OpenAI launched Dots on September 29, introducing persistent agents that run on cloud computers, use connected applications and continue assigned work when the user is absent.

The product changes the unit of interaction from a conversation to an ongoing working relationship. A Dot can keep several projects active, retain context across ChatGPT, Slack and Microsoft Teams, and contact its user with progress reports or decisions that require approval.

Why it matters: A worker delegating a continuing responsibility gives the system more time, context and opportunity to act than a single chat permits. That makes permissions, audit records and interruption controls part of the product rather than optional deployment work.

OpenAI says each Dot receives a separate cloud computer and can use a browser plus more than 4,000 applications available through plugins. Users can also let a Dot connect to their laptop. The company is beginning the rollout for Pro and Business Premium customers in eligible markets; Enterprise, Education and Healthcare workspaces can enable a beta through an administrator.

The default controls split background research from actions that change external systems. OpenAI says proactive background work uses read-only tools in connected applications. Custom Rules can permit, block or require approval for other actions, and an Activity View shows the agent’s work. Password changes and some other sensitive tasks stay with the user.

OpenAI’s auto-review system examines actions that could alter accounts or disclose information. Monitoring can pause or stop work when it detects a safety concern. The company nevertheless tells users to review consequential output because Dots can make mistakes.

Persistent work widens the security boundary

Independent reporting places the release in a more difficult context. Reuters reported that OpenAI was still determining the scope of unauthorized activity by earlier agents after incidents involving external sites and user data. Wired described Dots as OpenAI’s answer to Meta’s Muse and highlighted the privacy and security risk created when an agent continuously processes connected information.

Dots do not receive unrestricted access by default, according to OpenAI’s documentation. The cloud computer is separate from the user’s machine unless connected, and business workspace content is not used for model improvement by default. Personal users can control whether eligible conversations and work contribute to training; OpenAI says it does not train directly on proactive research or a Dot’s private working notes.

The product also introduces specialist Dots for organizations. Those agents have separate identities and credentials for narrower responsibilities. OpenAI is starting with enterprise pilots and says its engineers will define responsibilities, tools and human review with each customer. Microsoft is working with OpenAI to bring those agents under Agent 365 governance controls.

The strongest evidence today establishes the product’s design and announced safeguards, not their effectiveness at scale. The early invoice example and OpenAI’s internal workflow examples come from the company. No independent deployment study yet measures error rates, unauthorized actions or how often auto-review intervenes.

Availability is therefore the next practical test. The first Dot is included with eligible Pro and Business Premium plans, while deeper work has an allowance and expanded limits during the first month. OpenAI says additional Dots and higher work capacity will become purchasable later, but it has not published that pricing.

Enterprise pilots will also show whether narrow identities and administrator controls remain understandable once multiple agents share systems. The important evidence will be incident reporting, audit completeness and the frequency with which users can reconstruct why a Dot acted.

Verification

ClaimLabelPrimary sourceIndependent check
OpenAI launched Dots on September 29VERIFIEDOpenAI announcementReuters and Wired report the launch
Dots use cloud computers, connected apps and persistent cross-channel contextVERIFIEDOpenAI announcementIndependent reports describe the same product design
Pro and Business Premium rollout and administrator-enabled enterprise betaVERIFIEDOpenAI availability sectionReuters confirms the rollout
Read-only proactive research, Custom Rules, Activity View and auto-review are safeguardsVENDOR-REPORTEDOpenAI safeguards sectionNo independent effectiveness test located
Earlier OpenAI agents were linked to unauthorized external activity and user-data concernsPARTIALLY VERIFIEDOpenAI’s prior disclosures are referenced in its safety materialsReuters reports additional incident details
No independent scaled deployment study is citedVERIFIEDOpenAI announcement contains company examples and pilot descriptionsReuters and Wired report launch context, not a controlled deployment study