What are OpenAI dots? ChatGPT's always-on agents, explained
OpenAI's dots are always-on ChatGPT agents with their own cloud computer. Which plans include one, what it costs, what it can reach, and what stays with you.
Dots are OpenAI’s always-on agents, launched at DevDay on September 29, 2026. Each dot runs on GPT-6 Astra with a cloud computer and browser of its own, works through the apps you connect, and keeps going between conversations, messaging you in ChatGPT, Slack or Teams when it has results or needs a decision. One dot is included with ChatGPT Pro ($100, $200 or $500 a month, excluding the EEA, the UK and Switzerland at launch) or a ChatGPT Business Premium seat ($100 a user a month billed annually, $125 monthly). Plus, Go and Free plans don’t include one.
Anything that could affect your accounts or share information passes an automatic review first, and changing a password or transferring money is always handed back to you to do yourself. When a dot researches on its own initiative, its tools can only read.
Who can get one, and what it costs
Dots began rolling out on September 29, and OpenAI says access “may take several days to reach your account.” You have to be 18 or older. You create your dot in the ChatGPT desktop app (macOS or Windows) or in ChatGPT in a desktop browser, then talk to it in the mobile app once the update reaches you; you can’t create one on a phone, and mobile web isn’t supported. You give it a name and a look (shape, color, eyes, glasses and accessories), both of which you can change at any time, and its handle becomes @yourname-agentname. The plans, as OpenAI’s pricing page, Pro tiers article and Business release notes stated them on September 30:
| Plan | Price | Dot | Where |
|---|---|---|---|
| Pro 100, 200, 500 | $100, $200 or $500 a month, billed monthly only | One included | Supported ChatGPT countries except the EEA, the UK and Switzerland |
| Business, Premium seat | $100 a user a month billed annually, $125 monthly; workspaces start at two users | One included | All supported ChatGPT regions |
| Enterprise, Edu, Healthcare | Custom pricing through sales | Beta, off until a workspace admin turns it on | Rolling out worldwide |
The pricing page shows no dot on Plus, Go or Free, and on Business, OpenAI names Premium seats only, not the cheaper Standard seats.
The first dot comes “at no extra cost.” Talking to it doesn’t count toward your ChatGPT usage limits, but work it starts or manages in Codex or ChatGPT Work counts toward those products’ limits “as usual,” the same allowance each plan gives you in Codex. On top of that, the launch post says your plan includes “an allowance for deeper work, with extended limits for the first month after launch.” The September 29 release notes go further for that month: dots usage “won’t count toward eligible Pro, Business, and Enterprise users’ plan allowances,” and OpenAI will “share usage terms for each plan” afterwards. By our reading, that month runs to about the end of October 2026, and the limits that apply after it haven’t been published. OpenAI also says you’ll later be able to add more dots and scale each one’s speed or monthly workload, without saying what that will cost.
Its own computer, and yours if you allow it
Each dot works on a cloud computer and browser of its own, separate from your devices, and keeps working there while they are off. OpenAI’s computers and apps guide says that computer “can keep its state between periods of use,” with its own files, software and browser sessions. You can open it from the dot’s profile at any time to see what it is doing. Opening it doesn’t give you control; Take over hands you its mouse and keyboard until you select Return control.
When a site needs a login, the dot sends you a private sign-in form, and what you type goes to its browser without passing through the model. It can then keep using that session until you sign out or the site ends it. Its browser doesn’t inherit the sessions on your own computer, saving a login to Passwords is optional, and reusing a saved login needs your confirmation. The privacy and safety FAQ adds that a dot’s context “does not retain credentials, images, or screenshots.” Some websites block cloud browsers outright.
Your own computer stays out of reach until you connect it. You do that once, from the dot’s profile in the desktop app on that machine, and it lasts until you select Revoke access. One personal computer can be connected at a time, and it has to be online with the ChatGPT app open while the dot uses it. A connected computer lets the dot work with its files, code and local skills, start Work or Codex tasks on it, and fall back to your local browser when a site refuses the cloud one, and it can do so from any channel you message it on, your phone included. That computer’s camera, microphone and screen are reachable only once it is connected and the ChatGPT app has permission for them in your device settings.
