OpenAI launched Dots at DevDay on 29 September 2026: always-on agents that run on GPT-6 Astra, each with its own cloud computer and browser, connected to more than 4,000 applications through the plugins a ChatGPT account already has. The first dot is included at no extra cost on Pro and Business Premium plans, and Enterprise workspaces get a beta that an admin has to switch on. Three days later, the product is live for some accounts, gradually rolling out to others, and unavailable to every Pro subscriber in the European Economic Area, Switzerland and the UK. This is part one of a four-part series. It covers what a dot actually is, how it differs from ChatGPT and Codex, the four permission levels, the actions a dot is never allowed to take, and the pricing OpenAI has published alongside the pricing it has not. Parts two to four compare Dots with Meta Muse, work through the audit problem, and take the EU question apart.
What a dot is, and what it is not
ChatGPT is a conversation. You open it, ask, read, close it. Codex is a coding agent: you hand it a task against a repository and it works until the task is done. A dot is neither. OpenAI's own description is "always-on agents built to handle everything," and the operational meaning is that the agent persists between your sessions, holds goals you gave it days ago, and keeps working on them without you being present. It is not tied to a chat window, a device or a particular interface. You can reach it from ChatGPT on desktop, web or mobile, from Slack, from Microsoft Teams, and by voice call. Text messaging is listed as coming soon.
Each dot gets its own cloud computer and browser, hosted by OpenAI. You can watch that computer while the dot works. On supported websites the dot can sign in using saved passwords without the password ever being exposed to the model, which is the mechanism that lets it act in your accounts rather than just read about them. Connecting your own local machine is possible but optional, and it starts turned off: you enable it in the ChatGPT desktop app with an explicit confirmation, and camera, microphone and screen access each need a separate operating-system permission on top.
The behaviour that most separates a dot from a scheduled ChatGPT task is what OpenAI calls proactive research. When you are not asking it anything, the dot can read from the connected sources you have permitted and save private notes for later. OpenAI's help text is specific that proactive research is read-only: the research tools cannot send messages to other people, cannot change content through plugins, and cannot control a browser or a computer. A dot checking your calendar every morning and preparing notes is proactive research. A dot sending the resulting email is an action, and actions run under the permission model below.
A dot can run several projects at once and delegate parts of its work to sub-agents. When it starts coding work, that work runs in Codex. When it starts document work, that runs in ChatGPT Work. The dot is the coordinator; the existing products are the hands. That split matters for billing, which is covered further down.
The four permission levels
Custom Rules are the control surface. For each supported action type you pick one of four behaviours, and the wording in OpenAI's help centre is worth quoting exactly because it will end up in your usage policy:
- Take action without asking. The dot acts autonomously whenever it judges the action useful.
- Take action if pre-approved. The dot acts only when you explicitly asked for that action in your prompt.
- Ask before taking action. The dot proposes, you approve each time.
- Hand off to you. The dot prepares the work and stops. A human finishes it.
Above the rules sits auto-review. Before an action that could affect an account or share information, the dot checks the planned action against your instructions, your Custom Rules and OpenAI's safety requirements. The example OpenAI gives is an outgoing email: the recipient and the content are checked before the send is allowed, blocked or routed for approval. Custom Rules can add restrictions. They cannot remove the mandatory confirmations, the handoffs or the core safety requirements that OpenAI has fixed.
Those fixed items are the floor every organisation inherits:
- Password changes and money transfers always come back to the human. No rule moves them.
- Permanent deletion of data and installing software the dot does not recognise require per-action approval.
- Card purchases need approval either in advance or per transaction.
- Approving one message does not grant the dot ongoing permission to contact that person.
Read that list as a product decision rather than a safety guarantee. OpenAI's own launch text ends with "dots can still make mistakes, so always review consequential work." The floor stops the two or three catastrophic categories. Everything else, including sending contracts, changing calendar entries and editing documents in shared drives, is governed by whichever of the four levels you chose, and the default for a new dot is not the strictest one.
