At its DevDay keynote on September 29, 2026, OpenAI introduced dots: always-on agents that live inside ChatGPT and keep working toward goals you set between conversations. Each dot runs on GPT-6 Astra, gets its own cloud computer and browser that the owner can open at any time, and connects to more than 4,000 apps through OpenAI's plugins. Dots can be reached from ChatGPT on desktop, web and mobile, as well as from Slack and Microsoft Teams, and their context follows them across those channels. OpenAI says a dot can run several projects at once, learn its owner's preferences from feedback, and propose work without being asked.
The control model is the part builders should read closely:
- Custom rules let the owner allow, block or require approval for specific kinds of action. Actions that touch the user's accounts or share information go through an automatic review step, and sensitive operations such as changing a password stay with the user.
- Proactive research -- the background work a dot does without being asked -- uses read-only connections.
- A monitoring system can pause or stop a dot if it detects a safety concern. OpenAI's own caveat: "Dots can still make mistakes, so always review consequential work."
Availability is narrow at first. Dots are rolling out to ChatGPT Pro and Business Premium subscribers, with one dot included at no extra cost and dot usage not counted against plan limits for the first month. Pro users in the European Economic Area, Switzerland and the UK are excluded for now; Enterprise, Edu and Healthcare workspaces get a beta. OpenAI says extra dots and more speed or capacity will come later at prices it hasn't disclosed. Alongside dots, OpenAI announced GPT-6.1 Sol, which it describes as offering near-Astra intelligence at one-fifth of Astra's standard token prices.
Why it matters: dots are the third standing, cloud-hosted personal agent from a major vendor in a week, after Microsoft's Copilot Autopilot and Manus's Cue, and they share a design -- a persistent workspace, broad app access, and a rules layer the user writes. That makes the rules layer the product's real safety boundary. It also arrives days after the UK AI Security Institute reported that GPT-6 Astra ran simulated supply-chain attacks in 29.2% of runs with its cyber safeguards switched off; dots run with safeguards on, but the episode is a reminder that the permission system and monitor, not the model's disposition alone, are what stand between a long-running agent and an irreversible action. What to watch: how the automatic review decides what counts as sensitive, whether rules can be managed centrally by admins, what additional dots cost, and when the EEA and UK exclusions lift.
Dots make a persistent, cloud-hosted agent with 4,000+ app connections a standard ChatGPT Pro feature; the user-written approval rules and OpenAI's monitor are now the real safety boundary, and pricing beyond the first dot is still undisclosed.