OpenAI Dots Are Always On Agents With Their Own Computer. The Governance Question Is Which Plan Your Staff Are On
At DevDay on 29 September 2026 OpenAI launched Dots, background agents powered by GPT-6 Astra that keep working after the first instruction, run on their own cloud computer, and reach thousands of connected apps. They ship first to Pro and Business Premium, while Enterprise gets an admin gated beta, and that ordering is the part security teams should plan around.
OpenAI used its DevDay conference in San Francisco on 29 September 2026 to launch Dots, which it describes as always on agents. Alongside a new model, GPT-6.1 Sol, and an expanded Codex Cloud, Dots were the headline. A Dot is an agent you assign a goal to rather than a prompt. It keeps working after the first instruction, follows up on recurring work, and can hand parts of a job to sub agents. Each Dot runs on GPT-6 Astra with its own cloud computer and browser, and it can act through the same connected apps ChatGPT already uses, which OpenAI puts at more than 4,000. Launch coverage from 9to5Google, CNBC and others says users reach a Dot through ChatGPT and Slack, with Microsoft Teams, email and text messages also mentioned, and that a user can let a Dot use their own computer as well as its cloud one.
The commercial detail is where this stops being a product story and becomes a governance one. Dots are rolling out to ChatGPT Pro and Business Premium subscribers at no extra cost, with one Dot included per plan and more available to buy later. Enterprise, Education and Healthcare workspaces get an opt in beta that an administrator has to switch on. In other words, the version of Dots with the most central control arrives last, and the versions an individual can buy with a company card arrive first. For most organisations the first Dot touching company data will not be one the security team approved. It will be one a founder, a sales lead or an engineer turned on because it was included in a plan they already pay for.
Always on changes the risk shape in three ways. The first is time. A chat assistant acts while someone is watching it; a Dot acts at three in the morning on a goal set last Tuesday, and nobody is in the loop unless a rule puts them there. The second is reach. A Dot that can read a CRM, send email and post in Slack from one goal is a single identity spanning systems your access reviews treat separately. The third is delegation. Sub agents mean the thing that actually performed an action may be two steps removed from the instruction a person gave, which is the attribution gap we wrote about with UI operating agents and the loopjacking approval issue earlier this month.
OpenAI says Dots follow the existing ChatGPT permissions model, begin proactive research through read only connections, and support custom rules that decide when a Dot may act on its own and when it must ask for approval. Those are useful controls, but notice who sets them. In a personal Pro account the rules are set by the user, for the user. On Enterprise and Edu, OpenAI documents a Compliance Platform that exposes conversations, admin actions, authentication events and agent activity to eDiscovery, DLP and SIEM tools, and per agent controls on which app actions are allowed and when approval is required. Before you assume that visibility covers Dots, confirm two things with OpenAI in writing: whether Dot actions, including those of sub agents and those taken on a local computer, appear in those logs, and whether anything equivalent exists on Business Premium. If the answer is no for the plan your people are on, you have an agent with write access and no audit trail you control.
The framework mapping is straightforward. ISO 42001 expects an inventory of AI systems in use, documented intended use, and defined human oversight, and a Dot with an open ended goal and self set approval rules fails all three unless someone writes them down. Our ISO 42001 guide shows how to record that in an AI register. ISO 27001 Annex A 5.15 to 5.18 on access control and identity, 5.23 on the use of cloud services, and 8.15 and 8.16 on logging and monitoring all apply to an agent that holds OAuth grants to your systems. For SOC 2, CC6.1 and CC6.2 cover who and what is granted logical access, CC6.3 covers removing it, and CC7.2 expects you to detect anomalous activity, which is hard to evidence for actions taken from a cloud computer you do not operate. If you track controls in Vanta, Drata or Secureframe, a Dot is a new system with its own identity and belongs in scope, not in a note on the ChatGPT vendor record.
The OAuth side is the practical choke point. A Dot acts through connectors, and connectors act through grants your identity provider or SaaS admin consoles can see. Google Workspace, Microsoft Entra, Slack and most CRMs let you restrict which third party apps can request access and review which users have granted what. If a Pro account has been connected to company Gmail or Salesforce, that grant is visible to you today, whether or not you knew Dots existed. Reviewing those grants this week is the fastest way to learn how many personal agents already reach company data, and blocking unapproved OpenAI connector grants on company accounts until you have a policy is a reasonable default.
The same logic applies to the local computer permission. A Dot allowed to use a laptop is, in effect, a remote operator on an endpoint, and your endpoint rules should treat it that way. Decide whether that is allowed on company devices at all, and if it is, whether only inside a separate user account or virtual machine with no access to password managers, production credentials or customer data. Our piece on Claude Code deleting 48,000 files made the case that agent blast radius has to be enforced by the operating system rather than the prompt, and an agent that runs on a schedule while its owner is asleep raises the stakes on that argument.
A short list for this week. Update your AI acceptable use policy to say whether always on agents such as Dots may be used with company data, on which plans, and with which connectors. Review OAuth grants to OpenAI and ChatGPT apps across Google, Microsoft, Slack and your CRM, and revoke or approve each one. If you are on ChatGPT Enterprise, keep the Dots beta off until you have confirmed what the Compliance Platform records and have decided who may set approval rules. Add Dots, and any similar background agent from Anthropic, Google or Microsoft, to your AI register with an owner, a purpose and a stop condition. Our policy templates include an AI acceptable use policy you can extend with these clauses, and the compliance readiness checklist will show where agent logging evidence is missing.
Our view is that Dots are a genuinely useful product and that staff will adopt them faster than any policy is written, precisely because they come bundled with a subscription people already expense. That is not a reason to ban them. It is a reason to move the control point to where you can still see it: the identity grants, the endpoint and the plan your company pays for. An agent that works while everyone is asleep is fine. An agent that works while everyone is asleep, under rules only its user can see, on data you are accountable for, is the finding your next auditor will write up.
Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.
Get the next post by email
One short email when something worth knowing ships. No spam, unsubscribe anytime.
Comments
Moderation policyLoading comments...
Add a comment
Corrections and first-hand experience are the most useful things you can leave. Comments are screened automatically and reviewed by a human; see the moderation policy.