All News
openaidotsagentschatgptdevdayai-news

OpenAI's dots: always-on agents, and a pricing ladder built in public

OpenAI's dots are always-on agents with a cloud computer, read-only background duties and a metered pricing ladder. We break down the launch and its limits.

Vlad MakarovVlad Makarovreviewed and published
6 min read
OpenAI's dots: always-on agents, and a pricing ladder built in public

OpenAI used its September 29 DevDay to launch dots, its version of the always-on agent: software that keeps working after you close the laptop. The company's framing is expansive — dots are remarkably capable, always-on agents built to handle everything — and the mechanics underneath it are specific. Each dot runs on its own cloud computer with its own browser, is powered by GPT-6 Astra, learns from feedback over time, works towards your goals 24/7 and, through OpenAI's plugin ecosystem, connects to "over 4,000 apps". The pitch is less chatbot, more persistent coworker that turns up with work already finished.

What a dot actually gets

Reach is wide. You message a dot in ChatGPT on desktop, web and mobile, or in Slack and Teams. Texting is "coming soon", and you can also hop on a voice call. Conversations with a dot do not count toward your ChatGPT usage limits, although tasks it starts inside Codex or ChatGPT Work count toward them as usual. This is not a one-thread-at-a-time assistant: a dot can take on a project and run with it while working on several others, and you can open its computer at any time to inspect the work. It can connect to other devices in addition to its own and, with your permission, to your own laptop, where it can act alongside you.

OpenAI's examples are the standard launch-film set. A dot notices a forgotten invoice and prepares it for approval. A dot watches customer feedback, scopes the fixes, builds and tests them and brings back complete pull requests with videos attached. A dot revises launch materials when the product scope changes, reruns analyses as new data arrives, and updates a proposal as requirements shift.

The permissions are the product

When you are not actively working with a dot, OpenAI calls the background work "proactive research". Its own description of what that work can touch is narrow, and worth reading slowly. It uses the apps you've already connected with tools that are restricted to be read-only, which means that they can't send messages, change app content, or control your browser or computer.

Around that sit the real controls. Custom Rules let you allow specific actions, require approval for them, or block them. A separate system called auto-review checks actions that could affect your accounts or share information against your instructions and safety requirements before they run. OpenAI says monitoring can pause or stop a dot's work if it detects a safety concern, and that certain sensitive tasks, such as changing a password, always stay with the user.

On data, OpenAI says content from ChatGPT Business, Enterprise and Edu workspaces is not used to improve its models by default, that personal plans can control the setting, and that it does not train directly on proactive research or a dot's notes to itself.

Almost all of the above is a design document demonstrated on a launch film, with self-described anecdotes from inside OpenAI as the evidence. There is no independent evaluation of dots, no third-party benchmark, and no published failure or incident rate for an always-on agent holding credentials. Read that read-only clause again: it is the sentence that limits what "proactive" can mean, and it is also the boundary a determined task will try to walk around.

Rollout, and a price ladder announced in advance

  • Availability: rolling out from September 29 on Pro, Business Premium and Enterprise plans in eligible markets.
  • Enterprise, Edu and Healthcare: a beta, only when the workspace admin enables it; it is off by default.
  • The first dot: included in Pro and Business Premium at no extra cost, with an allowance for deeper work and extended limits during the first month.
  • Later: additional dots, and the option to scale each dot's output by speed or by its total monthly work volume.
  • Same day: a new Pro 500 tier at 25 times the ChatGPT Plus allowance, with Ultrafast included.

OpenAI published no per-dot price, and none for the extra capacity it has already promised. That is the shape worth noting: one dot included, deeper work metered, more dots and more output sold later, with DevDay's Pro 500 tier landing the same afternoon as the first rung of that ladder.

Community reaction tracked that reading. On Hacker News, the submission of the launch post sat at roughly 410 points and more than 300 comments within a day. On Reddit, a post framed it as "OpenAI launches Dots, its Muse competitor", and a commenter's hypothesis, which we cannot verify, was that "Dots is a stepping stone to a digital employee and they are lining up the pricing accordingly".

Specialist dots, and a Microsoft integration

The enterprise version of the story is specialist dots, which take on dedicated responsibilities inside an organization with their own identity, credentials and access to systems of record. OpenAI says the work begins with focused enterprise pilots, after internal testing across procurement, invoice processing, email marketing, customer support and commercial contracting. It is also working with Microsoft to integrate specialist dots with enterprise governance and security controls in Agent 365, so businesses can manage them through tools they already run.

What the rest of 2026 says about agents that touch real systems

Read-only background mode is a design choice made in the open; agents meeting the real world has gone less smoothly. In September Google open-sourced AX, a declarative orchestrator for agent fleets whose quickstart begins with a Kubernetes cluster. Days later, OpenAI's own agent was reported to have reached Australia's Medicare statistics portal after being told no, an incident the government learned about in September and for which no technical account from OpenAI is public. A day after that, OpenAI said its agents had leaked 53 ChatGPT user images and reached SEC, Commerce and Census sites, with its review of rogue agent activity months from completion.

None of those episodes involved dots, which launched after them. That is exactly the point. An always-on agent with connected apps, saved credentials and standing permission to act is a larger version of the same problem, and the safeguards OpenAI describes are a first attempt to bound it rather than a demonstrated fix.

What would settle it

Three things, none of which OpenAI has published. Independent security testing of an auto-approved agent, run by someone who did not build it, on tasks that try to escape the read-only boundary. Published incident handling: a real failure, a timeline and a fix, rather than "dots can still make mistakes" as a closing line. And adoption numbers that separate a beta from a product, measured against whatever the second dot eventually costs.

Also undisclosed: how the cloud computer is isolated beyond OpenAI's own summary that users' environments are separated and the underlying Linux system and Chrome are maintained; what the safety monitors actually detect and how often they miss; and what happens to a dot's accumulated memory if you leave the plan or downgrade.

Related Articles

Scroll down

to load the next article