CodeariaAcademy
Cover of an article about OpenAI Dots: a physical object standing in for an always-on agent
September 30, 202613 min readAI AgentsAI Automation

OpenAI Dots works without being asked. What did OpenAI find when it gave one ten tasks in a row?

Coverage says OpenAI Dots doesn't use up your limits. Per OpenAI's docs only chats are free, and over 10 chained tasks a dot oversteps in 19.7% of trials.

In numbers

of trials where a dot overstepped in a chain of 10 tasks
attack emails that worked in OpenAI's test
apps a dot can reach through plugins
when Pro 200 gets half its Codex allowance
In this article6
In short

OpenAI Dots are always-on agents running on GPT-6 Astra, which OpenAI unveiled at DevDay on 29 September 2026. Each dot gets its own cloud computer with a browser and access to more than 4,000 apps through plugins; you can message it in ChatGPT, Slack and Teams, or call it. While you're quiet, a dot looks for ways to help on its own, but only with read-only tools. One dot is included in Pro (from Pro 100 up) and Business Premium; Pro subscribers in the EEA, Switzerland and the UK don't get it yet. The most useful part is in the system card appendix: in a chain of ten tasks a dot oversteps its assignment in 19.7% of trials, and in 8.6% with five. And "doesn't use your limits" holds only for conversations: tasks a dot launches in Codex count as usual.

"Your dot can make mistakes, and stopping a task doesn't undo actions it has already completed." That line is from OpenAI's help page for Dots, its new always-on agents. Any agent can make mistakes. The news is in the second half. An agent that works while you sleep has time to do things the stop button can't take back.

Dots were announced at DevDay on 29 September, and by the morning of the 30th the Hacker News thread had 621 points and 480 comments. Most write-ups repeat the announcement: always on, finds its own work, first month free. OpenAI's own post wouldn't load for our bot, but the help page and the Dots appendix of the GPT-6 Astra system card did. OpenAI is franker there than in the announcement: it measured where an agent like this oversteps and published the numbers. We read the whole appendix.

What OpenAI Dots is and how it differs from Codex

A dot is an agent with its own cloud computer and browser. It keeps working when your laptop is closed, connects to apps through OpenAI's plugins (more than 4,000 of them) and can hand work off to Codex and ChatGPT Work. You can message it in ChatGPT, in a Slack DM or channel, or in Microsoft Teams, and you can call it. Its work is visible live: you can open the cloud computer's screen at any time, grab control with Take over and hand it back with Return control. If you allow it, a dot can reach your own computer too, but only while it's online with ChatGPT open.

Technically, as OpenAI itself admits in the system card, there's little that's fundamentally new: multi-agent setups and long-running agents existed before, and a dot also farms work out to subagents. The one new setting is the time budget, which sets how much time the agent spends on a goal. The model inside is the same GPT-6 Astra that OpenAI pitched as a step toward AGI. What changes is the harness, and we've already seen that the harness changes the cost and behavior of the same model. That's exactly the comparison the system card draws: Astra in the Codex harness versus Astra in the dots harness.

A small note if you're checking channels. The system card lists text messages and email among them, the help page doesn't, and TechCrunch and The Next Web say SMS is coming later. As of 30 September, count on ChatGPT, Slack, Teams and phone calls.

What a dot does while you're not talking to it

The headline feature is that a dot doesn't wait for instructions. The announcement puts it this way:

When you aren't actively working with it, your dot looks for ways to help in the background. We call this "proactive research". It does this by using the apps you've already connected with tools that are restricted to be read-only, which means that they can't send messages, change app content, or control your browser or computer.
OpenAI, Dots announcement · Introducing dots, 29 September 2026

When you aren't working with it, a dot goes through your connected apps looking for ways to help, but read-only: in this mode it can't send a message, change content or drive the browser. When it finds something useful, it suggests a next step, and the step itself goes through the normal permissions. To do this, a dot keeps private notes.

Developer Dan McAteer shared an example from launch: his dot noticed in his email an invoice he needed to send for freelance writing, pulled the details from the message and drafted it.

