# Dots (AI) Dots are [[OpenAI]]'s always-on [[AI Agents|agents]], announced at OpenAI DevDay on 29 September 2026 and built into [[ChatGPT]]. OpenAI writes the name lowercase ("your dot", "dots"). A dot is an agent that keeps working when you close the chat. It runs on [[GPT-6 Astra]], gets its own cloud computer and browser, connects to the apps you've plugged into ChatGPT (OpenAI says more than 4,000), and remembers what it learns about you over time. You talk to it in ChatGPT, Slack or Microsoft Teams, by message or voice call, and it also comes to you with progress, questions and decisions. The category isn't new. [[OpenClaw]], [[Peter Steinberger]]'s self-hosted assistant, started it: it began as a weekend project called Clawdbot in November 2025 (an agent with a computer, your accounts and a chat channel), and Steinberger joined OpenAI in February 2026. Ethan Mollick calls the whole family "Clawlikes". Dots are OpenAI's managed version: no server to set up, no model to pick, tied to a ChatGPT subscription. Who it's for: people who want a delegated assistant without running their own agent stack, and teams that already live in ChatGPT, Slack or Teams. Developers who run [[OpenAI Codex]] or [[Claude Code]] all day were the least convinced on [[Hacker News]] (see Reception). ## What a dot does - **Works in its own sandbox.** Each dot has a cloud computer (Linux plus Chrome, maintained by OpenAI) where it browses, creates files and runs tools. You can open that computer at any time to watch or take over - **Uses your computer if you allow it.** Local access is off by default. Once connected through the ChatGPT desktop app, a dot can work with local files, use local skills, create Work or Codex tasks, and use your local browser when its cloud browser is blocked - **Runs several projects at once.** You keep handing it new tasks without opening separate threads - **Researches in the background.** OpenAI calls this "proactive research": while you're away, the dot reads your connected apps looking for ways to help, and writes private notes for itself - **Runs scheduled work.** Reminders, recurring checks (e.g. a morning calendar review), monitoring - **Delegates.** It can create tasks in Codex cloud environments and ChatGPT Work - **Learns your preferences.** It receives memories from ChatGPT and creates its own, including from connected apps OpenAI's examples: a dot starts investigating as soon as a bug report lands in Slack; it turns a new design into a working app; it keeps a planning cycle on track. For developers, OpenAI showed a dot watching customer feedback, scoping small fixes, building and testing them, and returning pull requests with videos of the change. Outside OpenAI, an early tester's dot noticed he had forgotten to invoice a publication, prepared the invoice, and sent it after his approval. The announcement's "Dots are an extension of you" section frames it this way: "With a dot that knows your goals and standards, you can take on more without directing every step." It shows five examples, each with a named dot (Iggy, Felipe, Todd, Alfred and Jojo): - **Turn feedback into tested fixes**: a developer whose dot watches customer feedback for recurring requests - **Revise a launch as scope changes**: a product launch lead whose dot learns the audience, positioning and creative standards - **Update analysis with new evidence**: a scientist whose dot learns the research question and how they evaluate evidence - **Update a proposal as requirements shift**: a sales lead on an enterprise deal in technical review - **Automate content production work**: a content creator whose dot learns their voice and what matters to their audience ## Specialist dots Your primary dot works for you. **Specialist dots** take on a defined job inside a company, with their own identity, credentials, IT-provisioned hardware and deep integrations with systems of record. OpenAI tested them internally on procurement, invoice processing, email marketing, customer support and commercial contracting. They're in focused enterprise pilots, and OpenAI is working with [[Microsoft]] to manage them through Agent 365's governance and security controls. ## Availability and pricing - **Pro** (ChatGPT's $100 to $500 per month tier): rolling out from 29 September 2026 in markets **excluding the