Connectors: 4,000 apps and the permissions you already granted
Dots do not have their own connector directory. They use ChatGPT's plugins, which OpenAI counts at more than 4,000 applications, and plugin permissions are shared across dots, ChatGPT, ChatGPT Work and Codex. If an employee connected their mailbox, calendar and Slack to ChatGPT in the spring, their dot has those connections on day one. Nobody re-consents. Nobody re-scopes.
This is the exact opposite of the bet Meta made with Muse three weeks earlier. Meta built a curated directory of connectors that it reviews itself, and runs each user's agent in a dedicated Secure VM with a monitoring layer it calls Sentinel. OpenAI inherited an existing, very large permission surface and put a rules engine in front of it. Part two of this series looks at what those two trust models mean for blast radius. For now, the practical point is that the width of a dot's reach is set by decisions made before Dots existed, and most of those decisions were made by individual employees, not by IT. If you want a starting point for the Meta side, the Muse connectors post covers the directory in detail.
Two kinds of dot exist. A standard dot runs on the user's own account and identity: when it sends an email, the email is from that person, and when it edits a file, the audit log shows that person. Specialist dots, which are in an enterprise preview, get their own identity, their own credentials and their own access to company systems, and are designed to hold a defined role such as invoicing or procurement. OpenAI says it is partnering with Microsoft to integrate specialist dots with the governance and security controls in Microsoft Agent 365, which is where Entra agent identities would come in. Part three is about why that distinction between standard and specialist is the single most important fact in this product for anyone who owns an audit log.
Memory: you can reset it, you cannot read it
A dot builds its own memory from conversations, from proactive research and from what flows in through plugins. That memory can be paused, and it can be reset, which deletes the dot's conversations, saved memories and scheduled tasks together. What you cannot currently do is view, edit or delete an individual memory, including a specific detail that entered the dot's context from a connected app. Disconnecting an app stops new access but does not purge what the dot already saved from it. The memory also flows in both directions with the ChatGPT Memory setting on the same account.
For an individual user this is an inconvenience. For a European employer it is the start of a longer conversation about access and erasure requests, which part four takes up. The fact itself is simple and should be recorded as it stands today, 2 October 2026: the only erase operation on a dot's memory is a full reset.
Pricing and limits: what is published and what is not
The published position, from OpenAI's help centre and launch material, is this:
| Plan | Dots access at launch | Regions |
|---|---|---|
| Free, Go, Plus | None | n/a |
| Pro 100, Pro 200, Pro 500 | First dot included | Eligible markets only; EEA, Switzerland and UK excluded, no date given |
| Business Premium | First dot included | All supported ChatGPT regions |
| Enterprise, Edu, Healthcare | Beta, off until an admin enables it | Per workspace |
Talking to your dot does not count toward ChatGPT usage limits. Work the dot starts or manages in Codex or ChatGPT Work counts toward those products' limits as normal. So a dot that spends its day drafting and researching is close to free under the current terms, while a dot that spins up Codex tasks every hour is drawing on the same allowance a human developer would. OpenAI has said the launch month carries extended allowances and that per-plan usage terms will be published after that window, which lands around the end of October. Users must be 18 or over, and rollout is gradual: the help text says it "may take several days" to reach an account.
The Pro plans are changing underneath this. From 30 October 2026, Pro 200 keeps its $200 monthly price but its Codex and Work allowance falls from 20 times to 10 times the Plus allowance, and GPT-6 Pro messages drop from 200 to 100 per week. Existing Pro 200 subscribers keep today's limits until 29 October and receive a one-time grant of 62,500 usage credits, which OpenAI values at $2,500 and which expire on 31 December. A new Pro 500 tier at $500 per month is the only Pro plan with Ultrafast, OpenAI's up-to-eight-times-faster generation mode in Codex. If a dot's Codex work draws on the Pro 200 allowance, that allowance is about to halve.
Four things OpenAI has not published as of today, and which any budget owner should write down as open items rather than estimate:
- Permanent per-plan allowances for dot work once the launch month ends.
