OpenAI Gave Its New Agents a Computer and Told Them to Keep Working

OpenAI introduced Dots at its DevDay conference in San Francisco on 29 September 2026. They are always-on agents that run on GPT-6 Astra, and each one gets its own cloud computer and browser. They can connect to more than 4,000 apps through plugins, and they are built to keep working after you close the chat window.
That last detail is the whole point. A chatbot waits. A Dot is designed to continue. Chief executive Sam Altman described it at the event as an AI helper that always has your back, and added that it lets users trust the agent with as much responsibility as they are comfortable handing over. The product design follows from that sentence more than from any model benchmark.
You reach a Dot by messaging or calling it inside ChatGPT on desktop, the web and mobile, or by messaging it in Slack and Microsoft Teams. Text messaging is planned for later. A project that begins in one place carries its context into the next, so a task started in ChatGPT can be continued from Slack without re-explaining anything. The agent can also speak first, sending progress reports, asking questions, and flagging decisions that need a person.
What a Dot is supposed to do
The examples OpenAI gives are deliberately ordinary. A developer's Dot watches customer feedback for recurring bugs, builds fixes, tests them, and prepares pull requests with video of the changes. A scientist's Dot reruns an analysis when new data arrives and updates the figures. A content creator's Dot turns a new interview transcript into clips, show notes and social drafts. Inside OpenAI, the company says Dots are already being tested across software development, procurement, invoice processing, email marketing, customer support and commercial contracting.
One early tester's story has become the canonical illustration. Developer Dan McAteer's Dot noticed he had failed to invoice a publication, pulled the relevant details from the email thread, and drafted the invoice. After he approved it, the Dot sent it as a PDF. Read that carefully and you see the pattern OpenAI is aiming at. The Dot spots the task, does most of the work, and stops one step short of the irreversible action, handing the final move back to a human.
That shape shows up throughout the safety design. A Dot's cloud computer stays separate from the user's own machine unless the user chooses to connect it. Saved passwords for supported sites can be used without exposing them to the model. Background work runs under what OpenAI calls proactive research, where connected apps operate in read-only mode, so a Dot cannot send messages or change content while it is exploring. Background activity cannot take control of a computer at all.
Actions that could affect an account or share information go through an automatic review, which decides whether the Dot can proceed, needs approval, or must hand the task back. Users can write custom rules to allow, block or require approval for specific actions. Some things, including changing a password, always stay with the person. OpenAI's own safety note ends with the line that Dots can still make mistakes, so always review consequential work.
The machine is the new battleground
Three always-on agents reached the public within about seven weeks, and each arrived with the same unusual accessory: a computer of its own. SpaceXAI opened the beta for Grok Bot on 11 August. Meta released Muse in the United States on 8 September. OpenAI introduced Dots on 29 September.
The pattern is not a coincidence. A chatbot answers questions from inside a browser tab. An agent sits down at a machine, opens apps, signs in to accounts, and works through the afternoon while its owner is elsewhere. Once that happens, the question stops being about intelligence and becomes about trust, because the safety of a system holding passwords, calendars and card details depends entirely on the rules around it. OpenAI's answer is a cloud computer per agent plus a stack of approval rules. Meta and SpaceXAI have answered with variations on the same theme.

That reframing is why the benchmark conversation feels a step behind the product conversation right now. Two agents can look equivalent on every published test and behave completely differently the first time one of them decides a task is finished when it is not.
Plans, pricing and the specialist tier
Dots are rolling out to Pro and Business Premium subscribers in supported markets, ineligible markets aside. For Pro users, that excludes the European Economic Area, Switzerland and the United Kingdom for now. Business Premium gets access in all supported ChatGPT regions. The first Dot is included with the plan at no extra charge, and additional Dots will be priced later.
Enterprise, Edu and Healthcare workspaces can try a beta once an administrator enables it. Conversations with a Dot do not count against ChatGPT usage limits, while tasks it starts in Codex or ChatGPT Work do, which is a reasonable way to price the thinking without charging for the chatter.
OpenAI also previewed specialist Dots for companies. These get their own identity, credentials and access to internal systems so they can hold a defined role, and OpenAI says it has tested them internally across procurement, invoice processing, email marketing, customer support and commercial contracting. The company is working with Microsoft to bring specialist Dots under its Agent 365 governance controls. The long-term direction is not subtle: teams of agents, each with a job, managed like staff.
DevDay also brought GPT-6.1 Sol, which OpenAI says approaches Astra's performance on coding and professional tasks at one fifth of Astra's standard token prices, a new monthly plan at $500 aimed at high-volume users, and a shared team workspace called ChatGPT Space. OpenAI put weekly ChatGPT users at 1.2 billion.
The asterisks
Two things sit awkwardly next to the launch. On 28 September, OpenAI said its agents had posted users' images online, affecting 53 ChatGPT users, which is the kind of disclosure that reads differently once you have handed an agent your calendar. And the company cancelled the October launch of GPT-6.1 Astra after failed safety tests, having already shelved that model over concerns about its behaviour during evaluation.
Those details do not invalidate Dots. They explain why the approval rules exist and why OpenAI keeps describing autonomous action as something a user opts into rather than something the product simply does. The honest position is that OpenAI is shipping a genuinely new capability and a genuinely uncertain safety profile in the same box, and asking users to calibrate how much autonomy they want.
For anyone deciding whether to try one, the practical question is not whether a Dot can do a task. It is whether you would notice if it did it wrong. The jobs these agents are built for are long, repetitive and easy to stop watching, which is exactly the profile where a quiet mistake survives longest.
Related articles
Step 5 Skipped Four Version Numbers, Landed Second Among Open Models, and Nobody Is Calling It
Benchmark position is a signal producers use to judge a model. Call volume is a signal consumers produce by using it.
Gemini Omni 1.1 Flash Chained Four Requests Into a 40-Second Shot. The Workflow Is the Product.
Google shipped a production pipeline with a review gate built into the pricing.
Microsoft Cut Partial-Transcript Latency to 100 Milliseconds. That Changes What Transcription Is For.
Below 100 milliseconds, a transcription product can respond while someone is still talking.
Synthesia Spent a Decade Recording Avatars. Now It Wants Them to Talk Back.
A training tool people voluntarily repeat is a different product from one they complete because someone assigned it.