OpenAI Dots Agents Launch Amid Security Scrutiny and Rival Rush
OpenAI unveiled always-on AI agents called Dots at DevDay 2026, powered by GPT-6 Astra. The move comes as the company faces safety headwinds and intensifying competition from Grok Bot, Meta Muse, and Microsoft Autopilot.
OpenAI is betting the future of ChatGPT on agents that never sleep.
At DevDay 2026, OpenAI introduced Dots — a new class of always-on AI agents running on its latest model, GPT-6 Astra. Unlike the conversational assistants most people know from ChatGPT, Dots are designed to work continuously in the background, learning your preferences, connecting to thousands of apps, and acting autonomously until told otherwise.
The announcement matters because it marks OpenAI’s most aggressive move yet into autonomous AI. And it arrives at a moment when that kind of ambition is under intense scrutiny.
The product in plain terms
Dots operate from a dedicated cloud computer — essentially a sandboxed virtual machine with its own identity, browser, and permissions. They can connect to more than 4,000 applications through OpenAI’s plugin ecosystem. You start a project in ChatGPT, continue it via text message, add context in Slack, and the agent remembers everything across channels.
OpenAI says Dots can write code, test it, adjust launch plans when product specifications change, update analyses with new evidence, and automate content production workflows. The company shared internal examples: a dot investigating a bug report filed in Slack, another finishing design work while humans focus on customer feedback, a third flagging that a tester had forgotten to submit an invoice and drafting it for approval.
Perhaps most significantly, users can grant Dots access to their own laptops, letting the agent operate within their actual working environment rather than a cloud sandbox.
Availability starts today for Pro subscribers (from ¥16,800 per month) and Business Premium users. Enterprise users get beta access when workspace administrators enable it. Initial conversations with Dots don’t count against ChatGPT usage limits — a deliberate design choice signaling that OpenAI wants these agents to feel unlimited, not metered.
The safety question OpenAI can’t sidestep
Dots are the kind of product that makes security researchers nervous. An agent that runs 24 hours a day, operates across multiple apps, writes code, and has access to your computer is fundamentally more dangerous than a chatbot that answers questions and moves on.
OpenAI acknowledges this. The company says Dots include safety monitoring that can pause or stop work when suspicious behavior is detected. They’re built on ChatGPT’s existing protection layers, with additional safeguards for different task types. Users control which apps Dots can access, and signs-in use saved credentials without exposing passwords to the model.
But the architecture itself raises harder questions than the safety features can fully answer. When a Dots is working autonomously overnight, how does a user verify what it actually did? When it connects to enterprise systems, where does the audit trail end? And what happens when the agent encounters a situation it wasn’t designed for — a prompt injection in a Slack thread, a malicious plugin, a confused permission boundary?
The industry is still figuring out the answers to these questions. OpenAI’s internal tests may be clean, but the external environment is messier than any controlled demo.
The competitive pressure is real
OpenAI isn’t the only player making this bet. SpaceX’s Grok Bot, Meta’s Muse, and Microsoft’s Autopilot are all pursuing similar visions of persistent, autonomous AI assistance. The Japanese coverage of DevDay highlights something English-language wires often miss: the sense that this is becoming a crowded race, not a singular breakthrough.
Microsoft’s role here is particularly noteworthy. OpenAI is integrating Dots with Agent 365’s enterprise governance and security tools, plus Microsoft’s identity and access management systems. That’s a strategic play to make Dots viable inside organizations where IT departments hold the keys. Without that enterprise infrastructure, autonomous agents remain a consumer novelty.
What changes for enterprise AI adoption
The introduction of Dots signals a shift in how OpenAI wants enterprises to think about AI. This isn’t about giving workers a better chatbot. It’s about deploying AI employees — agents with dedicated identities, specific roles, and the authority to act without constant human oversight.
OpenAI is already running internal pilots for procurement, invoice processing, email marketing, customer support, and contract review. The company plans to offer specialized dots with distinct IDs and clearly defined responsibilities within organizations. That organizational layer is critical: it’s what separates a useful tool from a liability.
But enterprise adoption hinges on trust, and trust is fragile right now. Every high-profile AI security incident makes it harder for CIOs to approve always-on agents with broad system access. The question isn’t whether Dots can do the work — it’s whether organizations will let them.
What happens next
OpenAI founder Sam Altman described Dots as agents that “learn from feedback” — a feature that sounds simple but has enormous implications. The more a dot works with a user, the more it knows about their judgment, preferences, and standards. That’s powerful. It’s also the kind of deep personal and organizational knowledge that becomes a security risk if compromised.
The pricing model is still emerging. Initial access is free beyond existing subscription costs, with plans for per-dot fees and speed tiering later. That structure suggests OpenAI expects teams to deploy multiple dots — one for marketing, one for engineering, one for operations — each learning its domain.
The long-term vision is even more ambitious: dots that form teams and collaborate autonomously. OpenAI hinted at this during DevDay. If that vision materializes, we’re not just looking at better software tools. We’re looking at a new category of AI-driven organizational structure — one that could reshape how companies operate, who gets trusted with decision-making authority, and what “work” actually means.
The technology is moving faster than the guardrails. That’s the story of AI right now, and Dots are its latest chapter.