# OpenAI Dots and the EU: Pro is blocked, Business is not

OpenAI Dots is closed to ChatGPT Pro subscribers in the EEA, Switzerland and the UK but open through Business Premium from $120 a month, which makes the European customer the GDPR controller for an agent whose memories cannot be viewed or deleted one by one. The Enterprise beta does not support data residency, so a Swedish pilot needs a written purpose, a signed DPA and a plan for erasure requests before the first dot is named.

- Published: 2026-10-05 · Category: AI & Cloud Infrastructure · Tags: OpenAI Dots, GDPR, EU AI Act, Data Residency, ChatGPT Business, AI Agents, Agent Governance, Dots Series
- Author: Technspire AB, Stockholm (https://technspire.com)
- Canonical: https://technspire.com/en/blog/openai-dots-and-the-eu-pro-blocked-business-premium-open

A consultant in Stockholm paying $200 a month for ChatGPT Pro cannot get an OpenAI dot. A two-person company on the same street can have one for $120 a month. Six days after launch that is still the position: Pro plans exclude the European Economic Area, Switzerland and the UK with no date attached, while Business Premium rolls out in every region ChatGPT supports. This is the fourth and last part of our Dots series, after [the product](/en/blog/openai-dots-decoded-always-on-agents-on-gpt-6-astra), [the comparison with Meta Muse](/en/blog/openai-dots-vs-meta-muse-two-agent-trust-models-compared) and [the audit log](/en/blog/openai-dots-audit-log-whose-action-was-that). The question here is what a Swedish company takes on when it uses the one door that is open.

## The availability map on 5 October 2026

OpenAI's own pages return an error to automated fetches, so the table below was re-checked today against four independent write-ups of the launch post and help centre. They agree on every row.

| Plan | List price | Dots in the EEA, Switzerland, UK | Default state |
| --- | --- | --- | --- |
| Free, Go, Plus | $0 to $20 per month | No, in any region | Not applicable |
| Pro 100, Pro 200, Pro 500 | $100, $200, $500 per month | No. Available elsewhere for users over 18 | Gradual rollout outside the excluded regions |
| Business Premium | $100 per user per month on annual billing, $125 monthly | Yes, all supported ChatGPT regions | Rolls out to Premium seats; no default-off statement found |
| Enterprise, Edu, Healthcare | Contract | Yes, as a beta | Off until a workspace admin enables it |

The EEA is wider than the EU. Norway, Iceland and Liechtenstein sit inside the exclusion, so a Nordic group cannot solve this by buying Pro seats from its Oslo office.

## What OpenAI has said about why

Nothing. SmartScope, which read the launch post and both help articles on 30 September, records that specific technical or legal reasons for the exclusion "are not explicitly stated in official announcement materials". Hello Growth reached the same finding the same day and added that the talk about the AI Act circulating online does not originate from OpenAI. We have seen secondary sites attribute a regulatory explanation to Sam Altman. We could not trace that to a primary source and are not repeating it.

One structural difference between the two doors is on the public record, and it is the useful one. Pro is a consumer subscription. Business Premium is a business plan for which OpenAI will sign a Data Processing Addendum, with OpenAI Ireland Ltd. as the contracting party for EU companies, and where workspace data is excluded from model training by default. Under that arrangement the customer is the controller and OpenAI processes on its instructions. Whether that is the reason for the split is our reading and OpenAI has not confirmed it. The consequence holds either way: when dots arrive in Europe through Business Premium, the GDPR obligations arrive with your company's name on them.

## The open door, priced

Business plans need at least two seats in total, and Standard and Premium seats can be mixed. Only Premium seats include a dot. The arithmetic at list price, before VAT:

| Setup | Annual billing | Monthly billing |
| --- | --- | --- |
| Smallest workspace with one dot (1 Premium + 1 Standard) | $120 per month | $150 per month |
| Five-person pilot, all Premium | $500 per month | $625 per month |
| Ten-person pilot, all Premium | $1,000 per month | $1,250 per month |

The first dot is included. Talking to it does not count against usage limits, while work it hands to Codex or ChatGPT Work does. OpenAI has not priced additional dots or the speed and workload upgrades it says are coming, so a budget beyond the first dot per seat cannot be written yet.

Two side effects of that price list deserve attention. A sole trader locked out of Pro can reach a dot by opening a two-seat workspace for $120 a month, and in doing so becomes a business customer with a controller's duties. And any employee with a company card can do the same thing without asking IT. The Enterprise beta is off until an admin turns it on. We found no equivalent statement for Business Premium, so treat a self-service workspace as the likeliest way an unreviewed dot ends up reading a company mailbox.

## Data residency: the beta does not support it

The sentence European buyers should read first sits in OpenAI's guide to cloud and local access, quoted by both Hello Growth and Beri: "During the Enterprise beta, dots do not support data residency or inference residency." The same guide lists workspaces where dots are unavailable altogether: FedRAMP workspaces, workspaces using Enterprise Key Management, and workspaces with inference residency set to the UAE.

