Disclosure: This is not a hands-on review. I'm based in mainland China, which isn't a supported ChatGPT region, so I haven't used dots. Everything below comes from OpenAI's official blog post, Help Center article, and privacy/security FAQ (linked at the end). The one exception is pricing, which comes from WIRED's reporting and is marked as such. The companion video is AI-assisted (it includes AI lip-synced presenter footage); promo visuals are © OpenAI.
TL;DR
dots are OpenAI's "always-on agents", announced on 2026-09-29. Each dot is powered by GPT-6 Astra, has its own cloud computer and browser, and can reach 4,000+ apps through plugins.
Rollout: Pro (outside the EEA, Switzerland, and the UK), Business Premium (all supported regions), Enterprise/Edu/Healthcare as an admin-enabled beta. Not available to users under 18.
Setup happens on desktop only (ChatGPT desktop app or desktop web at chatgpt.com/dots); after that, mobile works.
The design is interesting because of the layered permission model: read-only background research, opt-in local machine access, four-level Custom Rules, mandatory human takeover for passwords and money transfers, and an automatic pre-action review.
What a dot actually is
From the Help Center, the difference from a normal ChatGPT conversation is ongoing responsibility: a dot "can take on ongoing responsibility and keep making progress between conversations." Concretely:
Capability
Source says
Model
GPT-6 Astra
Execution environment
Its own cloud computer and its own browser
Integrations
4,000+ apps via the plugin ecosystem; plugin permissions are shared across dots, ChatGPT, ChatGPT Work, and Codex
Channels
ChatGPT on desktop, web, and mobile (messages and voice calls), Slack, Teams
Outbound calls
Not supported at launch ("Your dot cannot initiate calls to you")
Texting
Blog: "coming soon"; Help Center: limited beta for US Pro users via a third-party provider. (The two pages differ, so treat it as not generally available.)
Codex
Can create cloud tasks in Codex cloud environments you've already created
You assign work in plain language ("review my calendar each morning and tell me what's coming up"), and track it in the dot's profile under In progress / Scheduled / Completed. You can also open the dot's cloud computer to inspect or interact with it, and the desktop Activity View shows ongoing and delegated tasks plus the steps taken.
Availability and billing
Pro: rolling out from Sept 29 in markets excluding the EEA, Switzerland, and the UK.
Business Premium: all supported ChatGPT regions.
Enterprise (incl. Edu, Healthcare): beta, off by default, enabled by a workspace admin.
Rollout is gradual; access "may take several days to reach your account."
Under 18: not available.
Your first dot is included in Pro or Business Premium at no extra cost.
For the next month, dots usage won't count toward eligible Pro, Business, and Enterprise plan allowances.
Conversations with your dot don't count toward ChatGPT usage limits; tasks it starts in Codex or ChatGPT Work do count as usual.
Price: WIRED reports Pro at $100/month. I couldn't find that number on OpenAI's official pages.
Setup (the official four steps)
Create your dot in the ChatGPT desktop app (macOS or Windows) or desktop web (chatgpt.com/dots). You can't create one on mobile; mobile web isn't supported.
Follow onboarding: name it (default handle @yourname-dot, which becomes @yourname-agentname), pick a character or a pet.
Connect apps from the Plugins screen and review each app's permissions first.
Let it introduce itself. After initial setup, you can message it in the ChatGPT mobile app.
The permission model (the part developers should read)
This is where the docs are most detailed. I'd summarize it as defense in depth with a human in the loop for irreversible or financial actions.
- Background work is read-only
When you're not actively working with it, a dot does "proactive research" over your connected apps. Those tools are restricted: they cannot send messages to other people, change content through plugins, or control a browser or computer. Any follow-up action goes through the normal action rules and safety checks. Custom Rules can't lift this restriction.
- Your machine is opt-in
The dot runs on its own cloud computer. Local computer access "is optional and starts turned off." You connect from the ChatGPT desktop app on that machine and confirm Allow access; Revoke access turns it off. Camera, microphone, or screen access additionally require OS-level permission for the ChatGPT app.
