The short answer
Dots move OpenAI from answering prompts to running background work: a named agent with its own computer, your app connections and a seat in Slack and Teams. Pro and Business Premium users get them now, and Enterprise, Edu and Healthcare workspaces get them when an admin switches them on. That admin switch is the moment to decide scopes, approvals and logging, the same groundwork we apply when we build custom AI agents for enterprise workflows.
The capability is real. So is the risk: an agent that acts on its own through thousands of connectors holds standing access to company data and runs when nobody is watching.
What did OpenAI launch with Dots?
Dots are OpenAI’s first agents designed to run without a user in the loop for each step. Sam Altman called them “remarkably capable, always-on agents built to handle really anything you can think of” in the DevDay keynote, CNBC reported. A user starts with one primary dot, names and customizes it, and gives it goals. The dot then works in the background on a dedicated cloud computer, using apps the user has connected, and improves from feedback.
TechCrunch notes that, unlike Codex or ChatGPT, dots are not tied to a specific interface or device. OpenAI’s own examples make the enterprise intent plain: a developer assigns a dot to watch customer feedback and ship bug fixes and requested features; a scientist uses one to rerun analysis as new data arrives. The same DevDay also introduced ChatGPT Space, where teammates and dots work together, and Pages, documents built for humans and agents to edit jointly.
Who can use Dots, and where?
Rollout started on launch day in ChatGPT for Pro and Business Premium subscribers in eligible markets. According to CNBC, Enterprise customers, including Edu and Healthcare workspaces, can try dots once their workspace administrators enable them. OpenAI has not published a general availability date for all plans.
The channels matter as much as the plans. Users can talk to a dot in Slack and Microsoft Teams, which places an autonomous agent inside the tools where most company conversations, files and approvals already live. TechCrunch also reports support for Microsoft Agent 365 security controls, a sign that OpenAI expects IT teams, not just individual users, to own the deployment decision.
Why are always-on agents different from chatbots?
A chatbot waits for a prompt and returns text. A dot holds standing goals, standing credentials and a computer of its own. That changes three things a security team cares about. First, effective permissions become the sum of every connector a user authorizes, and with 4,000+ apps available, that sum grows quietly. Second, timing: actions happen at 3 a.m. as easily as at noon, outside any human review window. Third, input surface: a dot that reads email, tickets and web pages also reads instructions hidden in them, so prompt injection becomes an operational risk rather than a demo trick.
OpenAI is aware of the stakes. CNBC’s DevDay coverage notes the launch came the day after OpenAI pulled GPT-6.1 Astra for failing its safety standards, and that Altman described the industry’s agent safety tooling as a good step but “not a full solution.” For buyers, that is a reason to design controls in from the start rather than retrofit them after an incident.
What it means for US & EU software teams
First, agent identity is now an IT problem. Each dot acts on behalf of a person through delegated OAuth grants and connectors. Identity teams need to know which agents exist, whose access they carry and how to revoke it in one step when someone changes role or leaves. Shadow agents will appear faster than shadow SaaS did.
Second, Slack and Teams become execution surfaces. Messages in a channel can now trigger work in other systems. Review which channels connect to external parties, and treat inbound content from customers or vendors as untrusted input for any agent that reads it.
Third, regulated data needs a decision before the toggle. For EU teams, GDPR accountability means you must be able to show what personal data an agent processed, on what legal basis and where. If a dot touches HR, health or customer records, run a data-protection impact assessment first. US healthcare and finance teams face the same question under HIPAA and their audit regimes.
Fourth, buy and build will coexist. Dots, along with the agents built on OpenAI’s platform and competing offerings from Microsoft, Salesforce and others, will cover much of personal productivity. Workflows that touch proprietary systems, customer decisions or strict residency rules will still need custom agents with your own logging and evaluation. Decide per workflow, not per vendor.
What to set up before Dots reach your workspace
- Keep the admin toggle off until there is a policy. Define who may enable dots, for which teams and with which connectors.
- Allowlist connectors. Start with read-only access to a short list of apps; add write access per use case, not per request.
- Require approval for consequential actions. Payments, external email, code merges, permission changes and data exports should need a human click.
- Log everything an agent does. Route agent activity into your SIEM with the agent and the human owner on every event.
- Test for prompt injection. Seed test emails, tickets and documents with hostile instructions and confirm the agent ignores them.
- Write an offboarding step. Revoking a person’s access must also stop and revoke every agent acting on their behalf.
Frequently asked questions
What are OpenAI Dots?
Dots are persistent AI agents OpenAI launched at DevDay on September 29, 2026. Powered by GPT-6 Astra, each dot has its own cloud computer, can connect to more than 4,000 apps, keeps working toward user-defined goals in the background and learns from feedback over time.
Who can use Dots today?
Dots are rolling out in ChatGPT to Pro and Business Premium users in eligible markets. OpenAI says Enterprise, Edu and Healthcare workspaces can try them once workspace administrators enable the feature, and that broader access will follow.
Can Dots work inside Slack and Microsoft Teams?
Yes. Users can message their dot in ChatGPT, Slack and Microsoft Teams, and OpenAI says text messaging support is coming soon. TechCrunch also reports integration with Microsoft Agent 365 security controls.
What is the main risk of always-on agents for companies?
Delegated access. A dot acts through the apps a user connects, so its effective permissions are the sum of those connections, and it acts while nobody is watching. Without least-privilege scopes, approval rules for consequential actions and an audit trail, an always-on agent becomes an always-on insider.
Should we build our own agents or adopt Dots?
It is not either-or. Dots suit personal and team productivity on top of standard SaaS. Workflows that touch regulated data, proprietary systems or customer-facing decisions usually need custom agents with your own identity model, logging, evaluation and data-residency controls. Map each workflow to one path before rollout.
Sources
OpenAI — Introducing dots (company announcement)
OpenAI — DevDay 2026 recap
TechCrunch — OpenAI launches Dots, its bubbly agentic avatar
CNBC — OpenAI DevDay recap: AI lab rolls out Dots agents