↓ Skip to main content
9 – 17 UHR +49 8031 3508270 LUITPOLDSTR. 9, 83022 ROSENHEIM
DE / EN

OpenAI dots: What Always-On Agents Mean for Your Company

Tobias Jonas Tobias Jonas | | 12 min read

Key facts (as of 30 September 2026):

  • OpenAI introduced dots at DevDay on 29 September 2026: always-on agents in ChatGPT based on GPT-6 Astra, each with its own cloud computer and browser, connected to more than 4,000 apps through plugins, reachable via ChatGPT, Slack and Microsoft Teams.
  • One dot is included in ChatGPT Pro and Business Premium. Pro users in the EEA, Switzerland and the UK do not get a dot for now; Business Premium rolls out in all supported regions, Enterprise gets a beta that administrators must enable.
  • The permission model is the most interesting part: Custom Rules in four levels, an auto-review before critical actions, mandatory hand-offs to the human for passwords and money transfers, local computer access off by default. OpenAI itself writes that its prompt-injection protection is not perfect.
  • For companies dots mean: agents now need an identity, rules and a cost frame before employees use them day to day. Anyone who wants to keep control inside their own tenant needs their own AI stack.

Until Monday, an AI agent was something you start. You give Codex or Claude Code a task, the agent works, delivers, the session ends. Since Tuesday OpenAI has been selling something different: an agent that does not end. A dot has its own computer in the cloud, its own memory, access to your connected applications and the mandate to keep working on your goals while you sleep.

A chatbot waits for your question. A dot waits for nobody.

That is a bigger step than the colourful bubbles in the presentation suggest. This article explains what dots are technically, how OpenAI puts them on a leash, why Europe is only partly included at launch and what a company should settle before the first dot shows up in a team.

What OpenAI announced on 29 September

dots were the biggest announcement of DevDay 2026, alongside more than 20 other items such as the GPT-6.1 Sol model, an Agents API in public beta with hosted execution and multi-agent support, Codex Cloud and a security scanner for repositories. The facts on dots as OpenAI describes them in the announcement and its help centre:

Each dot runs on GPT-6 Astra, the model OpenAI released in early September. It gets its own cloud computer with its own browser. Through the ChatGPT plugin ecosystem it connects to more than 4,000 applications, and it shares those connections with ChatGPT and Codex. A dot can be reached through ChatGPT on desktop, web and mobile, by voice call, in Slack and in Microsoft Teams. Texting follows first as a limited beta for Pro users in the US.

A dot takes on assignments, works on several projects in parallel, learns from feedback and takes over recurring checks and reminders. When it has no task, it performs proactive research across the connected tools, read-only. OpenAI cites internal examples of a dot that investigates bugs reported in Slack on its own, builds apps from design files or tracks down unbilled invoices. One early tester describes how his dot spotted an invoice due from an email thread, prepared the draft and sent it as a PDF after approval.

The first dot is included in ChatGPT Pro and Business Premium at no extra cost. In the first month after launch, usage does not count toward plan allowances; after that OpenAI intends to publish terms per plan. Conversations with the dot do not count toward usage limits, tasks via Codex and ChatGPT Work do. Additional dots per user and, as the stated vision, teams of dots working together are announced for later. For enterprises there is also a preview of Specialist dots with their own identity, credentials and access to company systems; an integration with Microsoft Agent 365 is planned.

Technically, little of this is new. What OpenAI bundles here was already possible with Codex and comparable harnesses. What is new is the packaging: a permanent colleague instead of a tool you invoke.

From tool to colleague with a desk of its own

In our last article we compared an agent to a new employee who lacks everything on day one: access, tools, rules, supervision. OpenAI now follows that analogy through. A dot gets its own workplace in the cloud, a memory fed from ChatGPT, and the freedom to find work for itself.

That last point changes the risk calculation. An agent that works on request makes mistakes while someone is watching. An agent that researches at night and presents proposals in the morning makes mistakes while nobody is watching. So the question is no longer what the model can do. The question is which leash OpenAI puts on the dot, and whether that leash is long enough, or short enough, for your organisation.

On memory, the help centre states: the memories of an individual dot cannot currently be viewed or edited. Anyone who wants to delete the context deletes the dot. Conversations with the dot in turn feed into ChatGPT memory as long as the memory setting is on.

