OpenAI introduced dots on September 29, describing them as “remarkably capable, always-on agents” that run on their own cloud computer, browse the web, and work toward your goals around the clock. The model underneath is GPT-6 Astra. The pitch is that a dot learns your preferences, connects to over 4,000 apps through plugins, and reaches you through ChatGPT, Slack, or Teams. The rollout starts today for Pro and Business Premium users in eligible markets, with Enterprise, Edu, and Healthcare on a beta that admins must enable.

Read past the marketing and the genuinely new thing here is not the intelligence. It is the machine.

Every dot gets a computer

OpenAI says each dot works on its own cloud computer, with its own browser, and you can open that computer at any time to inspect the work. That is a meaningful architectural commitment. Most agent products in 2026 are still a loop that calls tools inside a session you started. A dot is closer to a persistent VM with an identity, a filesystem, and a growing memory of what you asked for last week.

The company is explicit that dots can also connect to your laptop, and that your computer stays separate unless you choose to connect it. It also says dots can use saved passwords to sign into supported websites “without exposing them to the model.” That last detail is doing a lot of work. It implies a credential-broker layer sitting between the model and the login, which is the only sane way to ship this feature and also the part most competitors have not built.

Then there is the pricing shape. Your first dot is included with Pro or Business Premium at no extra cost, conversations with your dot do not count toward ChatGPT usage limits, and tasks routed into Codex or ChatGPT Work do count. OpenAI says future plans let you add more dots and scale each one by increasing its speed or the total work it takes on per month. That is not a feature list. That is a compute-metering business, and it tells you where the margin is going to live.

The proactive research loophole

The most consequential paragraph in the announcement is buried under “Built-in safeguards.” When you are not actively working with a dot, it looks for ways to help in the background. OpenAI calls this proactive research, and says it runs through the apps you have already connected using tools that are restricted to read-only, so they cannot send messages, change app content, or control your browser.

That restriction is a real mitigation and it is also a narrow one. Read-only access to your connected apps is still read access to your mail, your documents, your calendar, and your code. The attack surface is prompt injection through any of that content, which is why OpenAI says its monitoring can pause or stop a dot if it detects a safety concern. A monitoring system that can halt an agent mid-task is the right control. Whether it catches a slow, patient exfiltration spread across hundreds of innocuous-looking reads is a different question, and OpenAI does not answer it in this post.

The company points to a dots safety blog, a Help Center article, and a system card for the details. Those documents are where the actual claims will be testable.

Specialist dots and the enterprise grab

The second half of the announcement is the one that should worry anyone selling agent infrastructure. OpenAI is previewing specialist dots with their own identity, IT-provisioned hardware, and deep integrations into a company’s systems of record. It says it has been testing these internally across procurement, invoice processing, email marketing, customer support, and commercial contracting, and that it is starting focused enterprise pilots where OpenAI engineers define each dot’s responsibilities and approval flow.

It is also working with Microsoft to integrate specialist dots into Agent 365, so businesses manage them through Microsoft’s existing governance and security controls. That is a straight shot at the enterprise agent market, and it arrives with distribution attached. Any startup whose pitch is “we give your company governed agents with identity and audit trails” now has to explain why the buyer should not just take the one bundled with the ChatGPT seats they already pay for.

The interesting question is not whether dots work. It is who is liable when one of them does something expensive at 3 a.m.

What is actually hard here

Three things stand out as unresolved.

The first is reliability under autonomy. OpenAI’s own examples are the tell. A bug appears in Slack and dots start investigating. A design arrives and dots turn it into a working app. An early tester’s dot noticed a forgotten invoice, prepared it, and sent it after approval. Every one of those examples ends with a human reviewing or approving. That is honest, and it is also an admission that the approval step is load-bearing.

The second is the memory model. OpenAI says it does not train directly on proactive research or a dot’s notes to itself, and that it does not use Business, Enterprise, or Edu workspace content to improve models by default. On personal plans, you control whether dots’ conversations and work are used for training. Those are reasonable defaults. They also mean the dot’s accumulated understanding of you is a proprietary asset living on OpenAI’s infrastructure, and the post says nothing about portability.

The third is the multi-dot future. OpenAI says it envisions teams of dots working together on your behalf. Nothing in the announcement describes how one dot’s permissions constrain another’s, or what happens when two dots disagree about a shared resource. That is a coordination problem, and coordination problems at agent scale are where the interesting failures will come from.

What it means for builders

If you are building agents, the ground has moved twice in this post. Persistent cloud computers per agent are now table stakes at the consumer tier. Credential brokering that keeps secrets out of the model context is now a baseline expectation, not a differentiator. And read-only background access with a kill switch is the minimum viable safety story.

The defensible ground left is narrower and more specific: vertical depth in a workflow OpenAI has not piloted, portability of agent memory across vendors, and evaluation tooling that can actually prove an agent did what it claimed. OpenAI says it will share what it learns and use it to guide what it builds next. For everyone else, the useful move is to watch the system card, not the demo reel, and to price your product as if the bundled dot is free.