Read that against a typical Swedish Enterprise setup. A company that chose European data residency for ChatGPT made a decision about where conversations and files are stored. Enabling the dots beta puts an agent with mailbox and file access outside that decision. A company that went further and holds its own encryption keys cannot enable dots at all, which at least removes the ambiguity.

For Business Premium we found no residency statement specific to dots in either direction. The safe working assumption is that a dot's cloud computer, its browser sessions and its memory are processed outside the EEA, and that the international transfer terms in your DPA are what cover it. Confirm that in writing before the pilot. A transfer impact assessment written for a chat assistant that sees pasted text does not describe an agent that reads a whole mailbox continuously.

## Purpose limitation meets proactive research

Article 5(1)(b) of the GDPR requires personal data to be collected for specified, explicit purposes and not processed further in ways incompatible with them. A chat assistant fits that model without much strain, because a person decides what to paste and why. A dot inverts the sequence. It researches connected apps in the background with read-only access, decides for itself what is relevant to the goals it was given, and stores what it learns. innFactory put the difficulty plainly: proactive research is hard to reconcile with purpose limitation "if nobody has set the frame".

Setting the frame is the controller's job, and it is practical work:

- **Write the purpose per pilot role.** "Prepare meeting briefs from the account manager's own calendar and CRM records" is a purpose. "Help with work" is not one.
- **Scope the connections to match.** If the purpose needs calendar and CRM, do not connect the shared HR drive because it was already linked to ChatGPT. A dot inherits existing plugin grants with no new consent step.
- **Keep special categories out of reach.** Health data, union membership and similar Article 9 material in a mailbox or file share a dot can read is the hardest case to defend.
- **Run a DPIA before the pilot.** Systematic background processing of mailbox content by a new technology is the kind of processing Article 35 was written for. Your data protection officer decides whether it is required; starting the assessment costs little either way.

## The access and erasure problem

Part one of this series noted that a dot's memory can be reset and cannot be read. For a European controller that design choice has a direct legal edge. The documented facts, as reported from OpenAI's help centre and admin guide:

- Individual dot memories cannot currently be viewed, edited or deleted.
- Memory can be paused. Nothing published says pausing removes what is already stored.
- Disconnecting an app "does not delete information already obtained".
- Dot notes are kept separate from ChatGPT's saved memory, so clearing ChatGPT memory does not clear them.
- Reset deletes the dot together with its conversations, saved memories and scheduled tasks.

Now take an ordinary request. A former customer contact writes to ask what personal data your company holds about them under Article 15, and to have it erased under Article 17. Their name, phone number and a complaint thread are in a mailbox that an account manager's dot has been reading for three weeks. You have one month to respond under Article 12(3).

| What the request needs | Mailbox and CRM | Dot memory |
| --- | --- | --- |
| Find what is held about the person | Search | No view of individual memories |
| Give the person a copy | Export | No documented export of memories |
| Erase only that person's data | Delete the records | Not possible per memory |
| Be certain nothing remains | Verify by search | Reset the dot, losing all context and scheduled tasks |

Some care is needed about what this proves. We do not know what a dot actually retained about that person, and neither would you. OpenAI's admin guide points to the Compliance API for "supported cloud records" of user messages and dot replies, and it is possible that route exposes more than the product interface does. Which records are supported is not listed. Whether a dot's distilled notes count as personal data you must disclose is a question for your DPO and, eventually, for a supervisory authority. What can be said without qualification is that the only erasure control with a certain outcome today is the reset, and a reset per erasure request is a heavy price for a tool whose value is accumulated context.

OpenAI describes the memory limit with the word "currently". A viewer and per-memory deletion would change this section more than any regulatory development would.

## The AI Act: one duty that is live, one line to stay behind

Article 50 of the AI Act has applied since 2 August 2026. Its first paragraph binds providers of systems that interact directly with people: those people must be informed that they are dealing with an AI system unless that is obvious. The Commission's FAQ on Article 50 names AI agents alongside chatbots and avatars as examples of such systems. The duty sits with OpenAI as provider. The open question for a deployer is the recipient: when a dot sends an email in an employee's name to someone outside the company, that person has no way to know an agent wrote and sent it. How Article 50 reads on that situation is unsettled, and we are not going to settle it in a blog post. The disclosure line we recommended in part three costs one sentence in a signature and puts you on the right side of whichever reading prevails.

The line to stay behind is employment. AI systems used to screen candidates or to evaluate and manage workers fall in the Act's high-risk category. The Digital Omnibus moved those obligations for standalone systems to 2 December 2027, according to Goodwin's August summary, but the classification itself has not gone anywhere. Keep dots away from CV triage and performance material and the high-risk regime stays out of your pilot. The AI literacy duty in Article 4 has applied to deployers since February 2025 and covers dots like any other AI tool: pilot users should be able to explain the four rule levels before they name their dot.

## The Swedish angle

Sweden's supervisory authority is IMY. We found no statement from IMY, from the Irish Data Protection Commission or from any other European authority about dots as of today. Silence six days after a launch is normal and says nothing about what a first complaint would produce.