The leash: how OpenAI regulates permissions and approvals

For decision-makers the permission model is the most important part of the announcement, and it is pleasingly concrete. OpenAI describes five mechanisms:

Custom Rules in four levels. For each kind of action the user decides whether the dot acts without asking, acts only if the action was pre-approved, asks before acting, or hands the task over to the human entirely.

Auto-review. Before a dot does anything that affects accounts or shares information, a control system checks the planned step against the user’s instructions, their rules and OpenAI’s safety requirements. According to the FAQ, before sending an email the recipient and the message are checked.

Mandatory hand-offs. Password changes and money transfers are always carried out by the human. Permanent deletion and installing unknown software require confirmation. Card purchases can be approved in advance if they are described specifically enough.

Secure sign-in. For supported services the user enters credentials in a separate form without the model seeing them. A password typed into the chat is not covered by that protection.

Separate environments. The dot works on its cloud computer. Access to your own laptop is optional, off by default and must be explicitly confirmed in the desktop app. A monitoring system can pause dots when it detects safety concerns.

At its core this is the architecture we have been recommending for months: guardrails belong in the infrastructure, not in the prompt. A prompt is a request, a rule is a boundary. That OpenAI builds the boundaries as a product feature confirms the approach.

OpenAI is honest about the limits, too: according to the help centre, prompt-injection protection exists but is not perfect, and mistakes remain possible. A dot that reads mail, researches on the web and is allowed to send email combines exactly the three properties that make an agent attackable: access to internal data, contact with external content and a channel to the outside. The four rule levels are therefore not a convenience feature but the most important setting a company has to decide before rollout.

The context: two incidents in the week before launch

The announcement landed in a week in which OpenAI itself disclosed two incidents involving its own agents. Both concerned internal research models, not the dots product, and both show why the leash matters.

On 25 September OpenAI said that research agents had posted 53 images uploaded by users to external image hosts as unlisted but publicly reachable links. According to OpenAI the images came exclusively from accounts that had not opted out of model training; most files have since been taken down. The day before DevDay, OpenAI also apologised for an internal model that on 18 June, while researching public medicine spending, got past bot protections on an Australian health-statistics portal, entered areas that had not been authorised and wrote files to a server, according to OpenAI and the Australian government. No patient data was affected, OpenAI says. Australia’s prime minister publicly criticised that notification took around three months.

Add to that a decision OpenAI communicated at DevDay itself: the GPT-6.1 Astra planned for October will not ship because it did not pass the company’s own safety tests. dots therefore run on GPT-6 Astra, released in September.

We do not mention this to show OpenAI up. The company disclosed the incidents itself and withheld the model itself. We mention it because it confirms the lesson from our last article with the weight of the vendor: an agent with internet access, internal data and write permissions finds paths nobody planned for. Anyone operating such agents needs boundaries that hold even when the model gets creative.

Europe: who gets dots and who waits

For readers in Germany, Austria and Switzerland, availability is the first practical question. OpenAI writes that Pro users in the European Economic Area, Switzerland and the United Kingdom do not get a dot for now. Business Premium rolls out in all supported ChatGPT regions, and Enterprise, Edu and Healthcare customers get a beta that an administrator must enable and that is off by default. Users under 18 are excluded. OpenAI gives no reasons for the Pro restriction. According to NBC News, Sam Altman spoke in general terms of longer and less predictable procedures in the EU.

OpenAI is not alone in this decision: Meta’s agent Muse launched in the US only, and Apple is holding back its revamped Siri on iPhone and iPad in the EU. A spokesperson for the European Commission clarified that nothing in the Digital Markets Act prevents a launch and that the decision rests with the vendors alone.

Regardless of availability, three legal points apply to use in a company. They do not replace legal advice, but they belong on the table before rollout:

First, the legal basis. A dot continuously processes email, calendar and the content of connected apps. Under the GDPR each of these processing activities needs a legal basis and a defined purpose. Proactive research, where the agent itself decides what to look at, is hard to reconcile with purpose limitation if nobody has set the frame.

Second, data use. In ChatGPT Business, Enterprise and Edu, content is not used for training by default according to OpenAI; on personal plans the model-training setting decides. For safety reasons there may be limited human review. Anyone who uses dots privately and connects company mail bypasses every corporate rule. Shadow AI gets a new dimension with dots.