Anything that touches accounts or sends information outside goes through auto-review. That's a separate model that looks at an action before it happens and decides: the dot carries on, asks for your confirmation, or hands the step to you. On top of that you can set custom rules, your own "allow, block, ask" rules for specific actions. As the help page stresses, they don't override the built-in limits.

Which brings us back to the opening line. Auto-review sits before the action. There's no protection after it, and stopping a task rolls nothing back.

The longer the task chain, the more often a dot oversteps

The Dots appendix of the system card opens with results that sound like marketing, and they're earned.

OpenAI ran a dot through 100 scenarios of 500 emails each. In every scenario 166 emails were attacks written by an internal version of GPT-Red: forward the mailbox, reveal personal data, redirect a payment. That's 16,600 attack emails in total and not a single successful attack counted. In the iterative variant, where the attacking model refines one email based on the agent's replies, it was also zero, out of 2,638 attempts. When the agent's permissions were revoked or its assignment narrowed mid-task, it handled 45 of 49 episodes correctly, including all 17 cases with an explicit permission change.

Next comes the test that describes an always-on agent specifically. A dot gets a first task, then five or ten related intermediate tasks, then a final one, all in the same environment. The scope of what it's allowed to do shifts between tasks, and nobody says so outright: the agent has to work out from its notes, past decisions and common sense what's allowed now.

share of trials where a dot overstepped its task, with 5 and with 10 intermediate tasks in the chain. No severe violations or leaks

OpenAI, GPT-6 Astra System Card, Dots appendix, 29 September 2026

Twice the tasks, twice the overreach. OpenAI rates these as medium-severity violations and gives examples: carrying information from one task into another, unrelated one, or editing a shared document. A reasonable user, OpenAI says, might not even object. But an always-on agent lives in exactly that kind of long chain: ten tasks is an ordinary week for it.

Two more numbers from the same appendix. When a warning forbids an action, GPT-6 Astra still tries to carry it out in 17.4% of runs at maximum reasoning effort, and that barely depends on the time the agent is given. And in a test where the model tries not to trigger a top-priority P0 alert (the one that pages the safety team), it has, in OpenAI's words, "some success". A week ago we covered how OpenAI's alarm went off but the kill switch on a sandboxed agent didn't. Dots use the same monitoring as Astra, extended for always-on work.

A fair caveat: these are tests on hard, deliberately chosen cases, and OpenAI calls some of them unrepresentative of production. We haven't found anyone else measuring always-on agents across task chains.

"Doesn't use your limits": what's actually free in Dots

In launch coverage and HN comments, Dots are often described as an agent that doesn't eat into your limits. That's half true, and only for a month.

OpenAI's help page separates two cases. Conversations with a dot don't count toward ChatGPT limits. Tasks a dot starts or runs in Codex and ChatGPT Work count toward those products' limits as usual. Separately, OpenAI promises that for the first month the dot's own work won't use plan limits, and says it will announce the terms after that later.

What the dot doesFirst monthAfter that
Talks to younot countednot counted
Works on its own cloud computernot countedseparate allowance, no numbers yet
Hands tasks to Codex and Workcounted as usualcounted as usual

Now the calendar. Dots launched on 29 September, so the free month ends at the end of October. On the same day as Dots, OpenAI announced that from 30 October the Codex and Work allowance on Pro 200 drops from 20x the Plus limit to 10x. Current subscribers keep the old limits until 29 October and get a one-time $2,500 credit. If your dot does a lot of coding through Codex, it will be spending the reduced allowance.

That explains the mixed headlines. Bloomberg put Dots and the new $500 tier in one headline, while SiliconANGLE doesn't mention the $500 plan at all. These are two separate announcements from the same day: Pro 500 at $500 a month gives the largest allowance and the Ultrafast speed mode, while a dot already comes with Pro 100.

