatGPT, ChatGPT Work and Codex, so existing connections can be used within the permissions you've already granted. So, “always-on” really describes persistence rather than unlimited autonomy. A Dot can keep paying attention when you aren't there. What it can actually do with what it learns is a separate question.

What Can OpenAI Dots Do Without Your Approval?

OpenAI gives Dots different levels of freedom depending on the action involved. Users decide which apps their Dot can access, while Custom Rules can allow certain actions, require approval or block specific behaviour altogether. Some built-in safety requirements can't be overridden. 

Dots also use Auto-review, which checks certain planned actions against the user's instructions, Custom Rules and OpenAI's safety requirements before they're carried out. If a proposed action fails those checks, the Dot may ask for clarification or approval, find another permitted way to complete the task, hand control back to the user or stop. 

The more consequential the action becomes, the less freedom the Dot has. Purchases and permanent data deletion require approval, for example, while changing a password or transferring money between financial accounts must be handed back to the user. Granting new security-sensitive access also requires confirmation. 

In other words, giving a Dot ongoing responsibility doesn't mean giving it permanent authority to do whatever that responsibility might eventually require.

Who Can Use OpenAI Dots?

OpenAI is rolling Dots out gradually, so access currently depends on both your plan and where you're located. Pro users can access Dots in supported markets, excluding the European Economic Area (EEA), Switzerland and the UK at launch. Business Premium users have access across supported ChatGPT regions. 

Enterprise, Edu and Healthcare organisations can try Dots through the beta, but an administrator must enable access first. Enterprise access is off by default, so an eligible subscription doesn't automatically mean employees can create Dots. That distinction becomes more important once Dots move from individual productivity tools into company systems.

What Do OpenAI Dots Mean for Enterprise AI?

For enterprises, enabling Dots isn't really one decision. Administrators can separately control who can use them and whether they can access capabilities such as local computers, Slack and Microsoft Teams, Custom Rules and other computer functions. OpenAI also notes that existing Enterprise model controls and default model settings don't currently apply to Dots. 

The bigger change may come later. OpenAI is developing specialist Dots designed to hold specific responsibilities inside an organisation. Unlike a personal Dot working on behalf of one person, these agents would have their own identity, credentials and access to company systems. 

Early testing inside OpenAI has covered procurement, invoice processing, email marketing, customer support and commercial contracting. OpenAI is starting with focused enterprise pilots and is working with Microsoft on integrating specialist Dots with Agent 365 governance and security controls. 

That points towards agents being managed less like personal assistants and more like digital workers with defined jobs and access. OpenAI's own safety testing also shows why those boundaries need attention. In one test, Dots encountered 50,000 simulated emails, including 16,600 malicious ones, with no scored successful attacks. 

Another evaluation found a 91.8 per cent alignment pass rate when circumstances or permissions changed during a task. The picture became less tidy as work grew longer. When OpenAI doubled the number of intervening tasks in another test from five to 10, moderate scope violations increased from 8.6 to 19.7 per cent. 

Are you enjoying the content so far?

These weren't severe breaches, but they show how maintaining the right boundaries can become harder as an agent accumulates tasks and context. These are OpenAI's own test results rather than independent validation.

OpenAI Dots vs ChatGPT Work and Meta Muse

ChatGPT Work can already research information, use connected apps and complete multi-step projects. It can even run scheduled tasks. The difference is that Work is primarily built around completing defined work, while a Dot is designed to maintain context and responsibility across work that continues to change. 

Dots can also delegate tasks to ChatGPT Work or Codex, so they shouldn't be understood as replacements for either product. They sit above that kind of task execution as a more persistent layer. Meta's Muse points in a similar direction. Muse can work with personal apps and continue getting things done even when its mobile app is closed. 

The products aren't identical, but their arrival around the same time suggests persistent agents are becoming a broader competitive direction rather than an OpenAI experiment.

What Should Enterprises Check Before Enabling OpenAI Dots?

The practical question isn't simply whether Dots can save employees time. Organisations need to understand what authority sits behind that convenience, particularly when an agent can keep working after the person who assigned the task has moved on to something else. Before enabling Dots, it helps to answer a small set of product-specific questions:

  • Who genuinely needs a Dot, and what ongoing responsibility will it have?
  • Which company systems and data will it be able to access?
  • Where does read access become permission to change something?
  • Does it need access to an employee's local computer?
  • Which actions require human approval?
  • Who reviews its Activity View and ongoing work?
  • Who owns the Dot's permissions when an employee's role changes?
  • How quickly can access be revoked if something goes wrong?

Those answers define what the organisation is actually enabling far better than the label “autonomous AI” ever could.

Final Thoughts: OpenAI Dots Make Persistence the Product

AI agents completing complicated tasks aren't particularly new anymore. What makes OpenAI Dots interesting is the attempt to turn persistence into an everyday part of ChatGPT: an agent that remembers the work, notices new information and keeps responsibility for something even when nobody is actively prompting it. 

Specialist Dots could push that idea considerably further by giving persistent agents their own organisational identities and responsibilities. For enterprises, the useful question may therefore be less about how autonomous these agents are and more about what they're allowed to keep doing when nobody is watching the conversation. 

As that line continues to move, EM360Tech will keep tracking what persistent AI agents mean for the systems, teams and businesses increasingly expected to work alongside them.