OpenAI launches Always-on AI agents in ChatGPT Under Dots Project
OpenAI’s latest product is designed to shift artificial intelligence from a responsive chatbot into a persistent digital worker. Called dots, the agents operate continuously on dedicated cloud computers, connect with thousands of applications and pursue user-defined objectives with limited supervision. Their arrival could reshape productivity software, enterprise automation and the economics of AI subscriptions. Yet early tests reveal a familiar tension: the more autonomy an agent receives, the more valuable it becomes—and the more carefully its errors, permissions and judgment must be managed. Dots therefore represent both a major product evolution and an important test of whether autonomous AI is ready for practical work.
OpenAI moves beyond the chatbot
OpenAI has introduced dots, a new category of artificial-intelligence agents designed to remain active after a user closes the ChatGPT window. Announced at the company’s developer event on Sept. 29, 2026, the agents are intended to work continuously toward goals rather than simply respond to individual prompts.
Each dot runs on OpenAI’s GPT-6 Astra model and is assigned its own cloud computer and browser. Through OpenAI’s plugin ecosystem, it can connect to more than 4,000 applications, allowing it to work across software platforms instead of remaining confined to the ChatGPT interface.
That distinction is strategically important. Traditional chatbots generally wait for a user to ask a question or provide the next instruction. Dots are built around continuity. They can maintain projects, monitor developments, conduct research and return with progress updates or completed work.
OpenAI’s broader ambition is to make AI function less like a search box and more like a digital employee. The company describes dots as agents that can learn from feedback, retain context and operate around the clock on a user’s behalf.
The launch also places OpenAI directly in the increasingly competitive market for autonomous AI assistants. Technology companies are competing to move beyond text generation and into software execution, workflow management and enterprise decision support. In that market, the winning products may not be the systems that produce the most fluent answers, but the ones that can reliably complete complex tasks across multiple tools.
Availability and subscription structure
Dots are initially rolling out to ChatGPT Pro and Business Premium subscribers in eligible markets. Enterprise customers, including organizations using Edu and Healthcare plans, can access a beta version when their workspace administrator activates it.
OpenAI says the first dot is included with those plans at no additional cost. That pricing decision gives existing subscribers an immediate reason to experiment while allowing OpenAI to gather usage data before expanding the product more broadly.
Conversations with a dot do not count toward standard ChatGPT usage limits. However, work that the agent transfers to Codex or ChatGPT Work does count against the relevant usage allowances. This distinction could become significant for users assigning dots demanding coding, research or document-production tasks.
The structure also highlights an emerging challenge for AI companies: separating access to an agent from the cost of the computing resources required to operate it. A persistent agent that runs continuously can consume substantially more infrastructure than a chatbot that answers occasional questions. OpenAI’s decision to include one dot in selected plans may therefore be viewed as an introductory strategy rather than a guarantee that unlimited autonomous work will remain bundled into standard subscriptions.
For businesses, the economic calculation will depend on whether a dot can replace enough administrative work to justify the subscription and oversight required. A digital agent that saves several hours of scheduling, reporting or invoice processing each week could quickly become valuable. An agent that requires constant correction may instead create a new layer of supervision.
What a dot is designed to do
OpenAI describes a dot as receiving “almost everything you’d give a new employee.” That includes an identity, access permissions, a cloud computer and the ability to write and test code.
The comparison with an employee is deliberate. A dot is not simply a feature inside a single application. It is intended to have a defined role, access specific tools and carry responsibility for ongoing work.
Users can communicate with their dot through ChatGPT, Slack and Microsoft Teams. OpenAI also plans to add SMS support. Context is designed to move between those channels, meaning a user can begin an assignment in ChatGPT, discuss its progress in Slack and continue the same work through another supported interface.
The practical applications are broad:
Turning customer feedback into tested pull requests.
Repeating scientific analyses as new data becomes available.
Managing email and scheduling.
Preparing invoices and business documents.
Updating projects when underlying information changes.
Researching information across connected applications.
Writing, testing and deploying software.
Preparing work for human review before a consequential action is taken.
In one early example, a tester’s dot identified that a publication had not been billed. The agent prepared the invoice and sent it only after the tester approved the action. The example illustrates the type of administrative oversight OpenAI hopes to automate: work that is important enough to matter but easy to overlook during a busy day.
The potential value is particularly clear for professionals managing multiple streams of work. A content creator, for example, could use a dot to monitor audience feedback, organize production tasks, prepare draft invoices, update a publishing calendar and flag relevant business developments. A financial researcher might ask it to track selected company disclosures, refresh an analysis when new data arrives and prepare a report for review. The agent would not eliminate the need for judgment, but it could reduce the amount of repetitive coordination surrounding that judgment.
