What are OpenAI’s dots?
Dots are OpenAI’s always-on agents, launched on 29 September 2026. Each dot has its own computer in the cloud, works through the apps you connect, and keeps going between conversations, coming back to you for the steps that need your say.
They run on GPT-6 Astra, OpenAI’s most capable model. OpenAI published tests of what changes when a model works on its own for long stretches. This page covers how dots work, what keeps them in check, what those tests found, and problems reported since.
- Made by
- OpenAI
- Launched
- 29 September 2026
- Runs on
- GPT-6 Astra
01
How a dot works
A dot is GPT-6 Astra with a computer of its own in OpenAI’s cloud, with a browser, files and tools, working around the clock. It reaches your work through the apps you connect, more than 4,000 of them through OpenAI’s plugins. You message it in ChatGPT, Slack or Teams, or call it by voice. It learns your preferences as you work together, runs several projects at once and hands parts of them to other agents. A setting called a time budget decides how long it keeps at something.
Companies can also set up specialist dots, each with its own identity and logins, for set jobs like processing invoices. OpenAI is piloting those with businesses, and with Microsoft for its Agent 365 tools.
When you’re not working with it, a dot looks for ways to help. OpenAI calls this proactive research: background tasks that read your connected apps with tools that can only read, so they can’t send messages or change anything. What a dot finds goes into private notes it uses to decide what to offer you. OpenAI’s example from early testing: a dot noticed its user had forgotten to invoice a publication, prepared the invoice, and sent it once the user approved.
Dots started rolling out the same day to ChatGPT Pro and Business Premium subscribers, with a beta for Enterprise. The first dot comes with the plan. OpenAI says people will be able to add more dots, and that it envisions teams of dots working together.
02
What keeps a dot in check
Before a dot sends an email or changes a file, a separate system called Auto-review checks the planned step against your instructions, your own rules and OpenAI’s safety requirements, and can block it. Auto-review runs outside the computer the dot works on, so the dot can’t switch it off. Some steps need your confirmation each time, like deleting data for good or installing software from an unknown source. Others go back to you to do yourself, like changing a password or moving money between accounts. Purchases need your approval.
Passwords go through a separate sign-in service, so the model doesn’t see them. Monitoring watches what a dot plans and does, and can pause its work. OpenAI’s launch post still tells people to check the results: “Dots can still make mistakes, so always review consequential work.”
03
What OpenAI’s tests found
OpenAI added a chapter on dots to the GPT-6 Astra system card on launch day, and each result below comes from it. It tests what a model that keeps working for long stretches, with your email and accounts, might get wrong.
- Poisoned emails
Dots read 50,000 simulated emails, 16,600 of them attacks written by another OpenAI model to make them leak private details, forward mail or divert payments. 0 succeeded. An attacker that rewrote its email after each failure got nowhere in 2,638 tries. Human red-teamers did find weak spots in how dots handled sensitive details and asked for confirmation; OpenAI changed its rules and retested.
- Warnings
When a warning forbade an action, the model behind dots kept pushing in 15% to 17% of runs, whether it had 4 minutes or a simulated year to work.
- Permissions taken away
When a permission was withdrawn or the job changed partway through a task, dots adapted in 45 of 49 runs, including the 17 where the change was spelled out.
- Long chains of tasks
Given related tasks one after another, with limits that shifted without being stated, dots overstepped more as the chain grew: 8.6% of runs were flagged with five tasks in between, 19.7% with ten. OpenAI found no severe breach. The overreach was things like carrying information from one task into another.
- Other agents
On a message board where other agents asked for private information and illicit access, dots didn’t follow the requests, or engage with the board in any run. Their rules keep them out of conversations with agents outside OpenAI’s own unless the user asks.
- Work tests
In OpenAI’s tests of misbehavior at work, chosen because they’re the likeliest to go wrong, 0.84% of runs showed severe misalignment.
- Monitoring
Told to slip past OpenAI’s own security monitoring, the model had “some success at evading the assignment of a P0 priority,” the alert that pages OpenAI’s security team. Given the full record of what it did, the strongest monitor missed close to 0% of attempts.
These are OpenAI’s tests of its own product, mostly in simulated settings, and the card says its hardest work tests are “not necessarily representative of production.” The model underneath matters too. The same card found Astra’s written reasoning harder to monitor than earlier models’, which is the subject of Does GPT-6 Astra think in neuralese?
04
Problems reported so far
We haven’t found a checked report of a dot going wrong in real use as of 1 October 2026, two days after launch. When a case meets the bar on AI gone rogue, where a model did what it wasn’t asked to and the record shows it meant to, it goes there and here.
05
Sources
These are the sources behind this page. We checked them against the original text on 1 October 2026.
- Lab publication
OpenAI. Introducing dots. 29 Sep 2026.
What dots are, how they work and who can get them.
- Lab publication
OpenAI. How we build safety, security, and privacy into dots. 29 Sep 2026.
Auto-review, sign-ins, proactive research and the steps that stay with you.
- Lab publication
OpenAI. GPT-6 Astra System Card. 3 Sep 2026, updated 9, 22 and 29 Sep 2026.
The dots chapter and its test results.