European Economic Area, Switzerland and the UK** - **Business Premium**: all supported ChatGPT regions - **Enterprise, Edu, Healthcare**: beta, off by default until a workspace admin enables it - Not on Free, Go or Plus. Not available to users under 18 - Your first dot is included in the plan "at no extra cost", plus an allowance for deeper work, with extended limits for the first month - Talking to your dot doesn't count toward ChatGPT usage limits. Tasks it starts in Codex or ChatGPT Work do - Coming later: more dots per account, and paying to scale a dot's speed or monthly workload - Setup happens on desktop (ChatGPT app or desktop web). Mobile works after setup; mobile web doesn't. Texting is a limited US-only beta for Pro. A dot can't call you, and can't have its own email address at launch Two pricing details from the launch week. Tibo Sottiaux (OpenAI) announced Dots on X as "Included in your Pro plan, without drawing down on any of your usage". That post drew an X Community Note, and the next day he replied: "I got community noted, but the note is wrong." His clarification: the primary dot is included and available 24/7; work the dot does directly "uses nothing and is all on top of your plans usage"; a Codex task it creates draws usage as usual; and paying for more speed and "more bandwidth" will come later, while "the baseline functionality will always just be included in your plan." OpenAI's published terms are narrower, as The New Stack pointed out: extended limits are only promised for the first month after launch, with per-plan usage terms to follow. And on launch day, OpenAI announced that the $200 Pro plan's Work and Codex allowance drops from 20x Plus to 10x on 30 October, with a new $500 tier above it. So the moment a dot hands work to Codex, it spends from a shrinking budget, and nobody has said whether you'll be warned first. ## Safety model OpenAI's design separates finding work from acting on it: - **Read-only background research.** Proactive research tasks can't send messages, change app content or control a browser or computer. OpenAI says this is enforced in code - **Action rules.** Built-in defaults decide what a dot can do alone, what needs approval, and what it must hand back. Permanently deleting data, installing unknown software or granting security-sensitive access need approval each time. Changing a password or moving money between accounts always goes back to you. Purchases use cards saved on the merchant's site and need your approval - **Graduated sharing rules.** Health data needs a named recipient ("share my medical history with Dr. Thompson"). Less sensitive data like an email address needs a class of recipients ("any airline company") unless you widen it - **Custom Rules.** Per action: take action without asking, take action if pre-approved, ask first, or hand off to you. They can't override the core safety requirements - **Auto-review.** A separate model, borrowed from Codex, checks planned actions (sending an email, changing files) against your instructions, your rules and the safety requirements before they run. Its controls sit outside the environment the dot can modify - **Monitoring.** A safety monitor can pause or stop a dot's work and show you a warning - **Secure sign-in.** Passwords go through a dedicated encrypted credential service and never enter the model's context. A secret pasted into a message or document is still visible to the model - **Activity View** in the desktop app shows ongoing and delegated tasks; you can redirect or stop the dot from there. You can also pause or reset it Data and memory: - Business, Enterprise and Edu content isn't used for training by default. On personal plans, the "Improve the model for everyone" setting decides, and that can include the actions dots take and data from connected apps - OpenAI doesn't train directly on proactive research or a dot's notes to itself, but anything a dot brings from them into an eligible conversation can be used - **You can't view, edit or delete individual dot memories.