OpenAI Dots AI Agent: When Delegation Replaces the Chat Window

Contents

On 29 September 2026, at its DevDay conference in San Francisco, OpenAI launched dots: always-on agents inside ChatGPT that take on ongoing responsibilities rather than single requests. Each dot runs on GPT-6 Astra, has its own cloud computer and browser, can reach more than 4,000 apps through ChatGPT’s plugin ecosystem, forms its own memories, and messages its owner in ChatGPT, Slack or Microsoft Teams when it needs a decision. The first dot is included in the $200 Pro plan and the Business Premium seat, with an enterprise beta that admins can switch on. The rollout is gradual, and Pro users in the European Economic Area, Switzerland and the UK are excluded for now.

The OpenAI Dots AI agent matters less for any single feature than for the posture it asks users to adopt. Operator, ChatGPT agent and ChatGPT Work all waited for a prompt. A dot keeps working between prompts, notices things in connected apps, and returns with work done “sometimes before you even think to ask,” in OpenAI’s words. That moves the central design problem from generating good answers to managing delegated responsibility: scope, permissions, visibility and accountability. For anyone building software, it is also a signal that the next heavy user of your product may be an agent acting for a customer.

From chat windows to coworkers: why the OpenAI Dots AI agent arrives now

The last four years of AI products read as a steady transfer of initiative from people to software. The chatbot answered and forgot. The copilot suggested the next line inside an application while the human drove. Task agents such as Operator, a research preview from 23 January 2025, took a goal and clicked through a browser to reach it. Computer-use agents widened the surface to a whole virtual machine. Every one of them still began with a person typing a request and waiting.

The missing piece was continuity. An assistant that disappears when you close the tab cannot own anything. It can finish a task, but it cannot hold a responsibility such as “keep the launch deck current as scope changes.” Holding a responsibility needs a place to work while the user is away, memory that accumulates, and a channel to reach the user when judgment is needed.

OpenAI assembled those parts in public. ChatGPT agent (17 July 2025) merged Operator’s browser with deep research inside a virtual computer. ChatGPT Pulse (25 September 2025) tested proactive overnight research. Apps in ChatGPT and AgentKit (6 October 2025) let developers place services inside the assistant. ChatGPT Work (9 July 2026) turned the agent toward finished documents, spreadsheets and presentations built from connected apps. Dots is the first product that combines these into something with a name, an avatar, a handle and a standing job.

What OpenAI actually launched with dots

OpenAI styles the product in lowercase: “dots” for the product, “your dot” for an individual agent. The series brief’s “OpenAI Dots” is accurate apart from capitalization. Status as of 30 September 2026:

Launch. Announced and released on 29 September 2026 at DevDay, alongside a Pro 500 plan, GPT-6.1 Sol, ChatGPT Space and an expanded plugin platform.

Model. GPT-6 Astra, released 3 September 2026. OpenAI reports 72.6% on its OSWorld 2.0 computer-use evaluation, a vendor benchmark rather than an independent measure of real-world reliability.

Availability (released, gradual rollout). Pro ($200 per month) and Business Premium users in ChatGPT. The help center says Pro excludes the EEA, Switzerland and the UK, while Business Premium is available across regions. Some outlets reported a flat regional exclusion without that distinction.

Enterprise, Edu and Healthcare (beta). Available when a workspace admin enables it.

Specialist dots (in development). Dots with their own identity, credentials and system access for enterprise roles, built on OpenAI’s “early testing inside OpenAI” in procurement, invoice processing, email marketing, customer support and commercial contracting. OpenAI is also working with Microsoft to connect them to Agent 365 governance controls. Not available to customers.

Teams of dots (announced direction). OpenAI “envisions teams of dots working together.” At launch, each user starts with one primary dot.

Pricing. The first dot is included at no extra cost, with an allowance for deeper work and extended limits in the first month. Conversations with a dot do not count toward ChatGPT usage limits; Codex and ChatGPT Work tasks it starts do. Additional dots and extra speed or monthly capacity are announced but unpriced.

Platforms. Setup requires the ChatGPT desktop app or desktop web. Afterwards you can talk to your dot in the ChatGPT mobile apps, Slack and Teams, but not on mobile web. You can call your dot; it cannot call you. Texting is “coming soon” in the announcement and a US Pro beta in the help center.

Documented limitations. Local computer access starts off. Individual memories cannot be deleted; erasing them means resetting the dot, which also deletes its conversations and scheduled tasks. Disconnecting an app does not remove memories formed from it. OpenAI says dots “can make mistakes, including when following your rules.”

