OpenAI launches Dots: always-on personal agents that work while you sleep
At DevDay in San Francisco, OpenAI unveiled Dots — always-on agents that work across 4,000+ apps, control your PC, and act before you ask. First Dot is free for Pro users.

Updated
Why it matters
- OpenAI announced Dots at DevDay in San Francisco: always-on personal agents that work continuously and can interact with more than 4,000 apps via OpenAI's plugin ecosystem.
- Rollout starts today for Pro and Business Premium subscribers in select markets; the first Dot is free, with unlimited chat in ChatGPT but normal usage limits in Codex and Work.
- Dots' background 'proactive research' is restricted to read-only tools that cannot send messages, change app content, or control the browser or computer, and saved passwords are never exposed to the underlying model.
OpenAI used its DevDay event in San Francisco today to announce Dots, a new class of always-on personal AI agents that the company says can work on your tasks continuously — sometimes before you even ask.
The launch lands at an awkward moment. OpenAI's AI agents have landed the company in hot water in recent weeks, and Dots are, by the company's own description, agents that nearly anyone can use to carry out tasks with minimal supervision. That tension — between expanding agent autonomy and demonstrating that autonomy can be made safe — is the backdrop for everything OpenAI showed on stage and in its announcement materials.
What a Dot actually does
OpenAI is pitching Dots as proactive, always-on AI systems that can chip away at tasks for you every hour of the day. The pitch is not a chatbot that waits for a prompt. It is a persistent worker embedded in your workflow, across devices and applications.
"The magic of dots is when they bring you work done the way you would do it, sometimes before you even think to ask," the company explains.
One example OpenAI cites comes from testing: a tester's Dot noticed they had forgotten to bill a publication for an article. The Dot prepared an invoice and, after obtaining the person's approval, sent it on their behalf. That example encapsulates the product's premise — the agent notices an oversight, prepares the corrective action, and gates the final step behind human approval.
The scale of what Dots can reach is significant. With access to OpenAI's ecosystem of plugins, Dots can interact with more than 4,000 apps. New integrations with Slack and Microsoft Teams mean users can converse with their Dot outside ChatGPT and outside the company's Codex and Work apps.
"Dots can do nearly anything using their own cloud computer, their own browser, and the apps you've connected," says OpenAI. The company adds that you can open your Dot's "computer" at any time to check up on what it is doing — a transparency mechanism aimed at users who want to audit their agent's behavior mid-task.
Dots are not confined to the cloud. OpenAI says it is possible to connect a Dot to your own PC, allowing it to control the machine on your behalf and work alongside you.
Who gets one, and how much it costs
At launch, Pro, Business, Premium and Enterprise users in select markets will get access to one primary Dot, which users can name and customize. OpenAI is rolling out Dots in select markets to Pro and Business Premium subscribers starting today, with the first Dot free for those tiers.
Chatting with the Dot inside ChatGPT is unlimited. Usage limits in Codex and Work apply as normal, so heavier agent-driven work in those products still runs up against existing quota walls.
The single-Dot limit is temporary, according to the company's roadmap. In the future, OpenAI envisions giving users the ability to control teams of Dots — multiple agents operating in parallel, presumably dividing a workload the way a human team would.
How people are expected to use them
OpenAI sketches two concrete scenarios. A scientist might task their Dot with integrating new data into a paper as they collect it through lab tests — the agent keeps the manuscript current while the experiments run. A developer could use their Dot to collect feedback from users of their app or service, then task the agent with writing bug fixes and new features in response to those requests.
Both examples point in the same direction: Dots are aimed at knowledge workers whose output is continuous and incremental, where an agent acting in the background can compress the loop between input and finished work.
Interaction is deliberately conversational. "Working with your dot is as simple as having a conversation," explains OpenAI. "You can message or call dots in ChatGPT on desktop, web, and mobile. They can also message you with progress, questions, or decisions that need you." Dots carry context across every surface where you interact with them — a conversation started on mobile can continue on desktop without the agent losing the thread.
Safety architecture — and why OpenAI is leading with it
Given OpenAI's recent security track record, the company is keen to highlight the safety features built into Dots. The company is aware that the credibility of this launch rests on whether the guardrails are legible to users, not just present in the code.
Credential handling is one area OpenAI addresses directly. When signing into websites, the company says Dots can use your saved passwords without exposing them to the underlying model. The agent can authenticate as you without the model itself ever seeing the secret.
The second area is proactive research — the feature that allows Dots to complete tasks in the background without you watching. OpenAI has integrated safeguards into that feature. "It does this by using the apps you've already connected with tools that are restricted to be read-only, which means that they can't send messages, change app content, or control your browser or computer," says OpenAI. In other words, unsupervised background activity is capped at observation; anything that modifies the world requires the connected, supervised path.
Permission management rides on infrastructure OpenID users already know. Users manage a Dot's permissions through ChatGPT's existing app controls, and the default posture is deliberately conservative.
"Dots start with built-in rules for when to act independently and when to ask for approval," says OpenAI. Users can write their own custom rules to set what specific actions require approval — a policy layer that lets cautious users lock down their agent tightly while power users grant broader autonomy.
The stakes
The commercial logic here is straightforward. OpenAI is moving its subscription products from answering questions to completing work — a shift that justifies premium pricing and deepens lock-in, since an agent wired into 4,000 apps and your own PC is not easy to relocate to a competitor.
The risk logic is equally straightforward. An always-on agent that can send invoices, control your computer, and message colleagues is also an always-on surface for errors and abuse. OpenAI's read-only restriction on background research and its approval-rule system are the company's answers to that risk, and they will be tested in the field by the same users the agent acts on behalf of.
What comes next is already on the roadmap: multi-Dot coordination. OpenAI's stated vision of users controlling teams of Dots would multiply both the productivity on offer and the blast radius of any single misfiring agent — the two quantities that this entire product category will be judged on.
Source: Engadget
More from Rebecca Stone
Show full bio
Correspondent covering consumer brands and retail at AI In Context.
157 articles
Related articles
- OpenAI Launches Dots, Always-On AI Agents, at DevDay 2026
- OpenAI launches Dots, its answer to Meta's Muse
- OpenAI's ChatGPT Spaces Turns the Chatbot Into a Shared Workplace
- OpenAI Launches Workspace Agents in ChatGPT for Teams
- OpenAI launches Presence, an enterprise agent platform that resolves 75% of its own support calls