Apps come through ChatGPT’s plugins, which the launch post says reach more than 4,000 apps. Permissions are shared with ChatGPT, ChatGPT Work and Codex, so a plugin you have already connected is available to your dot within the access you granted, and you can let it read email without letting it send any. You can connect your personal email account, but at launch a dot can’t have an address of its own. For coding it can run tasks in a Codex cloud environment you’ve already set up.
Where you talk to it
The same dot answers in ChatGPT (the desktop app, a desktop browser or the mobile app), in Slack and in Microsoft Teams. Switching channels doesn’t reset it; messages stay in the channel they were sent in, and before repeating something from a private conversation to other people it checks that you’ve allowed it. In Slack you can message it directly or mention it in a channel, and by default it responds to you; you can tell it to engage with others. You can call it from its conversation in ChatGPT, but it can’t call you at launch. Texting is “coming soon” on the launch post and in OpenAI’s docs, while the getting-started article describes a limited beta for some Pro users in the US, run through a third-party provider.
What it does while you aren’t talking to it
A dot keeps work moving between conversations. It can decide for itself when to pause and when to wake up and continue, splits work among background agents running in parallel, and opens separate threads you can follow in any ChatGPT app. Work that has to happen at fixed times needs a saved schedule (OpenAI’s tasks guide suggests giving the time zone and an end date, then asking the dot to confirm what it saved). Where a connected service supports it, a dot can also act when something happens, such as a new bug report in a Slack channel, though adding it to a channel doesn’t by itself make it watch one.
It also looks for ways to help without being asked, which OpenAI calls proactive research. It reads the connected sources it has permission to read, keeps private notes, and can form memories from your connected apps “even when you haven’t asked a specific question about it.” The tools it uses for this are read-only: in the launch post’s words, they “can’t send messages, change app content, or control your browser or computer.” Anything it then wants to act on goes through the same checks as a task you gave it, and neither you nor the dot can lift those research restrictions.
What always stays with you
Before a dot takes an action that could affect your accounts or share information, a separate check OpenAI calls Auto-review compares it with your instructions, your custom rules and built-in safety requirements, and decides whether it goes ahead, waits for your approval, or comes back to you. The FAQ sets out the defaults:
- You do it yourself. “The most sensitive actions like changing a password or transferring money require you to take over so you can complete them yourself.”
- Approval each time. Actions such as permanently deleting data or installing software “may require approval each time.”
- Approval in advance. Some, such as recurring messages, or a purchase with a card you’ve saved on a merchant’s website, can be approved ahead of time when the approval specifically covers them. Approving one message “does not give your dot ongoing permission to contact people on your behalf.”
Custom rules let you set your own boundaries for supported actions, with four choices per rule: take action without asking, take action when you say so, ask before taking action, or hand off to you. They are instructions the dot “tries to follow,” they can’t switch off the built-in requirements, Auto-review or the research restrictions, and if a workspace admin disables custom rules, your saved ones stop applying. OpenAI’s own monitoring can also pause or stop a dot’s work when it detects a safety concern.
Stopping a dot takes more than one switch. According to the controls guide, Pause stops its current main task but not the tasks it has delegated or its future scheduled runs, which you stop from Activity and Scheduled in its profile. Stopping doesn’t undo what is done. You can ask the dot to fix a mistake, and the FAQ says it may be able to reverse an edit to a document or recall an email, but some actions cannot be undone, and the docs warn that a completed run “doesn’t by itself confirm that the requested result was achieved or delivered.”