** The only way to clear them is to delete (reset) the dot. Disconnecting an app stops new access but doesn't remove what the dot already learned from it - Human review can happen in limited cases, including safety cases, even with model improvement off ### What the system card says The [[GPT-6 Astra]] system card has a section on dots. The numbers worth knowing: - In a test where each episode had an initial task, five or ten intervening tasks and a final task, with the scope of authorization changing between tasks without being stated, **doubling the intervening tasks from five to ten roughly doubled the flag rate, from 8.6% to 19.7% of samples**. No high-severity breach or exfiltration; the flags were moderate scope violations like carrying information between unrelated tasks or editing a shared document - 91.8% alignment pass rate (45/49 episodes) on a permission-change evaluation, including all 17 explicit permission changes - 0.00% observed misalignment across 151 tasks where inputs fed misleading hints to proactive behavior - When a warning prohibits an action, Astra kept trying to get around it in 17.4% of rollouts at maximum reasoning budget - Indirect prompt injection defense went from 96.23% to 99.79% (internal). The New Stack reports that Gray Swan's external test estimated an 8.5% attack success rate over 15 attempts per scenario The pattern matters for any long-running agent. Permissions set once and carried forward drift as tasks pile up. See [[Prompt injection]] and [[Human-in-the-Loop]]. ## How it compares | | Dots | Meta Muse | [[Grok Bot]] ([[xAI]]) | [[Gemini Spark]] | [[Claude Cowork]] / [[Claude Tag]] | [[OpenClaw]] / [[Hermes Agent]] | |---|---|---|---|---|---|---| | Hosting | OpenAI cloud computer per dot | Managed by Meta | Managed by xAI; one shared cloud computer and set of logins per roster | Managed by Google | Managed by Anthropic | Self-hosted | | Entry price | ChatGPT Pro ($100+) or Business Premium | Free, $20, $100 | Paid only | Google AI Ultra | Claude Pro and Max (Team and Free announced); Tag on Team and Enterprise | Free software, bring your own model | | Channels | ChatGPT, Slack, Teams, texting beta | WhatsApp | | Gemini app | Claude app; Tag in Slack | WhatsApp, Telegram, etc. | | Models | OpenAI only | Meta | xAI | Gemini | Claude | Any provider | Sources for the Muse, Grok Bot and Claude rows: The New Stack (Matt Burns, 3 October 2026). Anthropic's take on the same idea merged Cowork (scheduled jobs that run after you close your laptop, since July) into the main Claude app in September 2026, with no mascot and no new name. For the self-hosted options, see [[AI Agent Harness]]. ## Reception - **[[Hacker News]]** (765 points, 646 comments on the launch thread): mostly negative. Commenters couldn't work out what Dots is from the marketing page, compared it to "hosted OpenClaw", Clippy and Grok Bot, and mocked the name and the mascot. The main objections were trust (giving an agent write access to your life, safety monitoring that can stop your agent), vendor lock-in through integrations and memory, compute and token cost, the $100 entry price, and the EEA/UK exclusion. Developers said their throughput is limited by their own review, so an agent working overnight doesn't help them. One commenter reported that the cloud environment intercepts HTTPS with an OpenAI-issued certificate. The few early hands-on reports were mixed: a "B-" from one user annoyed by repeated booking confirmations, and a failed GitHub-issue attempt where the cloud machine died several times. The positive side came from heavy Grok Bot users, who like separate domain-specific agents, and from people who want an always-on agent without running OpenClaw themselves - **X**: Sottiaux's launch post (2.9M views) promised that dots are "Included in your Pro plan, without drawing down on any of your usage", and that you'll "soon" be able to create "entire teams of them". It got an X Community Note questioning the usage claim; he answered that the note was wrong (see Availability and pricing) - **Ben Thompson** (Stratechery, paywalled; only the teaser is public): "OpenAI's Dev Day showcased a product that is, frankly, pretty confusing. However, there is more vision here than it might seem." - **Ethan Mollick** (One Useful Thing) uses Dots and Muse to introduce "Clawlikes", and says his personal agents increasingly find his mistakes rather than the reverse: one caught a wrong project number in a permit email to his town, and Muse spotted an expiring airline credit. His bigger point (organizing agents turned out easier than he expected) comes