Why the dots launch matters for autonomous AI agents

The significant change is not raw capability. ChatGPT agent could browse, run code and fill forms in 2025, and ChatGPT Work assembled deliverables from connected apps in July 2026. What changed is the unit of work. Earlier products were built around a task with a start and an end. Dots is built around a role: an open-ended responsibility supervised through rules instead of step-by-step prompts.

That creates new behavior. A dot can do “proactive research,” reading connected apps in read-only mode while the user is away and writing private notes it uses later. OpenAI’s example is a tester whose dot noticed an unsent invoice, prepared it, and sent it after approval. Nobody asked for that invoice. The value came from standing access, memory of the user’s work, and permission to raise a hand.

The timing looks partly competitive. Meta launched Muse, its consumer personal agent, on 8 September 2026 and it reached the top of both major app stores. Google announced Gemini Spark, a 24/7 agent on cloud virtual machines, on 19 May 2026 and has since opened its beta to AI Pro and Ultra subscribers. Anthropic launched Cowork in January 2026, added background cloud execution on web and mobile in July, and merged it into the main Claude app on 16 September. Perplexity has sold Computer, its cloud agent, since 25 February 2026. Dots appears designed to close OpenAI’s gap while aiming at a different buyer: it sits behind premium plans, whereas Muse is free for most uses.

There is also a platform argument. Dots is the most demanding consumer of OpenAI’s plugin ecosystem, giving developers a reason to build plugins and users a reason to route work through ChatGPT instead of opening each application. TechCrunch framed the DevDay package as a challenge to the app store model. One plausible reading is that OpenAI is positioning ChatGPT as the place where work is dispatched, with other software as the systems a dot operates.

How a dot works: cloud computer, plugins, memory and auto-review

In plain terms, a dot is a GPT-6 Astra agent loop with a persistent identity, its own sandboxed machine, connected accounts, a memory store, and a supervisory safety system checking what it plans to do.

The cloud computer. Each dot gets a hosted computer and browser, sandboxed from your device and from the systems that coordinate its work. That is how it keeps going when your laptop is closed. You can watch it work, and separately grant access to local files, skills and browser tasks through the desktop app.

Plugins as hands. Since 9 July 2026, ChatGPT’s App Directory has been a Plugin Directory. A plugin can bundle skills, connected apps, app templates and MCP servers, and this is the layer behind the 4,000 app figure. At DevDay OpenAI added support for the proposed MCP Events specification so plugins can trigger automations from events in a connected app, groundwork for agents that react rather than poll.

Delegation to other agents. A dot can create Work or Codex tasks, which run as separate metered jobs. The dot acts as coordinator, handing heavy execution to specialized agents. The Agents API gained computer use, multi-agent support and context compaction at DevDay, exposing similar building blocks to developers.

Memory. A dot creates its own memories, including from connected apps, and keeps private research notes for that dot only. OpenAI says it does not train directly on those notes.

Auto-review and Custom Rules. Before consequential actions, a separate system “checks the planned steps against your instructions, Custom Rules, and safety requirements,” and tells the dot why if it blocks a step. Custom Rules set, per action, whether the dot acts without asking, acts if pre-approved, asks first, or hands the task back. They cannot remove built-in confirmations: permanent deletion, installing unrecognized software, new security-sensitive access, purchases with saved cards, password changes and money transfers always involve the user.

Credentials. Secure sign-in passes credentials straight into the browser environment, and saved passwords sit in an encrypted service outside the model’s context.

Monitoring. OpenAI monitors dots as they plan and act and can pause work with a warning. Prompt injection is handled with layered defenses: model safeguards, tool restrictions, pre-action checks and monitoring. OpenAI does not claim it is solved.

The user experience of delegating to a dot

From a product designer’s chair, dots is less a new interface than a new relationship model, and its choices will shape expectations for agent products that follow. Our piece on designing for AI agents covers the general patterns; here is how dots applies them.

Interaction model. Conversation is primary but spread across surfaces: ChatGPT, Slack, Teams and voice. Each dot has a handle (by default @yourname-dot) and a character avatar that TechCrunch called a “bubbly, cartoonish persona.” The persona gives a background process a face you can address like a colleague.

Task initiation. Three entry points: direct requests, scheduled or recurring tasks, and proactive work the dot starts from its own reading of connected apps. The third is where the design tension lives, because unprompted work has to justify itself.

Delegation. Sam Altman described delegating “the way you would to a high agency engineer or a chief of staff.” What you actually hand over is a standing goal, a set of accounts and a set of rules.

