ChatGPT Dots proactive research is the behaviour that makes people uneasy, and it is also the one OpenAI has documented most precisely. When you are not working with your dot, it looks for ways to help in the background. The question worth asking is not whether that is unsettling but what, exactly, it is allowed to do while it does it.
Updated October 2026. Dots launched on 29 September 2026 and are rolling out gradually, so check OpenAI own pages for the current position before relying on any detail here.

1. It is restricted to read-only tools
This is the central constraint. OpenAI states that proactive research uses the apps you have already connected with tools that are restricted to be read-only, which means they cannot send messages, change app content, or control your browser or computer. Background work can therefore look, and form an opinion, but not act.
2. It can form memories without being asked
The part people miss is that reading has a consequence. The Help Center says a dot can review information from connected apps proactively and form memories from it, even when you have not asked a specific question about it. So the boundary is not read-only in the sense of leaving no trace; it leaves a trace in the memory of the dot.
That matters when you disconnect an app, because disconnecting does not delete what the dot already took from it. The documented way to remove that is Reset, which deletes the dot along with its conversations, memories and scheduled tasks.
3. What OpenAI says it does not train on
OpenAI states that it does not train directly on proactive research or on the notes a dot makes to itself, and that information from them may still be used if it helps inform an eligible conversation or task, depending on your settings. Workspace content from Business, Enterprise and Edu is not used to improve its models by default, and on personal plans you control whether the conversations and work of your dot are used.
4. Why read-only is a security decision, not just a courtesy
An agent that reads unfamiliar content all day is an agent exposed to instructions hidden in that content. This is prompt injection, and it is the reason the background mode cannot act.
OpenAI tested this directly. In a bulk attack evaluation, each run delivered 500 simulated emails, 334 benign and 166 generated attacks. Across 100 runs that is 50,000 emails including 16,600 attack emails, and OpenAI reports no scored attack successes. In an iterative variant, where the attacker refines its email using feedback from the previous attempt, it reports no scored successes across 2,638 valid attempts. In the traces it inspected, dots flagged suspicious requests, withheld risky actions and asked the user.

5. Human red-teamers tried harder
Automated tests only find what they are designed to find, so OpenAI also ran manual red-teaming with internal and external teams, across email, calendar, shopping and business workflows, with testers impersonating colleagues or posing as tools and services. It reports that attempts to send data from an openai.com address to a gmail.com address all failed, and that dots resisted attachment-based attacks and hidden instructions.
It is equally clear about the caveat: initial testing found weaknesses in how dots handled sensitive disclosures and sought confirmation, which were mitigated by updating the confirmation policies, and it says it will continue to test and address issues throughout deployment.
6. You can stop it
Proactive work is not something you have to live with. You can pause a dot from the menu in its profile, which stops it until you resume, and you can review background work in the Activity View and in the profile of the dot. Scheduled runs and proactive updates appear in the conversation rather than happening silently.
One more published result is worth noting, because it addresses the obvious worry that a proactive agent will be talked into something by another agent. OpenAI ran an evaluation with a cached message board containing instructions to act improperly and reports a 0 percent rate of following them, with dots not engaging with the board in any run. The confirmation policy for dots further restricts engagement with agents outside their own ecosystem unless you explicitly ask for it.
What ChatGPT Dots proactive research means for privacy
Strip away the mechanics and the privacy question is simple: a system you are not watching is reading accounts you connected, and keeping notes. Whether that is acceptable depends on three things you can actually check.
- Which apps are connected. This is the real privacy control, because proactive research can only reach what you have already connected. Connecting fewer apps is more effective than any setting.
- Whose plan you are on. Business, Enterprise and Edu workspace content is not used to improve OpenAI models by default. On personal plans you choose whether the conversations and work of your dot are used.
- Whether it is running at all. Pausing the dot stops it, and Reset removes it with everything it remembered.
The uncomfortable asymmetry is the memory one, and it is worth stating plainly because it is the detail most likely to catch people out: you can revoke an app in seconds, but what the dot already learned from it only goes when the dot does. Decide what to connect on that basis rather than assuming you can undo it later.
A sensible way to start
If the background behaviour is the part you are unsure about, the way to evaluate it is not to turn everything on and watch. Connect one app whose contents you would not mind summarised, leave the dot running for a few days, and read the proactive updates it posts into the conversation. You will learn more about what it considers helpful from that than from any description, including this one. Our guide to dots use cases covers what to ask for next, and dots custom rules covers how to constrain it when you move beyond reading.
Common questions
Can ChatGPT Dots proactive research send an email? No. OpenAI states the tools used in proactive research are restricted to read-only, so they cannot send messages or change app content.
Does it remember what it reads? Yes. A dot can form memories from connected apps proactively, even without a specific question from you.
Does disconnecting an app erase what it learned? No. Disconnecting does not delete information already obtained. Reset deletes the dot and its memories.
Is proactive research used to train OpenAI models? OpenAI says it does not train directly on proactive research or on the notes a dot makes to itself, though information from them may inform an eligible task depending on your settings.
How do I turn it off? Pause the dot from the menu in its profile. You can resume it later.
Sources and further reading
Where the figures and rules above come from, so you can check them:
- The announcement, including proactive research and the control model: OpenAI, Introducing dots
- Appendix B, the red-teaming and alignment results for dots: OpenAI, GPT-6 Astra system card
- Setup, connected apps, scheduling, memory, rules and reset: OpenAI Help Center, Getting started with your dot
- Everything else announced alongside dots: OpenAI, DevDay 2026 Recap
Photo credits: Office building at night (13346726533) by Thomas Quine, CC BY 2.0, via Wikimedia Commons. Blackview A60 Smartphone Android mobile phone and folio case by Acabashi, CC BY-SA 4.0, via Wikimedia Commons. Diagnostic monitors in the control room of Wendelstein 7-X by Siarhei Besarab, CC BY-SA 4.0, via Wikimedia Commons.
Join the discussion