- Custom Rules: four behaviors
For supported actions, you pick one of:
Take action without asking
Take action if pre-approved # "pre-approved" = you explicitly requested it in your prompt
Ask before taking action
Hand off to you
Custom Rules cannot turn off core safety requirements, the separate Auto-review system, or the proactive-research restrictions.
- Tiered sensitive actions
From the privacy/security FAQ:
Changing a password or transferring money → you must take over and complete it yourself.
Permanently deleting data or installing software → may require approval each time.
Purchases with a card saved on a merchant's site → require your approval (can be given in advance if it specifically covers the purchase).
Approving one message does not grant ongoing permission to contact people.
- Auto-review before side effects
Actions that could affect your accounts or share information are checked against your instructions, Custom Rules, and safety requirements. Example from the FAQ: before sending an email, Auto-review checks the recipient and message to catch a wrong address or unintended disclosure. If blocked, the dot may ask for clarification/approval, try a permitted alternative, or stop — and your approval can't override core safety requirements.
- Credentials never hit the model (for supported flows)
For supported sign-ins, the dot pauses and you enter credentials in a secure form that sends them directly to the browser environment, "without exposing them to the model." Passwords pasted into chat, docs, or plugins are not covered.
- Prompt injection: mitigated, not solved
The FAQ is explicit that web pages, emails, or documents may contain instructions aimed at the agent. Content it encounters "does not grant permission on its own," and there are tool restrictions, automatic checks, approvals, and monitoring — but these "help reduce the risk … they do not eliminate it."
- Memory: coarse-grained controls (for now)
Pause from the profile's ••• menu.
Reset deletes the dot, including conversations, saved memories, and scheduled tasks.
You cannot view, delete, or edit individual dot memories today.
Disconnecting an app stops new access but doesn't delete what the dot already built into its context.
Memory can flow between ChatGPT and the dot; turning off ChatGPT Memory stops sharing but doesn't delete what the dot already received.
- Data use
Business, Enterprise, and Edu workspace data isn't used for training by default. On personal plans, the "Improve the model for everyone" setting applies. OpenAI says it doesn't train directly on proactive research or the dot's notes to itself, though that information may be used if it informs an eligible conversation or task, depending on settings.
Specialist dots (preview)
OpenAI is also previewing specialist dots for organizations: each gets its own identity, credentials, and system access for a well-defined responsibility. OpenAI says it tested this internally across procurement, invoice processing, email marketing, customer support, and commercial contracting, and is starting with focused enterprise pilots. It's also working with Microsoft to bring specialist dots into Microsoft Agent 365 governance. This is a preview/pilot, not general availability.
Takeaways
The interesting engineering is the boundary, not the autonomy. Read-only background research + pre-action review + mandatory human takeover for credentials and money is a clear pattern for anyone building agents.
"Pre-approved" is scoped to explicit intent. Approval is per-action and limited to what you authorized — a useful model for consent design.
Memory governance is the weak spot. No per-item deletion, and disconnecting a data source doesn't purge derived context. If you connect email or calendar, plan for that.
Humans keep the final say — and the wallet. The agent can do nearly anything; paying and deciding stay with you.
Sources
OpenAI — Introducing dots (2026-09-29): https://openai.com/index/introducing-dots/
OpenAI Help Center — Getting started with your dot: https://help.openai.com/en/articles/20001530-getting-started-with-your-dot
OpenAI Help Center — Dots privacy, security, and safety FAQs: https://help.openai.com/en/articles/20001529-dots-privacy-security-and-safety-faqs
OpenAI launch video — Introducing dots: https://www.youtube.com/watch?v=uXspbC2srEQ (footage © OpenAI)
Pricing: WIRED's reporting (not on OpenAI's official pages)
Companion video (Mandarin, 6 min): https://www.youtube.com/watch?v=YOUR_VIDEO_ID — AI-assisted production; not affiliated with or sponsored by OpenAI.
Top comments (1)
Some comments may only be visible to logged-in visitors. Sign in to view all comments.