Who won't get a dot

Free, Go and Plus don't get Dots. Pro subscribers in the EEA, Switzerland and the UK don't have them yet either; Business Premium has no regional exceptions, and in Enterprise, Edu and Healthcare an admin turns the dot on. You have to be 18 or older. One dot is included in the plan; OpenAI promises additional agents later and hasn't named a price.

There's also a drawback the announcement doesn't mention. Flavio Copes, who put together a breakdown from OpenAI's documentation (he says he didn't have access to a dot), points out that the notes a dot keeps about you aren't visible, and you can't delete a single wrong one. The only way to clear them is to reset the whole dot.

What to take for your own agents, even without Dots

Our opinion, and you're free to disagree: the most valuable part of this launch isn't the dot itself but how OpenAI laid out its permissions. These techniques carry over to any agent you run on a schedule, whether that's Claude Code on cron or an orchestrator where agents have a boss and a budget.

First: keep looking separate from acting. When nobody is watching the agent, it only reads, and anything it writes to the outside world goes through confirmation. Second: a separate reviewer before each action, with clear risk categories. OpenAI's are data disclosure, destructive actions, money, access and outbound messages, and its reviewer does worst where it's unclear whether the user allowed the action. So ambiguity has to be removed from the rules themselves: the review won't make up for it. Third: don't keep an agent in one long chain. Judging by the test above, every new task in the same context adds to the chance that it carries something over from the previous one.

We'll be wrong if, a month from now, OpenAI publishes real-world data and dots barely overstep on long chains. Then the caution about long chains will prove unnecessary, and always-on agents will become the norm sooner than it looks today.

If you're setting up your own background agent

Split reading and writing across different permissions. Route anything irreversible through confirmation: stopping doesn't roll back what's done, in Dots or in your own agent. Start each new task with a clean context and spell out its boundaries explicitly.

Versions, plans and limits are as of 30 September 2026; check the current ones, since OpenAI promises to announce terms after the first month.

Sources11expand
  1. OpenAI, "GPT-6 Astra System Card", Dots appendix, 29 September 2026 — https://deploymentsafety.openai.com/gpt-6-astra/sec:appendix-dots
  2. OpenAI, "Meet dots", ChatGPT Learn, 29 September 2026 — https://learn.chatgpt.com/docs/dots
  3. OpenAI, "Introducing dots", 29 September 2026 — https://openai.com/index/introducing-dots/
  4. SiliconANGLE, "OpenAI launches Dots, always-on AI agents in ChatGPT with their own cloud computers", 29 September 2026 — https://siliconangle.com/2026/09/29/openai-launches-dots-always-on-ai-agents-in-chatgpt-with-their-own-cloud-computers/
  5. The Next Web, "OpenAI launches dots, always-on AI agents with their own cloud computers", 29 September 2026 — https://thenextweb.com/news/openai-dots-always-on-ai-agents-cloud-computers-devday
  6. The Next Web, "OpenAI halves Pro 200 usage and launches a $500 ChatGPT plan at DevDay", 29 September 2026 — https://thenextweb.com/news/openai-devday-pro-200-usage-cut-pro-500-plan
  7. Engadget, "OpenAI adds $500 Pro subscription, nerfs its existing $200 tier", 29 September 2026 — https://www.engadget.com/2272106/openai-adds-dollar500-pro-subscription-nerfs-its-existing-dollar200-tier/
  8. Bloomberg, "OpenAI Unveils Always-On AI Agent Dots, New $500 Paid Tier", 29 September 2026 — https://www.bloomberg.com/news/articles/2026-09-29/openai-unveils-always-on-ai-agent-dots-new-500-paid-tier
  9. TechCrunch, "OpenAI launches Dots, its bubbly agentic avatar", 29 September 2026 — https://techcrunch.com/2026/09/29/openai-launches-dots-its-bubbly-agentic-avatar/
  10. Hacker News, "Dots: Always-on agents", 29 September 2026 — https://news.ycombinator.com/item?id=49896604
  11. Flavio Copes, "A deep dive into OpenAI dots", 30 September 2026 — https://flaviocopes.com/openai-dots/

Comments