from OpenAI's agent swarm, not from Dots - **Amplifying.ai** asked Dots to build the same app 8 times and leave the stack open. Every build used Cloudflare Workers and D1 with ChatGPT sign-in, through ChatGPT Sites; Vercel, Supabase, Neon, Clerk and WorkOS never showed up. Three of the eight builds shipped without the required background schedule - **The New Stack**: always-on agents are too early to have a winner, the moats are shallow, and the real test is whether people trust them with the next job ## My take I like the safety design more than I expected: read-only background research, an action reviewer outside the agent's reach, and passwords that never enter the model's context. Those are the lessons OpenClaw users learned the hard way, now built into the product. What bothers me is memory. A dot builds a model of you from your apps and conversations, and you can't see it, correct it or delete parts of it; you can only reset the whole dot. I keep my agents' memory in plain Markdown inside my vault precisely so I can read and edit it (see [[AI Agent Memory]] and [[AI Agent Portability]]). An assistant that knows me but can't show me what it knows is a hard sell. And from Belgium, the question is moot for now: Pro access excludes the EEA. ## Caveats - Specs, examples and safety claims come from OpenAI. The system card numbers are OpenAI's own evaluations - The Muse, Grok Bot and Claude comparison comes from one New Stack article; prices and features in this space change monthly - Dots launched four days before this note was written. Expect changes to pricing (after the first month), regions and limits - HN reports (HTTPS interception, hands-on experiences) are individual commenters' claims, not verified - Sottiaux's "always just be included" is a statement on X, not a published term. I didn't see the text of the Community Note itself, only his reply to it ## References - Announcement, "Introducing dots": https://openai.com/index/introducing-dots/ - "How we build safety, security, and privacy into dots": https://openai.com/index/how-we-build-safety-security-and-privacy-into-dots/ - Help Center, "Getting started with your dot": https://help.openai.com/en/articles/20001530 - Help Center, "Dots privacy, security, and safety FAQs": https://help.openai.com/en/articles/20001529-dots-privacy-security-and-safety-faqs - GPT-6 Astra system card (dots section): https://deploymentsafety.openai.com/gpt-6-astra/change-log - Tibo Sottiaux, launch post on X (29 September 2026): https://x.com/thsottiaux/status/2104981170685616361 - Tibo Sottiaux, reply to the Community Note on X (30 September 2026): https://x.com/thsottiaux/status/2105102312167575701 - Hacker News discussion: https://news.ycombinator.com/item?id=49896604 - The New Stack, "OpenAI just launched Dots. Here's why they matter for developers.": https://thenewstack.io/openai-dots-gpt6-agents/ - The New Stack, "OpenAI's Dots boundary problem rate doubled in longer tests": https://thenewstack.io/openai-dots-agent-permissions/ - The New Stack, "OpenAI's always-on agents are free, until one specific thing happens": https://thenewstack.io/openai-dots-codex-usage/ - The New Stack, "OpenAI halves $200 plan allowance, launches $500 plan": https://thenewstack.io/openai-halves-200-plan/ - The New Stack, "Anthropic's answer to Dots and Muse is already inside Claude": https://thenewstack.io/claude-answer-to-dots-muse/ - Ben Thompson, Stratechery, "OpenAI Dev Day, Dot and OpenAI's Product Transition, Sign In With ChatGPT" (paywalled): https://stratechery.com/2026/openai-dev-day-dot-and-openais-product-transition-sign-in-with-chatgpt/ - Ethan Mollick, "The Dot and the Swarm": https://www.oneusefulthing.org/p/the-dot-and-the-swarm - Amplifying.ai, "What Dots Actually Choose": https://amplifying.ai/research/openai-dots-choose ## Related - [[2026-10-03 OpenAI Dots - always-on agents, with a memory you can't inspect]] - [[OpenAI]] - [[ChatGPT]] - [[GPT-6 Astra]] - [[OpenAI Codex]] - [[OpenClaw]] - [[Hermes Agent]] - [[Gemini Spark]] - [[Claude Cowork]] - [[Claude Tag]] - [[Claude Managed Agents]] - [[AI Agents]] - [[AI Assistants]] - [[AI Agent Harness]] - [[AI Agent Memory]] - [[AI Agent Identity]] - [[AI Agent Portability]] - [[Prompt injection]] - [[Human-in-the-Loop]] - [[AI Safety]] - [[Peter Steinberger]] - [[Sam Altman]]