Memory, training, and deleting a dot
A dot starts with your ChatGPT memory and recent conversation context, and its conversations can feed back into ChatGPT memory. Turning Memory off in ChatGPT stops the sharing without deleting what the dot already received. It also keeps notes of its own, and those you can’t inspect: you “currently cannot view, delete or directly modify individual dot memories.” Disconnecting an app stops new access but leaves what the dot already learned from it. The one way to clear its notes is to delete the dot, and none of OpenAI’s dots pages describes a way to export them first.
Deleting a dot (Reset, in the help center’s wording) removes its own context, its conversations with you, its saved memories and its scheduled tasks, and can’t be undone. Files, Codex threads and ChatGPT conversations it created are stored separately and stay. So do changes it made in connected apps and messages it already sent to other people.
On personal plans, the “Improve the model for everyone” setting decides whether your dots’ conversations and work, which may include the actions they take and data from connected apps used in a conversation, may be used to train OpenAI’s models. Business, Enterprise and Edu workspace data isn’t used by default. OpenAI says it doesn’t train directly on proactive research or its notes, though anything from them that a dot brings into an eligible conversation may be used depending on your settings, and that human review “may occur in limited circumstances, including safety-related cases, even when model improvement is turned off.”
What OpenAI’s own testing found
On launch day OpenAI added an appendix on dots to the GPT-6 Astra system card, focused on the risks of proactive, long-running work. In automated prompt-injection tests, 100 runs each fed a dot 500 simulated emails, 50,000 in all, of which 16,600 were attacks, and none scored a success; 2,638 iteratively refined attacks also produced none. Human red-teaming found “opportunities to strengthen how dots handle sensitive disclosures and seek user confirmation,” which OpenAI says updates to its confirmation policies mitigated in the scenarios it tested, and the card states: “While we continue to address known vulnerabilities, we believe deployment is appropriate given the conditions required to exploit them.”
One result speaks to the long-running part. Given a chain of related tasks in one persistent environment, dots showed no severe breach or exfiltration, but were flagged for going beyond the intended task in moderate ways, such as carrying information between unrelated tasks or editing a shared document, in 8.6% of samples with five tasks in between and 19.7% with ten. Some of the card’s evaluations ran without the production safeguards in place. The FAQ’s own summary is that these protections reduce the risk of malicious instructions causing an unwanted action, “but they do not eliminate it.”
Specialist dots, and dots at work
The dot on a Pro or Business Premium plan works for one person. OpenAI is also previewing specialist dots that hold a defined job inside an organization, each set up by the company with its own identity, credentials, access to the systems it needs and IT-provisioned hardware. They start as “focused enterprise pilots” in which OpenAI’s engineers agree each dot’s responsibilities with the customer, building on internal testing in procurement, invoice processing, email marketing, customer support and commercial contracting, and OpenAI is working with Microsoft so that businesses can manage them in Agent 365.
In Enterprise, Edu and Healthcare workspaces the dot is a beta an admin switches on. OpenAI’s admin guide says that during the beta dots support neither data residency nor inference residency, aren’t available to FedRAMP workspaces, workspaces using Enterprise Key Management or those with UAE inference residency, and don’t provide strict zero data retention.
Where dots fit
An agent that keeps working on a computer of its own and reports to you wherever you are is what people have started calling a cloud agent, and dots are OpenAI’s version, built into ChatGPT. xAI’s Grok Bot, which arrived in August, differs on one point that matters before you hand over logins: every bot on an account shares one computer, while each dot works on its own. At launch you get one dot, and “teams of dots working together on your behalf” is something OpenAI says it envisions over time.
A dot exists only inside a ChatGPT plan, on OpenAI’s cloud. OpenAI’s pages name one model for it, GPT-6 Astra, and describe no way to choose another or to take a dot’s notes elsewhere. Even with your laptop connected, the work is coordinated from OpenAI’s cloud, and the admin guide says conversations, tool results and task context “do not stay exclusively on the connected computer.” That is the main line between a dot and an open-source agent such as OpenClaw on a computer you control, the comparison drawn in full in dots, Meta’s Muse or your own agent.