Abstract glowing digital assistant connected to a cloud computer, email, calendar, document and code icons, with a human hand holding an approval token.

Illustration of a persistent AI agent using a dedicated cloud computer with a human approval step. Credit: Illustration: Unhyd

AI

OpenAI Launches Dots, Its Always-On AI Agents

OpenAI’s DevDay release turns the AI-agent idea into a persistent, connected work companion—while making permissions, memory and review harder to ignore.

By Unhyd Editorial Staff
September 30, 2026 · Updated

Add Us On Google (opens in a new tab)

OpenAI’s new Dots push the AI-agent conversation beyond a chat window. Announced at DevDay on 29 September, Dots are designed to keep working between conversations on a user’s behalf. OpenAI says each one runs on its own cloud computer, can use a browser and connected apps, and can retain context across ChatGPT, Slack and Microsoft Teams. The change is not simply a new assistant personality. It is a product bet that people will trust software with a standing brief, an execution environment and enough context to return with work when no prompt is open.

That is why the launch matters to anyone following how AI changes work. The useful question is no longer only whether a model can draft, search or code in a single session. It is whether a persistent system can do those things over time without accumulating too much access, memory or unreviewed authority. OpenAI’s product announcement says Dots are powered by GPT-6 Astra and can connect to more than 4,000 apps through plugins. The company is beginning a rollout to Pro, Business Premium and eligible Enterprise users.

What always-on AI agents change

A conventional chatbot waits for a question. A persistent agent can hold a goal, watch for new information and decide which next step is useful. In OpenAI’s examples, that can mean turning recurring customer feedback into proposed fixes, revising launch material when requirements change, or rerunning research analysis when data arrives. Those are examples rather than guarantees, but they reveal the design shift: the product is organized around continuing responsibility rather than isolated answers.

Dots also separate the agent’s workplace from the user’s laptop by default. The dedicated cloud computer is intended to be inspectable, while access to a local computer starts turned off and requires the user to enable it. That distinction is important, but it should not be mistaken for a blanket security conclusion. An agent with connected apps, saved context and a continuing task can still create a broad operational footprint even if it never touches a local desktop.

The control model matters as much as the capability

OpenAI describes several guardrails. Background “proactive research” uses connected apps in read-only mode; the company says those tools cannot send messages, change app content or control a browser or computer. Users can choose connected apps, inspect activity, set custom rules to allow, pre-approve, require approval for, or hand off certain actions, and pause the agent. OpenAI also says some sensitive actions, including password changes, remain with the user. These are sensible product controls, but they are controls described by the vendor, not an independent audit of every workflow a Dot might be asked to run.

That distinction is practical rather than cynical. The moment an agent reads a shared inbox, reviews customer data or prepares an external action, its risks are shaped by permissions and process design as much as by the underlying model. Unhyd’s guide to testing AI agents before scaling argues for reviewing outcomes, evidence, tool use and approval behavior together. Its permission-first security guide makes the companion point: an agent should receive only the authority necessary for a defined job.

What the rollout does—and does not—make available

Availability is phased. OpenAI’s Help Center says Pro access starts in markets excluding the European Economic Area, Switzerland and the UK; Business Premium is available across supported ChatGPT regions; and Enterprise access is a beta that workspace administrators must enable. Access may take days to appear. This is not a broad consumer rollout, and it is not a promise that every agent feature will work identically across plans or regions.

Teams should also read the fine print around information persistence. A Dot can form memories from connected apps, and disconnecting an app does not erase information it has already obtained. The Help Center says deleting the Dot is the route for deleting its conversations, saved memories and scheduled tasks. That is a concrete governance requirement: organizations need a clear owner for setup, connection reviews, retention decisions and offboarding—not only a clever instruction at the start of a project.

What to watch next

Dots arrive as many vendors are trying to make agentic software feel ordinary: a colleague-like presence rather than a sequence of automations. The appeal is clear. A system that can preserve context and carry work forward could reduce the overhead of handoffs, follow-ups and routine monitoring. The test is whether that continuity can be bounded. Early deployments should begin with a narrow, reversible workflow; read-only access where possible; explicit approval for external, financial, destructive or privileged actions; and logs a human can actually review.

OpenAI’s release gives that discussion a high-profile product form. It does not remove the need for organizations to decide which work should be delegated, which information should be reachable, and which outcomes still require a person to decide. The most meaningful metric will not be how personable a Dot appears. It will be whether a team can explain what its agent was allowed to do, what it did, and how it could be stopped when the context changed.

Sources