OpenAI launches dots as always-on agents

OpenAI published Introducing dots on 29 September 2026. Dots are always-on agents powered by GPT-6 Astra. Each dot gets its own cloud computer, can keep working between conversations, and connects through ChatGPT plugins to more than 4,000 apps, OpenAI says.

A companion post, How we build safety, security, and privacy into dots, explains Auto-review, Custom Rules, proactive research limits and training defaults.

Pro and Business Premium in eligible markets first

Dots are rolling out the same day in ChatGPT to Pro and Business Premium users in eligible markets. Enterprise users, including Edu and Healthcare, can try the beta when a workspace admin enables it. OpenAI says it plans to expand to more users soon. Eligible-market detail sits behind a help-center link in the post.

Your first dot is included in Pro or Business Premium at no extra cost. The plan includes an allowance for deeper work, with extended limits for the first month after launch. Conversations with a dot do not count toward ChatGPT usage limits. Tasks a dot starts or manages in Codex or ChatGPT Work still count toward those limits as usual.

Users can message dots in ChatGPT on desktop, web and mobile, and in Slack and Teams. Texting is described as coming soon. Specialist dots for organizations are in focused enterprise pilots, with a stated Microsoft Agent 365 governance path.

Cloud computer, Auto-review and read-only proactive research

OpenAI says each dot runs on its own cloud computer and browser. You can open that computer to inspect work, and you can optionally connect a personal laptop. Dots carry context across ChatGPT, Slack and Teams.

Control surfaces named in the posts:

  • App access uses existing ChatGPT app and plugin controls.
  • Custom Rules let you allow, require approval for, or block specific actions. Built-in safety requirements still apply.
  • Auto-review is a separate check before actions that could affect accounts or share information. Sensitive steps such as changing a password stay with the user.
  • Proactive research runs in the background with read-only tools. OpenAI says those research tasks cannot send messages, change app content, or control a browser or computer. Follow-up actions must still pass the usual rules and checks.
  • For supported sign-ins, dots can use saved passwords without putting them in the model context.

OpenAI says it does not use ChatGPT Business, Enterprise or Edu workspace content to improve models by default. On personal plans, the "Improve the model for everyone" setting controls training on dots' conversations and work. The company says it does not train directly on proactive research threads or a dot's notes to itself.

Eligible markets, admin gates and mistake risk remain

Eligible markets are not listed in the main post body. Enterprise access needs an admin enablement. Specialist dots remain enterprise pilots without a general SKU in the posts. OpenAI states that dots can still make mistakes and that consequential work should be reviewed.

The launch posts do not publish a separate per-dot price beyond the plan inclusion and deeper-work allowance. Future add-on dots and speed or monthly-output scaling are described as later options.

Compare this product shape with OpenAI's Introducing the Agents API post and Frontier's Agents API public beta notes. Also compare NVIDIA's Open Agent Safety Platform and OpenShell if you buy agent runtime controls.

Set Custom Rules before connecting mail apps

If your workspace is on Pro or Business Premium in an eligible market, create the first dot in the ChatGPT desktop app or desktop browser. Review plugin permissions before connecting mail, calendar, CRM or payment tools.

Write Custom Rules for send, share, purchase and delete before you give the dot broad app access. Keep password changes and money transfers as human steps. For Enterprise, decide whether the admin enables the beta and whether specialist-dot pilots belong in procurement or support first.

Treat sandbox and tool isolation as a live risk class, the same way OpenAI's DNS sandbox escape pause already does for training and tool-use inference.