Enterprise agents and specialist identities
OpenAI is also testing “specialist dots” for enterprise use. These agents have their own identities and credentials, allowing them to operate within controlled corporate environments.
The company says the concept has grown out of internal testing in procurement, invoice processing, customer support and commercial contracting. These are areas where work often follows established procedures, involves large volumes of documents and requires access to several business systems.
A specialist dot could, for example, review purchase requests, compare them with company policies, identify missing approvals and prepare a recommendation. In accounts payable, it might match invoices with purchase orders, flag discrepancies and route exceptions to an employee. In customer support, it could organize incoming cases, retrieve relevant account information and prepare responses for approval.
OpenAI is working with Microsoft to connect specialist dots with the governance controls in Agent 365. That integration points to the central enterprise question surrounding autonomous AI: not merely whether an agent can perform a task, but whether an organization can prove what the agent accessed, which instructions it followed and why it took a particular action.
In a corporate setting, identity and permissions are as important as intelligence. A highly capable agent with excessive access could create greater risk than a less capable system operating within narrow boundaries. Specialist dots therefore appear to be part of a wider effort to make AI agents auditable, governable and compatible with existing security structures.
The commercial implications are substantial. If specialist agents can perform routine work across procurement, finance, customer service and legal operations, they could become a new software layer between employees and enterprise applications. That could pressure traditional workflow and business-process software vendors while increasing demand for identity management, monitoring and AI security tools.
Guardrails for autonomous work
OpenAI says dots use read-only tools when users are not actively working with them. In that background mode, they can conduct what the company calls “proactive research,” but they cannot send messages or modify content inside connected applications.
This limitation is designed to separate observation from action. A dot may inspect information and identify something that needs attention, but it should not independently alter records or communicate externally without permission.
Users can also create custom rules that determine what the agent may do. An action can be allowed automatically, sent for approval or blocked entirely. Sensitive operations, such as changing a password, remain under the user’s control.
OpenAI has emphasized that dots can still make mistakes and that users should review consequential work. That warning is more than a standard product disclaimer. Autonomous systems can misunderstand instructions, draw incorrect conclusions, use outdated information or perform a technically valid action that is inappropriate in context.
The risk grows when an agent operates across several applications. A small error in one system may be transferred into another, creating a chain of incorrect actions. For example, an agent that misinterprets a customer request could update a sales record, prepare an inaccurate proposal and send a misleading follow-up unless approval checkpoints are in place.
For that reason, the most sensible operating model is not “set it and forget it.” Users should begin with narrow permissions, require approval for external communications and financial transactions, and expand the agent’s authority only after observing its performance.
For businesses, the practical safeguards should include:
Clearly defined access permissions.
Separate identities for individual and specialist agents.
Approval requirements for external messages and financial actions.
Audit logs showing what the agent accessed and changed.
Read-only defaults for background activity.
Restrictions on password, deletion and account-management tasks.
Regular reviews of connected applications and credentials.
Human oversight for legal, financial and customer-facing decisions.
The quality of these controls may prove as important as the quality of GPT-6 Astra itself. In enterprise markets, trust is not created by fluent output alone. It depends on predictable behavior, traceability and the ability to stop an agent when its work begins to diverge from the user’s intent.
The reliability gap matters more than the novelty
Dots arrive at a moment when the AI industry is moving from conversational capability toward delegated execution. The change sounds incremental—allowing software to take actions instead of merely suggesting them—but its commercial consequences are much larger.
A chatbot can be useful even when an answer requires editing. An autonomous agent operates under a higher standard. If it is asked to update a website, schedule an appointment, prepare an invoice or send an email, success means completing the task accurately and within the user’s boundaries.
That creates a reliability gap between what an agent appears capable of doing and what users can safely delegate. The gap is especially visible in tasks involving unfamiliar websites, human-verification systems, incomplete information or multiple applications.
The most attractive use cases may initially be those with structured inputs and clear outputs. Email organization, calendar coordination, recurring reports, document classification and data monitoring are more predictable than open-ended travel booking, complicated customer negotiations or tasks requiring a series of uncertain browser interactions.
Investors and business leaders should therefore assess dots through operational metrics rather than marketing language. Relevant questions include:
How often does the agent complete a task without intervention?
How frequently does it ask for unnecessary approval?
How costly are its mistakes?
How much context can it retain over long-running projects?
Does performance deteriorate when several applications are involved?
Can administrators reconstruct the agent’s actions?
How much human time is required to supervise it?
Does the resulting productivity gain exceed the subscription and governance costs?
The answers will determine whether dots become a meaningful enterprise product or remain an impressive consumer experiment.
