ChatGPT Dots are OpenAI’s new always-on agents, announced on 29 September 2026 at DevDay. A dot is not a chat window that waits for you: it has a name you choose, its own cloud computer and its own browser, it keeps working between conversations, and it can message you when it needs a decision. It is also two days old, so this piece separates what OpenAI has published from what is still unclear.
Updated October 2026. This is a new product and details may change; check OpenAI’s own pages for the current position.

What ChatGPT Dots actually are
OpenAI’s announcement describes dots as always-on agents powered by GPT-6 Astra, with their own cloud computer, learning from feedback and working towards your goals around the clock. Through OpenAI’s plugin ecosystem they can connect to over 4,000 apps. The Help Center adds that a dot takes on ongoing responsibility and remembers context for continuing work.
The underlying model matters. GPT-6 Astra, introduced on 3 September 2026, is the one OpenAI calls its strongest for computer use and browsing, the capability a dot is built around. For the loop this sits inside, see our explainers on what an AI agent is and agentic AI.
You create your first dot in the ChatGPT desktop app or on desktop web, give it a name and connect apps. You cannot create one on mobile, and dots are not supported on mobile web, though you can message an existing one from the mobile app.
What a dot can and cannot do
The limits are specific, and OpenAI has written them down:
- It works from its own machine. Each dot has its own cloud computer and browser, and you can open that computer to inspect its work.
- Your computer is separate by default. Local access starts turned off. You connect it through the desktop app, and can revoke that access.
- Background work is read-only. What OpenAI calls proactive research cannot send messages, change content through plugins, or control a browser or computer.
- Some actions stay with you. Changing a password or transferring money requires you to take over yourself; deleting data or installing software may need approval each time.
- It cannot call you, and it cannot have its own email address, at launch.
- Not for under-18s. The Help Center states that dots are not yet available to users under 18.
Reachability is broader than ChatGPT itself: desktop, web and mobile, plus Slack and Teams. OpenAI’s announcement says texting is coming soon; the Help Center is more precise, describing it as a limited beta using a third-party provider, restricted to Pro users in the United States and unavailable in Business or Enterprise workspaces.
Who can get ChatGPT Dots, and where they are not available
The rollout is narrow and geographically uneven, a detail most early coverage flattened.
- ChatGPT Pro: rolling out in markets excluding the European Economic Area, Switzerland and the UK.
- Business Premium: available across all supported ChatGPT regions.
- Enterprise, Edu and Healthcare: a beta a workspace administrator has to switch on. It is off by default.
- Everyone else: nothing yet. OpenAI says it plans to expand soon, without naming a date.
OpenAI also warns that the rollout is gradual and access may take several days, so being on the right plan is not the same as having a dot today.
What ChatGPT Dots cost
Your first dot is included in a Pro or Business Premium plan at no extra cost, with an allowance for deeper work and extended limits for the first month after launch. Conversations with it do not count towards your ChatGPT usage limits; tasks it starts in Codex or ChatGPT Work do.
Beyond that, OpenAI says only that you will later be able to add more dots and scale each one by speed or monthly workload. No price has been published for either. A figure for a paid capacity tier appears in one secondary report; we are leaving it out.

The privacy and security questions raised by ChatGPT Dots
An agent that browses on your behalf, holds your app connections and runs while you are asleep concentrates a lot of risk in one place. The central threat is the familiar one: a website, email or document can carry hidden instructions aimed at the agent rather than at you. OpenAI says a dot is designed to distinguish your instructions from content it encounters, that such content does not grant permission on its own, and that these protections reduce the risk without eliminating it. That is prompt injection, the same problem covered in our guide to using AI browser agents safely.
Three system-level controls sit on top. Auto-review checks planned actions that could affect your accounts or share information against your instructions, your Custom Rules and OpenAI’s safety requirements before they run; the example given is checking an email recipient before sending. Safety monitoring can pause or stop a dot’s work. Custom Rules let you allow, require approval for, or block actions, and cannot switch off core safety requirements, auto-review, or the limits on proactive research.
