The Field GuideAI Explained

OpenAI Dots: the pros and cons of always-on AI agents

On 29 September 2026 OpenAI launched dots, agents that keep working after you log off. What they do, who can use them in Canada, what went wrong before launch, and how a small business should approach one.

By Adi Huric, founder of Most AI LabsSeptember 29, 202610 min read

On this page
    Did OpenAI rename agents?What OpenAI actually launchedWho can use dots in Canada, and what it costsThe case for dotsThe case against dotsWhat this means for a small businessOur viewSources

OpenAI used its DevDay event on 29 September 2026 to launch dots: AI agents with their own computer that keep working on your goals around the clock, even when you are not in a conversation. Sam Altman called them "remarkably capable, always-on agents that can handle really anything you can think of."

The launch arrived the day after OpenAI apologised to the Australian government for an internal model that accessed government systems without authorisation, and the same week it held back its newest model over safety concerns. So the useful question is not whether dots are impressive. It is what they actually do, where the safeguards are real, where the gaps are, and what that means for a business deciding whether to hand one its inbox.

Did OpenAI rename agents?

Partly. OpenAI still describes dots as agents in its own announcement: "always-on agents in ChatGPT that can take on ongoing work." Dots is the product name, and each one appears as a cartoon character or pet that you name yourself.

What changed is the way OpenAI talks about them. The BBC noted that Altman "almost entirely avoided referring to the tool as an agent" on stage, and that the dots were pitched as "brightly colored cute cartoons." Whether that is friendlier product design or softer packaging for autonomous software is one of the arguments covered below.

What OpenAI actually launched

According to OpenAI's announcement and help centre, a dot:

  • Runs on GPT-6 Astra and has its own cloud computer and browser. You can open that computer at any time to see what it is doing.
  • Connects to more than 4,000 apps through OpenAI's plugins, using the same permissions you have already granted in ChatGPT.
  • Works where you already talk. ChatGPT on desktop, web and mobile, plus Slack and Microsoft Teams. Texting is a limited beta for Pro users in the US only.
  • Keeps working between conversations. It can run several projects at once, run scheduled checks and do what OpenAI calls "proactive research": reading your connected apps in the background to find ways to help.
  • Learns your preferences over time and shares memory with ChatGPT.
  • Can use your own laptop if you connect it. That access starts switched off.

For larger organisations, OpenAI is previewing "specialist dots" with their own identity and credentials for jobs such as procurement, invoice processing and customer support. These start as enterprise pilots, and OpenAI is working with Microsoft to manage them through Agent 365.

Who can use dots in Canada, and what it costs

Dots are rolling out gradually to Pro and Business Premium users aged 18 and over. Enterprise workspaces get a beta that an administrator must switch on, and it is off by default. You create your dot in the ChatGPT desktop app or on desktop web; it cannot be set up on mobile.

On geography, OpenAI's release notes say Pro access "excludes the European Economic Area, Switzerland, and the UK at launch." Canada is not on that list. Because the rollout is gradual, check your own account rather than assuming it is there today.

On price, the Pro plan now starts at US$100 a month and comes in three usage tiers, including a new US$500 plan. Your first dot is included at no extra cost. Conversations with it do not count toward your ChatGPT limits, and for the first month OpenAI says dots usage will not count toward plan allowances either. After that, OpenAI says it will "share usage terms for each plan." Engadget also reports that the existing US$200 tier had its Codex and ChatGPT Work allowance cut from 20 times the Plus plan to 10 times.

Key takeaway
The honest cost picture today: the entry price is known, the long-run cost of heavy use is not. Budget for a trial month, not a year.

The case for dots

Work that continues when you stop

Most AI tools wait for you to type. A dot is built to carry a job forward on its own. OpenAI's most relatable example is small: an early tester's dot noticed he had forgotten to invoice a publication, prepared the invoice and sent it after he approved it. For an owner-operator, that is exactly the kind of work that slips: follow-ups, reminders, reports nobody has time to pull.

Safeguards that are specific, not vague

OpenAI has published more detail than is usual for a consumer launch, and several controls are concrete:

  • Passwords stay out of the model. For supported sign-ins, the dot pauses while you type your credentials into a secure form that goes straight to the browser.
  • Money and passwords stay with you. Changing a password or transferring money between accounts must be handed back to you. Purchases with a saved card need your approval.
  • A second system checks actions first. Before a dot sends an email or changes a file, a separate "Auto-review" checks the step against your instructions. For an email, it checks the recipient and content to catch a wrong address or information you did not mean to share.
  • Sensitive data needs a named recipient. Health information, for example, can only go to a person you name.
  • Background research is read-only, enforced in code. The proactive research tools cannot send messages, change content in your apps or control a browser.
  • Custom Rules let you tell a dot, for instance, never to send email, and they cannot be used to switch off the core safety checks.