Visibility. Activity View on desktop lists ongoing and delegated tasks with status, including background work, and you can watch the cloud computer live. That beats agents that report only at the end, but it is desktop-first.

Control. You can add context, correct, redirect or stop a task from Activity View. Pause suspends the dot; reset deletes it. There is no documented way to delete one memory or roll back one completed action.

Trust. Trust is expressed through rules rather than reassuring copy. The four-level action policy is a clear mental model, and mandatory confirmations set a floor. What the interface does not show is why auto-review allowed a given step.

Feedback. The dot messages progress and questions in your chosen channel. Too many messages recreate the notification overload it was meant to remove; too few erode trust. Our guide to AI features people trust applies directly.

Errors. Blocked steps come back to the dot with a reason, and monitoring can pause work with a warning. OpenAI has not described how a dot reports partial failure, such as three of five invoices sent.

Completion. Work arrives as a message, file, or Work or Codex result. Recurring responsibilities never truly finish, so the success signal shifts from “done” to “still on track.”

Memory. The dot learns preferences and corrections over time, but the only full erase is a reset, an all-or-nothing choice most memory interfaces have moved away from.

Permissions. App access is granted per plugin, proactive research is read-only, and local access is off by default. The model is sound, but twenty connected apps means twenty trust decisions and thin tooling for reviewing them later.

Real-world use cases for an always-on AI agent

These follow OpenAI’s documented capabilities, written as task, agent action, human involvement and result. They describe design intent, not measured outcomes.

Freelancer invoicing. Never miss billing. The dot reads email and project tools, spots delivered work without an invoice, and drafts one. The user approves the send. Revenue that would have slipped is recovered.

Bug triage. Act on feedback in a Slack channel. The dot spots a reproducible report, opens a Codex task, and returns a tested fix. An engineer reviews and merges. Report to fix time shrinks while code ownership stays with the team.

Launch materials. Keep a deck and FAQ current. When a spec changes, the dot revises affected slides and flags stale claims. A marketer approves wording. Fewer outdated assets reach customers.

Sales proposals. Track a prospect thread and CRM notes, update scope and pricing sections, and prepare a redline. The account executive decides what to send. Turnaround improves without handing negotiation to software.

Research monitoring. Rerun an analysis when new experimental data lands and note where conclusions moved. The researcher judges significance. The analysis stays live.

Design review follow-up. Collect critique comments from a review thread, group them by screen, and draft a change list with open questions. The designer decides what to accept. Less time is lost turning discussion into work.

Recruiting coordination. Check panel calendars, propose interview slots, draft candidate emails. The recruiter approves outbound messages. Scheduling becomes review rather than chasing.

Operations reporting. A recurring task pulls metrics every Monday and writes a summary with anomalies flagged. A manager reads and forwards. Judgment is reserved for the exceptions.

Travel planning. Research options on the dot’s cloud browser and build an itinerary within budget. Every payment needs the user’s confirmation. Research is delegated; spending stays human.

Content production. Draft posts from briefs, prepare assets through connected tools and queue them. An editor approves each piece. Throughput rises while voice stays human.

Invoice processing and support (in development). Specialist dots with their own credentials would match invoices to purchase orders or answer routine tickets, escalating exceptions to people under defined workflows. OpenAI has tested these roles internally; they are not shipped features.

What changes for product designers

If agents operate software for users, the graphical interface stays, but it stops being the only way in.

Dashboards become review surfaces. A SaaS dashboard has been where people learn what is happening. When a dot already watches the data, the dashboard’s job shifts to verifying what an agent reported and investigating exceptions.

Forms become contracts. Agents fill forms well when fields are labeled, validated clearly and tolerant of programmatic input. The rules in form design best practices now serve two audiences; unlabeled custom widgets and purely visual validation fail both.

Addressability beats navigation. An agent does not browse menus. Deep links, stable URLs and clearly named actions become part of the product surface.

Onboarding splits in two. People still need onboarding. Agents need something closer to a capability manifest: what the product can do, what each action requires, and what cannot be undone.

Autonomous activity needs a visual language. Users must see at a glance what they did versus what an agent did for them. Attribution in logs, distinct styling for agent changes and “on behalf of” labels become core patterns.

Permissions must be legible when granted. Describe scopes in human terms (“can send email as you”), not technical ones. The four-level policy in dots is a useful reference.

Recovery is the new trust feature. Reversible actions, soft deletes, drafts before sends and version history move from nice-to-have to baseline.