Three local points follow from the availability split. First, Sweden has a large population of one-person consultancies, and many of them are exactly the Pro subscribers now excluded. Reaching a US Pro dot through a VPN would put client data into a consumer plan with no DPA, where training depends on a personal setting. The two-seat Business workspace is the legitimate route, and it comes with the controller duties described above. Second, a dot that reads an employee's mailbox continuously is a change in how employee communications are processed. Raise it with employee representatives before the pilot, as part three argued for logging. Third, compare the position with Meta Muse, which had no EU launch date and no business contract path when we covered [Muse and the EU](/en/blog/muse-and-the-eu-no-launch-date-no-dpa-and-your-options) a week ago. OpenAI has given European companies a contractual route and left the open questions inside it. Meta has given them nothing to assess yet.

## Decision guide: three positions for a Swedish company

| Position | Fits when | Cost and tradeoff |
| --- | --- | --- |
| Wait | You hold your own keys, need EU residency for the workload, or handle special category data in the systems a dot would read | No spend. You learn nothing first-hand until memory controls and residency ship |
| Constrained Business Premium pilot | A small group with low-sensitivity mailboxes, a written purpose and a signed DPA | $500 to $1,000 per month for five to ten seats. Erasure requests may force a reset |
| Build the agent in your own tenant | The workload touches customer personal data at volume or is one a regulator may ask about | You design the memory store, so access and erasure are queries you control. You also build and run it, without 4,000 plugins |

The third position is where our own work sits. An agent in Azure AI Foundry keeps its memory in a store you choose, in a region you choose, with deletion you can prove. The EU deployment position for the model family is covered in our post on the [GPT-6 Astra Foundry price gate and EU gap](/en/blog/gpt-6-astra-foundry-price-gate-eu-gap), and the [Azure OpenAI integration offers](/en/services/azure-openai-integration#offers) describe how we scope a build like that.

## Action list for this week

1. Check card statements and expense reports for self-service ChatGPT Business workspaces opened since 29 September.
2. If you run ChatGPT Enterprise, confirm the dots beta is still off and record who may turn it on.
3. Ask OpenAI in writing where a dot's cloud computer and memory are processed for your plan, and when data residency support is planned.
4. Ask which dot records the Compliance API returns, and whether Business Premium includes it.
5. Sign the DPA with OpenAI Ireland before any pilot seat is assigned.
6. Write a one-paragraph purpose per pilot role and trim plugin connections to match it.
7. Start the DPIA, with the data subject request procedure as its own section: who decides on a reset, and what the requester is told.
8. Add the agent disclosure line to pilot users' signatures.
9. Set a review date. The memory viewer, residency support and a Pro date for the EEA are the three announcements that would change this assessment.

## Sources

- [OpenAI: Introducing dots (29 September 2026)](https://openai.com/index/introducing-dots/)
- [OpenAI Help Center: Dots privacy, security and safety FAQs](https://help.openai.com/en/articles/20001529-dots-privacy-security-and-safety-faqs)
- [OpenAI Help Center: Getting started with your dot](https://help.openai.com/en/articles/20001530)
- [OpenAI: Enterprise privacy (DPA, OpenAI Ireland Ltd., training defaults)](https://openai.com/enterprise-privacy/)
- [OpenAI: ChatGPT Business pricing](https://openai.com/business/pricing)
- [European Commission: Transparency obligations under Article 50 of the AI Act (FAQ, updated 24 July 2026)](https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act)
- [Goodwin: EU AI Act transparency obligations are now in force (August 2026)](https://www.goodwinlaw.com/en/insights/publications/2026/08/alerts-technology-dpc-eu-ai-act-transparency-obligations-now-in-force)
- [SmartScope: OpenAI dots supported countries and plans (30 September 2026)](https://smartscope.blog/en/blog/openai-dots-regional-availability-2026/)
- [Hello Growth: OpenAI dots, always-on agents in Europe (30 September 2026)](https://hellogrowth.ai/en/blog/openai-dots-always-on-agents)
- [Beri: OpenAI's dots beta skips data residency (2 October 2026)](https://www.beri.net/article/openai-dots-always-on-agents-enterprise-beta-admin-controls-data-residency-audit-gaps)
- [innFactory: OpenAI dots, always-on AI agents in the enterprise (30 September 2026)](https://innfactory.ai/en/blog/openai-dots-always-on-ai-agents-enterprise/)
- [eesel: OpenAI Dots pricing (30 September 2026)](https://www.eesel.ai/blog/openai-dots-pricing)
- [Creuto: OpenAI Dots, decide these four things before you enable one (2 October 2026)](https://creuto.com/openai-dots-controls-before-you-enable)

---

Technspire AB builds AI agents, Azure OpenAI solutions, and production web platforms for Swedish and EU enterprises. Book a call: https://calendly.com/technspire · hello@technspire.com · More articles: https://technspire.com/en/blog · Site overview for agents: https://technspire.com/llms.txt
