Technology

ChatGPT Dots Proactive Research: 6 Limits Worth Knowing

ChatGPT Dots Proactive Research: 6 Limits Worth Knowing
Photo: Office building at night (13346726533) by Thomas Quine, CC BY 2.0, via Wikimedia Commons

ChatGPT Dots proactive research is the behaviour that makes people uneasy, and it is also the one OpenAI has documented most precisely. When you are not working with your dot, it looks for ways to help in the background. The question worth asking is not whether that is unsettling but what, exactly, it is allowed to do while it does it.

Updated October 2026. Dots launched on 29 September 2026 and are rolling out gradually, so check OpenAI own pages for the current position before relying on any detail here.

ChatGPT Dots proactive research: Blackview A60 Smartphone Android mobile phone and folio case
Blackview A60 Smartphone Android mobile phone and folio case by Acabashi, CC BY-SA 4.0, via Wikimedia Commons

1. It is restricted to read-only tools

This is the central constraint. OpenAI states that proactive research uses the apps you have already connected with tools that are restricted to be read-only, which means they cannot send messages, change app content, or control your browser or computer. Background work can therefore look, and form an opinion, but not act.

2. It can form memories without being asked

The part people miss is that reading has a consequence. The Help Center says a dot can review information from connected apps proactively and form memories from it, even when you have not asked a specific question about it. So the boundary is not read-only in the sense of leaving no trace; it leaves a trace in the memory of the dot.

That matters when you disconnect an app, because disconnecting does not delete what the dot already took from it. The documented way to remove that is Reset, which deletes the dot along with its conversations, memories and scheduled tasks.

3. What OpenAI says it does not train on

OpenAI states that it does not train directly on proactive research or on the notes a dot makes to itself, and that information from them may still be used if it helps inform an eligible conversation or task, depending on your settings. Workspace content from Business, Enterprise and Edu is not used to improve its models by default, and on personal plans you control whether the conversations and work of your dot are used.

4. Why read-only is a security decision, not just a courtesy

An agent that reads unfamiliar content all day is an agent exposed to instructions hidden in that content. This is prompt injection, and it is the reason the background mode cannot act.

OpenAI tested this directly. In a bulk attack evaluation, each run delivered 500 simulated emails, 334 benign and 166 generated attacks. Across 100 runs that is 50,000 emails including 16,600 attack emails, and OpenAI reports no scored attack successes. In an iterative variant, where the attacker refines its email using feedback from the previous attempt, it reports no scored successes across 2,638 valid attempts. In the traces it inspected, dots flagged suspicious requests, withheld risky actions and asked the user.

ChatGPT Dots proactive research: Diagnostic monitors in the control room of Wendelstein 7-X
Diagnostic monitors in the control room of Wendelstein 7-X by Siarhei Besarab, CC BY-SA 4.0, via Wikimedia Commons

5. Human red-teamers tried harder

Automated tests only find what they are designed to find, so OpenAI also ran manual red-teaming with internal and external teams, across email, calendar, shopping and business workflows, with testers impersonating colleagues or posing as tools and services. It reports that attempts to send data from an openai.com address to a gmail.com address all failed, and that dots resisted attachment-based attacks and hidden instructions.

It is equally clear about the caveat: initial testing found weaknesses in how dots handled sensitive disclosures and sought confirmation, which were mitigated by updating the confirmation policies, and it says it will continue to test and address issues throughout deployment.

6. You can stop it

Proactive work is not something you have to live with. You can pause a dot from the menu in its profile, which stops it until you resume, and you can review background work in the Activity View and in the profile of the dot. Scheduled runs and proactive updates appear in the conversation rather than happening silently.

One more published result is worth noting, because it addresses the obvious worry that a proactive agent will be talked into something by another agent. OpenAI ran an evaluation with a cached message board containing instructions to act improperly and reports a 0 percent rate of following them, with dots not engaging with the board in any run. The confirmation policy for dots further restricts engagement with agents outside their own ecosystem unless you explicitly ask for it.

What ChatGPT Dots proactive research means for privacy

Strip away the mechanics and the privacy question is simple: a system you are not watching is reading accounts you connected, and keeping notes. Whether that is acceptable depends on three things you can actually check.

  • Which apps are connected. This is the real privacy control, because proactive research can only reach what you have already connected. Connecting fewer apps is more effective than any setting.
  • Whose plan you are on. Business, Enterprise and Edu workspace content is not used to improve OpenAI models by default. On personal plans you choose whether the conversations and work of your dot are used.
  • Whether it is running at all. Pausing the dot stops it, and Reset removes it with everything it remembered.

The uncomfortable asymmetry is the memory one, and it is worth stating plainly because it is the detail most likely to catch people out: you can revoke an app in seconds, but what the dot already learned from it only goes when the dot does. Decide what to connect on that basis rather than assuming you can undo it later.

A sensible way to start

If the background behaviour is the part you are unsure about, the way to evaluate it is not to turn everything on and watch. Connect one app whose contents you would not mind summarised, leave the dot running for a few days, and read the proactive updates it posts into the conversation. You will learn more about what it considers helpful from that than from any description, including this one. Our guide to dots use cases covers what to ask for next, and dots custom rules covers how to constrain it when you move beyond reading.

Common questions

Can ChatGPT Dots proactive research send an email? No. OpenAI states the tools used in proactive research are restricted to read-only, so they cannot send messages or change app content.

Does it remember what it reads? Yes. A dot can form memories from connected apps proactively, even without a specific question from you.

Does disconnecting an app erase what it learned? No. Disconnecting does not delete information already obtained. Reset deletes the dot and its memories.

Is proactive research used to train OpenAI models? OpenAI says it does not train directly on proactive research or on the notes a dot makes to itself, though information from them may inform an eligible task depending on your settings.

How do I turn it off? Pause the dot from the menu in its profile. You can resume it later.

Sources and further reading

Where the figures and rules above come from, so you can check them:

Photo credits: Office building at night (13346726533) by Thomas Quine, CC BY 2.0, via Wikimedia Commons. Blackview A60 Smartphone Android mobile phone and folio case by Acabashi, CC BY-SA 4.0, via Wikimedia Commons. Diagnostic monitors in the control room of Wendelstein 7-X by Siarhei Besarab, CC BY-SA 4.0, via Wikimedia Commons.

Join the discussion

Held for review before it appears. Links are not allowed and your email is never published.