OpenAI used DevDay in San Francisco on Sept. 29 to introduce Dots, an always-on agent inside ChatGPT that can keep working toward a user’s goal after the user stops typing. In OpenAI’s help documentation, a dot is described as a GPT-6 Astra-powered agent with its own cloud computer that can work across connected apps, Codex, and ChatGPT Work to research, analyze data, prepare documents, and build software. The product matters because it moves ChatGPT from answering requests to holding delegated responsibility.
The practical question is the one buyers, admins, and ordinary professionals will ask before the demo glow wears off: can an agent do useful work between messages without turning ordinary ChatGPT permissions into a new class of privacy, security, review, and cost-control problem? So far, OpenAI has shipped the beginnings of a governed answer — user-set boundaries, approvals, pause and reset, limited availability, and an Enterprise beta that starts off — but not yet the full operating manual that businesses will want before they treat Dots as workflow infrastructure.
From prompts to permissioned continuity
What OpenAI is selling here is not just a better reply. It is continuity. A dot can keep researching in the background, review connected information proactively, run scheduled reminders or recurring checks, and form memories from ChatGPT and connected apps. Users set a goal and boundaries; the dot can continue in the background, ask for judgment when needed, and surface work under In Progress, Scheduled, and Completed. AP and Axios reported that one dot per user is the initial product shape.
That is a real product shift. A chatbot waits for the next prompt. An always-on agent is expected to decide what to do next, use tools, and come back later with work finished or at least advanced. For knowledge workers, the attraction is obvious: recurring research, data preparation, document drafting, or software tasks are often interrupted, multi-step, and repetitive in the same places. A persistent agent with memory and scheduling can attack exactly that terrain.
It also changes the failure mode. A prompt that goes wrong usually produces a bad answer. A persistent agent can keep going with a stale goal, mistaken assumption, or overly broad permission. That makes the interface details unusually important. Dots has a separate cloud computer, which creates a clearer boundary than assuming default access to a user’s machine. Local-computer access is optional, off by default, and requires the user to connect a desktop computer and confirm access. Even outward communication is being rationed: texting is a limited beta through a third-party provider for some U.S. Pro users and is not available in Business or Enterprise workspaces at launch.
Both the Associated Press and Axios described Dots as OpenAI’s answer to Meta’s Muse. The contrast is less about branding than distribution. Meta’s approach has been aimed at broad consumer reach. OpenAI is starting with paid users and businesses: Pro users in supported markets outside the European Economic Area, Switzerland, and the U.K.; Business Premium across supported regions; and an administrator-enabled Enterprise beta that is initially off by default. That is a smaller launch, but potentially a more governable one.
What OpenAI is trying to control
The most interesting part of the launch is not the list of tasks. It is the permission model. OpenAI says users can define custom rules for sharing, purchasing, or access, with options to let a dot act without asking, act if pre-approved, ask before taking action, or hand off to the user. Those modes acknowledge the central problem of persistent agents: the system must know when to move and when to stop.
That matters more than benchmark talk because Dots shared DevDay with other developer products, including GPT-6.1 Sol, while landing a day after OpenAI decided to hold back GPT-6.1 Astra because researchers raised concerns about model behavior and security. According to AP, Sam Altman said at DevDay that the company had done additional safety, security, and monitoring work for agents. That chronology does not prove Dots is risky, but it does raise the bar for traceability. If a company is going to let an agent keep working after the conversation ends, it has to show not just that the agent is capable, but that its actions can be inspected, bounded, and interrupted.
OpenAI has clearly thought about that user experience. A dot can be paused. It can also be reset, which deletes the dot’s conversations, saved memories, and scheduled tasks. The product surfaces active and completed work instead of hiding background activity. Those are sensible controls for early deployment, especially in a gradual rollout where the first dot is included on eligible plans and access expands over time.
But the limits of those controls matter too. Resetting a dot’s state is not the same as reversing an external action already taken in a connected app. A user boundary is also not a technical guarantee if the underlying permissions are broader than the task really needs. And AP reported lag during a live Dots demonstration, a small but useful reminder that persistent software still inherits ordinary agent brittleness.
The missing layer is reconstruction
The clearest gap in the public material is not capability. It is reconstructability. OpenAI’s public documentation does not fully spell out data retention, administrator audit logs, app-specific permission granularity, cross-tenant isolation, model and tool activity logs, or how a user or admin can replay every meaningful action after something goes wrong. For business buyers, that is the difference between a clever assistant and an auditable system.
The same is true for cost and operations. OpenAI has not yet laid out independent failure rates for long-running tasks, incident rates, or evaluation results showing how well Dots holds up as jobs stretch across time and tools. It is also still unclear how usage will be measured after the initial launch allowances, what long-term rate limits will look like, how many simultaneous tasks a dot can run, how often it polls or acts without a fresh user message, and which actions always require confirmation. Those are not edge questions. They determine whether an IT team can set budget guardrails, whether a security team can enforce least privilege, and whether a manager can tell who owns a scheduled task when the human who started it goes on vacation or changes roles.
That leaves Dots in a promising but not yet settled category. The product looks most useful where goals are bounded, tools are permissioned narrowly, and a human is still close enough to review ambiguous moments: recurring research, data prep, document assembly, and code work inside known environments. It looks least ready to be treated as invisible infrastructure that can wander across connected systems without strong logging and approval design.
OpenAI’s launch strategy suggests the company knows this. Dots is not being pushed as a global, default feature with unlimited reach. It is being staged through paid tiers, regional limits, admin gates, optional local access, and explicit pause and reset controls. That is a responsible shape for an experiment in delegated continuity. The unresolved business question is whether OpenAI can turn that caution into a durable operating model — one where a user can see what the dot saw, what it did, what it was allowed to do, what it cost, and how to unwind mistakes. If that layer arrives, Dots could become a meaningful new unit of AI work. If it does not, many organizations will keep the feature impressive, but behind approval gates.




By
By


By
By
By
By