Data handling has real edges. A dot shares memory with ChatGPT in both directions. Its context does not retain credentials, images or screenshots, and for supported sign-ins your password reaches the browser environment without being exposed to the model. But you cannot currently view, delete or edit individual dot memories: deleting the dot is the only way to clear its context, and disconnecting an app does not remove what it already absorbed. Human review may occur in limited cases, including safety cases, even with model improvement turned off.
7 safety checks before you start
These follow from what OpenAI has documented. Work through them before the first task:
- Connect the fewest apps that make it useful. Plugin permissions are shared across dots, ChatGPT, ChatGPT Work and Codex, so existing connections are in scope from the start.
- Leave your own computer disconnected until a task genuinely needs it, then revoke access afterwards.
- Write Custom Rules before the first real job. The example OpenAI gives is telling a dot never to send emails.
- Assume anything it reads may be hostile. See what to allow an agent to do with your email.
- Be specific when you pre-approve. OpenAI warns that approving one message does not grant ongoing permission to contact people. Name the recipient, the content and the condition.
- Read the Activity View. It shows ongoing and delegated tasks and the steps taken.
- Know where Pause and Reset are. Reset deletes the dot with its conversations, memories and scheduled tasks, and is currently the only way to clear its context.
What is not confirmed yet
Two days in, several things are announcements rather than shipped features. Specialist dots with their own identity and credentials are described as a preview and focused enterprise pilots. The Microsoft Agent 365 integration is stated as a goal. Teams of dots working together is a direction of travel: “Over time, we envision teams of dots working together on your behalf,” OpenAI wrote. And OpenAI repeats the obvious caveat itself: dots can make mistakes, including when following your own rules, so consequential work needs reviewing. For the governance picture see the EU AI Act and AI governance; for what happens when an agent exceeds its brief, the Hugging Face and RubyGems incidents are the cautionary reading, and OpenAI built an evaluation informed by the Hugging Face incident when testing GPT-6 Astra.
Common questions
What are ChatGPT Dots? Always-on agents inside ChatGPT, announced on 29 September 2026. Each runs on GPT-6 Astra with its own cloud computer and browser, connects to apps you choose, and keeps working between conversations.
How much does a dot cost? Your first is included in a Pro or Business Premium plan at no extra cost, with extended limits for the first month after launch. OpenAI has not published prices for additional dots or capacity.
Can I get ChatGPT Dots in the UK or the EU? Not on Pro: OpenAI says that rollout excludes the European Economic Area, Switzerland and the UK. Business Premium covers all supported ChatGPT regions, and Enterprise workspaces can enable a beta.
Can a dot send emails or spend money without asking? OpenAI says background research tools are read-only and cannot send messages or change app content, that purchases with a saved card need approval, and that password changes and money transfers require you to take over.
Where can I talk to my dot? ChatGPT on desktop, web and mobile, plus Slack and Teams. Texting is a limited beta through a third-party provider, currently for Pro users in the United States only.
Sources and further reading
Where the figures and rules above come from, so you can check them:
- Introducing dots, 29 September 2026: OpenAI
- Getting started with your dot: OpenAI Help Center
- Dots privacy, security and safety FAQs: OpenAI Help Center
- GPT-6 Astra, 3 September 2026: OpenAI
- OpenAI launches Dots, its bubbly agentic avatar: TechCrunch
- Always-on AI agents with their own cloud computers: The Next Web
Photo credits: Smartphone with ChatGPT on keyboard (52917311050) by Jernej Furman from Slovenia, CC BY 2.0, via Wikimedia Commons. Woman sits at desk working on laptop in home office by Shixart1985, CC BY 2.0, via Wikimedia Commons. Technician with laptop working on server rack at NERSC by Derrick Coetzee from Berkeley, CA, USA, CC0, via Wikimedia Commons.
Join the discussion