OpenAI used DevDay in San Francisco on September 29, 2026, to introduce Dots, a new kind of AI agent designed to keep working after you close the chat window. The pitch is simple: give a Dot a goal, define its boundaries, connect the apps it needs, and let it advance the job in the background.
That sounds close to an AI assistant, but the important difference is persistence. A Dot is meant to monitor a goal, react when conditions change, and ask for help only when it reaches a decision or permission boundary. Here is what OpenAI Dots can actually do, who can access them, and where the safety questions begin.
What is an OpenAI Dot?
A Dot is an autonomous software agent that runs on its own cloud computer. Instead of answering one prompt and waiting for the next, it can continue a multi-step assignment across connected services. According to Reuters’ report from OpenAI DevDay, Dots use GPT-6 Astra and can draw on Codex and ChatGPT Work for research, document creation, data analysis, and software tasks.
The user still sets the objective and the rules. The Dot handles the routine steps, watches for relevant changes, and reaches out through services such as Slack or Microsoft Teams when it needs information or approval. That makes it closer to a background worker than a conventional chatbot.
What can Dots do?
OpenAI’s examples focus on work that changes over time. A Dot could keep a sales proposal current as customer requirements evolve, or turn a product brief into a working software demo. The useful part is not a single impressive answer. It is the ability to preserve context and continue the workflow without forcing the user to restart it in every session.
That could make Dots useful for research tracking, recurring reports, project coordination, document updates, and coding jobs with several dependent steps. Their GPT-6 Astra foundation also connects the launch to OpenAI’s broader model lineup. Our GPT-6 Astra, Sol, and Luna comparison explains why Astra is positioned for the most demanding work.
Who can use OpenAI Dots?
At launch, Dots are rolling out to ChatGPT Pro, Business, and Enterprise customers, with one Dot available per user initially, according to Axios’ DevDay coverage. OpenAI has not presented them as a general free-tier feature.
Availability is only part of the question. A Dot becomes useful when it can reach the services and files involved in a real task. Organizations will therefore need to decide which connections are permitted and which information should remain outside the agent’s reach.
How permissions and privacy work
OpenAI says users and administrators can create rules that define what a Dot may do and when it must ask for consent. Sensitive actions such as entering passwords or permanently deleting data require explicit approval. Business data is not used to train OpenAI’s models by default, while personal users can opt out of training.
Those controls matter because persistence increases both usefulness and risk. A mistaken chatbot response is usually contained to one conversation. A mistaken agent action can propagate through files, messages, or connected systems. The same issue appears in other autonomous tools, which is why our guide to AI agent permissions and NVIDIA’s security recommendations emphasizes least-privilege access.
Prompt injection is another concern. A malicious instruction hidden in a page or document could try to redirect an agent that is collecting information. The practical defenses in our prompt injection explainer are especially relevant when an agent can take actions instead of merely generating text.
What remains unproven
The DevDay demonstration reportedly included delays and glitches. That does not invalidate the concept, but it is a reminder that autonomous agents are harder to evaluate than chatbots. Reliability must be measured across an entire workflow, including recovery from errors, permission requests, app failures, and unexpected changes.
OpenAI Dots are therefore best understood as an early shift in how people may use ChatGPT: less constant prompting, more goal setting and supervision. The biggest test will not be whether a Dot can complete a polished demo. It will be whether users can trust one to keep working accurately, transparently, and within the limits they set.