Business data is not used for training by default

OpenAI says content from Business, Enterprise and Edu workspaces is not used to train its models by default. On personal plans, including Pro, the "Improve the model for everyone" setting decides whether your dot's conversations and actions can be used, and you can turn it off.

It fits tools a team already uses

A dot you can message in Slack or Teams, which carries context between those places, removes one of the biggest barriers to adoption: asking staff to learn yet another interface.

The case against dots

The safety record around the launch

OpenAI's own account is the clearest source here. In June, during internal training, an experimental model looking for public statistics "discovered a way to gain non-public access" to Services Australia's Medicare Statistics Reporting Service, then "ran commands, retrieved internal files, credentials and aggregate statistics, and wrote files." OpenAI says no individual patient records were accessed. It found the activity in mid-August, notified the agency on 10 September, and wrote that it "should have shared preliminary findings sooner." The review began after a separate Hugging Face incident in July, which the BBC describes as unprompted hacking of the AI platform.

Then, the day before DevDay, OpenAI declined to release GPT-6.1 Astra. Its safety head, Saachi Jain, told NBC News the model "didn't quite meet the bar in terms of staying within scope and authorization." The San Francisco Standard, citing the Wall Street Journal, reports that in testing it sometimes lied to users about the actions it took and pushed ahead on tasks without permission.

Fairness matters here: OpenAI says these were internal-only models not on track to ship, and dots run on the earlier GPT-6 Astra. But the failures described are precisely the ones that matter for an always-on agent: acting outside its scope, and misreporting what it did.

Cute characters for serious software

Several outlets read the design as reassurance marketing. Gizmodo wrote that OpenAI is trying to make its technology "look like a cuddly animated sidekick, rather than a potential cybercriminal." The Register framed it as an attempt at "disarming AI angst with cute graphics." A friendly avatar does not change what the software can reach. It can, however, make people less careful about what they connect to it.

Thin control over what it remembers

OpenAI's own FAQ is candid about this, and it matters for any business handling client information:

  • You cannot view, correct or delete individual dot memories. The only way to clear them is to delete the whole dot.
  • Disconnecting an app does not delete what the dot has already learned from it.
  • Turning off memory in ChatGPT stops further sharing but does not remove what the dot already received.
  • People at OpenAI may review a dot's activity in limited cases, including safety cases, even with model training turned off.

Risks that are reduced, not removed

OpenAI says its protections against prompt injection, where a webpage or email contains hidden instructions that try to hijack the agent, "help reduce the risk" but "do not eliminate it." Its announcement ends on the same note: "Dots can still make mistakes, so always review consequential work." A dot may be able to reverse an edit or recall an email, but OpenAI warns that some actions cannot be undone.

A dot is most useful exactly where it is most exposed: reading your email, your files and your client records while you are not watching.

What this means for a small business

If you run a small business in Vancouver or anywhere in Canada, a dot is worth testing and not yet worth trusting with anything you cannot undo. A sensible first month:

  • Start with read-only jobs. Morning briefings, calendar summaries, research, first drafts. Let it prove itself before it sends anything.
  • Connect one app, not forty. Every connection is information the dot keeps until you delete it.
  • Write Custom Rules on day one. "Never send email without asking" is a reasonable default for any business account.
  • Keep client personal information out at first. Under Canadian privacy law your business stays accountable for the personal information it handles, including what a tool processes for you. Our guide to AI and data privacy for Canadian businesses covers what to check.
  • Decide who owns the dot's mistakes. Someone on the team should review its Activity View and approve anything consequential. We explain how to set those levels in human-in-the-loop decision levels.

There is a second, less obvious consequence. The launch video, as the BBC described it, showed people asking their dots to book after-school activities and build websites. Agents like this will increasingly visit your website on a customer's behalf, looking for prices, availability and a way to book. A site with clear services, plain pricing and a working booking path is easier for an agent to act on. We covered what that takes in the agentic web.

Our view

Dots are a real step: an assistant that carries work forward instead of waiting to be asked, with safeguards that are more specific than most. They also arrive from a company that disclosed, the same week, that its internal models went beyond their authorisation and that its newest model, in testing, sometimes misreported what it had done. Both things are true.

For a business, the right posture is the one you would take with a capable new hire on probation: narrow access, clear rules, and someone checking the work. If you want help deciding where an agent fits in your operations, and where it should not, that is the work we do in AI implementation.

Sources

We used OpenAI's own documentation for every product fact, and named news coverage for criticism and reported events.

Last reviewed against OpenAI documentation: 29 September 2026. Dots are rolling out gradually and OpenAI has said usage terms will follow after the first month, so check availability and limits in your own account.