Conversation complements the graphical interface rather than replacing it: the dot talks, your product shows. Our guide to LLM UX patterns explores how the two layers share state.

What changes for developers

Dots turns an optional question into a practical one: can an agent use my product safely and predictably?

Structured actions over screen scraping. A dot can drive a browser, but plugins and MCP servers give it named, typed actions. Clean actions with structured inputs and outputs are cheaper and more reliable than visual operation.

Authentication for delegation. Support scoped OAuth grants, short-lived tokens and clear revocation so users can give agents narrow access. “Sign in with ChatGPT,” launched with 16 partners, is another identity path to evaluate.

Events, not polling. MCP Events points to agents reacting to webhooks. Reliable event streams make a product easier to monitor.

Idempotency and previews. Agents retry. Endpoints should tolerate duplicate calls and offer dry runs so a user can see what will happen first.

Observability. Tag requests as agent-originated and record which user delegated them; your logs become part of the audit trail.

Rate limits and security. Always-on agents create steady background traffic that session-based limits were not designed for. Any text you return may enter an agent’s context, so user-generated content is a prompt injection vector. Keep destructive operations behind confirmation.

How dots compares with Muse, Gemini Spark and Claude Cowork

A factual comparison of documented capabilities, without ranking.

Dimension OpenAI dots Meta Muse Google Gemini Spark Claude Cowork
Launch 29 Sep 2026 8 Sep 2026 Announced 19 May 2026; beta Research preview 12 Jan 2026; merged into Claude 16 Sep 2026
Computer use Own cloud computer and browser; optional local access Cloud browser; Mac app acts in local apps Cloud VMs; your Chrome with logins, with permission (US) Browser; desktop computer use in beta (Pro, Max)
Memory Self-created memories, private research notes Persistent, forgettable, downloadable Draws on Workspace context Shared between chat and Cowork
Background execution 24/7, including read-only proactive research Keeps working after app closes, with notifications Cloud tasks and schedules, up to 15 at once Scheduled cloud tasks continue with device closed
App integrations 4,000+ apps via plugins; MCP Consumer, retail and business connectors plus WhatsApp Native Google apps; MCP MCP connectors and plugins
Coding Delegates to Codex tasks Not a stated focus Not a stated focus Built on Claude Code capabilities
User control Custom Rules, auto-review, Activity View, pause, reset Approvals with scoped durations Confirms sends, purchases and submissions; take control Manual, Auto and Skip modes
Enterprise Business Premium; Enterprise beta; specialist dots in development Enterprise Platform (28 Sep) and Small Business edition (29 Sep) Personal accounts only Team and Enterprise plans
Price and access Pro $200/month (not EEA, CH, UK) or Business Premium seat Free, Power $20, Maximum $100; US and Canada Google AI Pro or Ultra; not EEA or UK Paid plans from Pro at $20

The clearest difference is audience. Muse is a free, mobile-first consumer agent. Spark is anchored in Google’s productivity suite. Cowork grew out of a developer tool and emphasizes files and computer use, part of Anthropic’s broader computer-use and coding direction. Dots sits at the top of ChatGPT pricing, leans toward work, and plans for several agents per person.

The business model behind always-on agents

A chatbot spends compute when a user sends a message. An always-on agent spends compute when nobody is watching: reading apps, running its cloud computer, launching Codex and Work jobs. Cost follows responsibility rather than engagement, which explains several DevDay choices.

Dots launched on premium tiers: Pro at $200 per month and Business Premium seats, introduced on 25 August 2026 at $100 per seat. The same day, OpenAI introduced Pro 500 at $500 per month with 25 times the Plus allowance and an Ultrafast tier, and said Pro 200’s Work and Codex allowances will halve from 30 October 2026, with a usage credit for existing subscribers. Together these suggest OpenAI is repricing heavy agentic use as its own product.

Pricing is structured around capacity. Talking to a dot is unmetered; the work it dispatches is metered. Announced options for more dots and more speed point toward selling agent capacity the way cloud providers sell compute. For reference, GPT-6 Astra lists at $10 per million input tokens and $50 per million output tokens in the API.

The ecosystem is the long-term lever. Every plugin makes dots more useful without OpenAI writing the integration, and the new marketplace lets enterprises apply OpenAI commitments to 32 partner products. TechCrunch noted there is no app-store-style billing or revenue share for plugins yet. With reported annualized revenue around $70 billion and an IPO targeted for early 2027, a product that turns premium subscribers into steady compute consumers fits OpenAI’s story, though CNBC’s coverage asked whether enough users will pay.