Third, transparency. A dot that sends messages or creates invoices on behalf of an employee acts toward the outside world. The EU AI Act requires transparency toward the people affected when they interact with AI systems. A customer corresponding with a dot should know.

What dots mean for your company

Whether a dot shows up in your company is only partly your decision. As soon as Business Premium licences are in the building, it shows up. Three things should be settled first.

Agents need an identity. OpenAI’s Specialist dots with their own credentials and Microsoft’s Agent 365 with agent identities in Entra show where this is heading: an agent is a principal in the directory, with its own rights, its own lifecycle and its own log. An agent working with an employee’s credentials is indistinguishable from that employee in an audit. Anyone running Entra ID or Keycloak today should look now at how agent identities are modelled there.

Agents need a cost frame. A dot that works around the clock consumes compute around the clock. In the first month that is free according to OpenAI; after that usage counts toward plan allowances whose terms are still to come. Agent time thus becomes a resource somebody has to budget and assign to a cost centre. dots run in OpenAI’s cloud and cannot be routed through your own gateway; what companies see is OpenAI’s billing. For the tools that do run through your infrastructure, meaning Codex, Claude Code or OpenCode on developer machines, our AI Gateway with its companion measures how much agent time and model time each project and cost centre causes, even on subscriptions.

Agents need a place. The real decision is where your agents should live. dots live at OpenAI, with a permission model OpenAI defines and a memory you cannot inspect. For many tasks that is fine. For processes involving customer data, core systems and write permissions, a company needs agents in its own tenant, with identity from its own directory, guardrails in its own infrastructure and a log its own data protection officer can read. That is exactly what we build CompanyGPT for, as your own AI stack, operated in your Azure tenant or sovereignly on STACKIT, with the AI Gateway as the control point in front of it. Anyone who prefers to run agents entirely themselves will find the open-source route in our guide to the OpenClaw ecosystem.

What you should do now

Three steps that should be done before the first dot, whether it enters the company via Business Premium, an Enterprise beta or an employee’s private account:

  1. Rules before rollout. Translate your approval processes into the four levels of Custom Rules: what may an agent do without asking, what only with prior approval, what never. Start with sending email, calendar changes and anything that moves money.
  2. Inventory your connectors. Which applications are already connected in ChatGPT, with which permissions? A dot inherits those connections. What an employee approved for chat today is available tomorrow to an agent that researches at night.
  3. Decide your own path. Determine which tasks an agent may complete at the vendor and which must stay in your own tenant. That boundary is the most important architecture decision of the next twelve months, and it cannot be written into a prompt afterwards.

dots are not the moment agents become powerful. They are the moment agents become ordinary. Whoever sets the rules now decides what that looks like.

Sources

All statements about dots reflect OpenAI’s documentation as of 30 September 2026. Features, availability and terms may change.

Further reading


Which tasks do you want to entrust to an agent, and where should it live while doing them? We help you define the rules before the first dot shows up in your team. Get in touch.

Tobias Jonas
Written by

Tobias Jonas

Co-CEO, M.Sc.

Tobias Jonas, M.Sc. ist Mitgründer und Co-CEO der innFactory AI Consulting GmbH. Er ist ein führender Innovator im Bereich Künstliche Intelligenz und Cloud Computing. Als Co-Founder der innFactory GmbH hat er hunderte KI- und Cloud-Projekte erfolgreich geleitet und das Unternehmen als wichtigen Akteur im deutschen IT-Sektor etabliert. Dabei ist Tobias immer am Puls der Zeit: Er erkannte früh das Potenzial von KI Agenten und veranstaltete dazu eines der ersten Meetups in Deutschland. Zudem wies er bereits im ersten Monat nach Veröffentlichung auf das MCP Protokoll hin und informierte seine Follower am Gründungstag über die Agentic AI Foundation. Neben seinen Geschäftsführerrollen engagiert sich Tobias Jonas in verschiedenen Fach- und Wirtschaftsverbänden, darunter der KI Bundesverband und der Digitalausschuss der IHK München und Oberbayern, und leitet praxisorientierte KI- und Cloudprojekte an der Technischen Hochschule Rosenheim. Als Keynote Speaker teilt er seine Expertise zu KI und vermittelt komplexe technologische Konzepte verständlich.

LinkedIn