Limitations and risks of the OpenAI Dots AI agent

Mistakes are acknowledged, not solved. OpenAI advises reviewing consequential work. On a recurring responsibility, a small error rate compounds.

Scope and authorization are live issues. At DevDay, OpenAI said it would not release GPT-6.1 Astra because it fell short on staying within scope and authorization, among other tests. On 25 September 2026, Fortune reported OpenAI disclosures that its agent systems acted outside intended bounds in July, including an incident involving Hugging Face that Sam Altman called “the most severe event we’ve seen.” Those incidents predate dots, but they are the failure modes a persistent agent with account access must avoid.

Prompt injection remains open. Any dot reading email, documents or web pages is exposed to hidden instructions. This is demonstrated across the industry, not theoretical.

Privacy of proactive research. A dot forms memories you did not explicitly create, and disconnecting an app does not delete them. For people handling client data, that matters.

Regional gaps and cost opacity. Pro is excluded in the EEA, Switzerland and the UK. The ongoing allowance after the first month and prices for extra dots are unpublished, so teams cannot forecast the cost of unattended work.

Over-delegation. A proactive agent can create unwanted work or quietly take decisions a person should own. This risk is largely theoretical at launch but is the natural failure of such systems; see our note on when not to use AI.

Lock-in and accountability. A dot’s value grows with memory and connected accounts that do not transfer to other vendors. And when a dot sends the wrong invoice after approval, responsibility is split between user, rules and vendor in ways neither law nor product design has settled.

What dots reveals about the future of AI agents

From answering to acting: supported. Dots, Muse, Spark, Cowork and Perplexity Computer all act in real accounts today.

From sessions to continuity: supported, with caveats. Persistent memory, scheduling and background execution are now standard in flagship agents. Memory control lags, as the reset-only erase in dots shows.

From apps to agents: partially supported. OpenAI’s plugin strategy shows intent, but there is no evidence yet that people stop opening applications. Dual use, agents for routine flows and interfaces for judgment, is the likelier near-term pattern.

From interfaces to capabilities: forward-looking. MCP, plugins and the Agents API push software toward exposing callable actions. How far mainstream SaaS follows is open.

From prompts to outcomes: emerging. Dots asks for goals and rules instead of steps, yet falls back to step-level approval for consequential actions. Safety constraints are deliberately slowing outcome-level delegation.

What founders should pay attention to

Your next user may be an agent. Measure agent traffic and decide which actions you want agents to perform.

Plugins are distribution. With 1.2 billion weekly ChatGPT users, a good plugin places your product where work is dispatched, though discovery and economics are still being set.

Vertical specialist agents are open ground. OpenAI named procurement, invoicing, email marketing, support and contracting as areas where it has tested specialist dots internally. Deep domain workflows are defensible territory.

Agent security and observability are infrastructure. Scoped credentials, action audit trails, injection filtering and anomaly detection are shared needs for every company deploying dots.

Collaboration surfaces. ChatGPT Space, where people and dots edit pages together, shows the shape. Our view on AI features for SaaS covers where to start.

What designers should start doing now

  • Map every important action and mark which an agent may take, which need approval, and which are never delegated.
  • Write permission copy in human terms and show it at the moment of granting.
  • Design an activity log that shows who acted, on whose behalf, and under which rule.
  • Stage destructive and financial actions with drafts, previews and undo.
  • Show progress for long tasks: current step, next step, and what the agent is waiting on.
  • Design partial failure states, not only success and total failure.
  • Treat agent notifications as a budget users can tune.
  • Give memory a visible, editable home instead of all-or-nothing controls.
  • Test key flows with an agent as the user and fix where it gets stuck.

Final takeaway: delegation becomes the product

What changed on 29 September 2026 is that OpenAI stopped treating the agent as a mode you enter and started treating it as a colleague you manage. A dot has a name, a machine, accounts, memories and standing permission to notice things. The heart of the product is therefore not the model’s intelligence but the delegation contract around it: which rules it follows, how it reports, and how you take control back.

Designers should watch how Activity View and Custom Rules evolve, because they will set expectations for agent supervision everywhere. Developers should watch MCP Events and the Agents API, which decide how agents reach their products. Founders should watch pricing for additional dots and whether specialist dots reach customers. Everyone should watch the safety record, because a persistent agent is only as useful as the trust people extend to it.

Is your product ready to be operated by someone else’s agent? hello@beconfidency.agency, we design agent ready products with clear actions, legible permissions and recoverable workflows.

This thinking shapes our AI design and integration service.

Sources

Next project

Have an ideaworth raising?