- The price of a second dot. OpenAI says you will "later be able to add more dots," with no figure.
- The cost of speed or workload upgrades for a single dot, which OpenAI has described as a future option.
- Any per-task charge for background work, including proactive research, if one is introduced.
Until those are published, a cost model for Dots is a cost model for the Codex and ChatGPT Work usage it generates, plus the plan price. That is a usable number for a pilot and an unusable one for a procurement decision.
Where this sits next to Azure
Dots is a ChatGPT product, not an API product. There is no Dots endpoint, nothing to deploy in Azure AI Foundry, and no way to point a dot at your own tenant's model deployment. The model underneath is GPT-6 Astra, which is available through Foundry under the pricing and regional conditions covered in our Foundry price-gate post, and whose actual capabilities we mapped in what GPT-6 Astra can and cannot do. An Azure team that wants an always-on agent with the same model, its own identity, and logs it controls has to build that agent: an Entra agent identity, an agent runtime, a scheduler and connectors it chose. That is more work than switching on a dot. It is also the only version of this pattern where the audit log, the memory store and the data location are yours.
The two paths are not exclusive. A reasonable Swedish enterprise position for the next quarter is to let a small, named group pilot dots on Business Premium under tight Custom Rules, and to run the specialist-dot and Agent 365 story through its Microsoft account team, while anything that touches regulated data stays on a self-built agent in the tenant.
The Swedish and EU angle
The availability table above contains the sharpest fact for a Swedish reader. A Swedish company on ChatGPT Business Premium can switch dots on today, because Business Premium rolls out in all supported ChatGPT regions. A Swedish individual on ChatGPT Pro cannot, because the EEA, Switzerland and the UK are excluded from the Pro rollout with no date attached. An Enterprise workspace in Sweden sits in between: the beta is there, but off, until the workspace admin enables it. OpenAI has not said why the consumer tier is held back while the business tier ships, and it has not said when that changes.
For the company that does switch it on, the questions arrive in a predictable order. A dot doing proactive research across a mailbox and a calendar is processing personal data for a purpose that was not the purpose the data was collected for, and an always-on agent makes the purpose-limitation conversation under GDPR harder than a chat window does. A memory that cannot be inspected item by item sits awkwardly next to a data subject's access request. And an agent that acts under an employee's own identity raises questions under the AI Act's transparency provisions that nobody in the company has had to answer before. None of that is a reason to refuse the pilot. It is a reason to write the rules before the first dot is named, and part four of this series is the worked version of that argument. Our Azure OpenAI integration service covers the self-built alternative for teams that want the agent in their own tenant from the start.
Decision guide for this week
- Find out which plan you are on. Business Premium means dots are reachable in Sweden now. Enterprise means an admin decision is pending. Pro means nothing until OpenAI opens the EEA.
- Inventory existing ChatGPT plugin connections for the pilot group before anyone creates a dot. Those connections are the dot's reach on day one.
- Set the four levels explicitly. For a first pilot, put outbound messages and file edits on "ask before taking action" and leave only reading and drafting on "take action without asking."
- Keep local computer access off. It is off by default. A pilot does not need it.
- Treat the memory as reset-only. Tell pilot users that the only erase is a full reset, and keep the pilot away from data you would have to erase selectively.
- Budget on Codex and Work usage, not on the dot. If pilot users are on Pro 200, their allowance halves on 30 October.
- Record the four unpublished prices as open items in the pilot's cost sheet, and revisit after OpenAI publishes per-plan terms.
subscribe # the AI news that matters, minus the noise
Sources
- OpenAI: Introducing dots (29 September 2026)
- OpenAI Help Center: Getting started with your dot
- OpenAI Help Center: Dots privacy, security and safety FAQs
- OpenAI Help Center: Manage dots in ChatGPT workspaces
- OpenAI: DevDay 2026 recap
- The Next Web: OpenAI halves Pro 200 usage and launches a $500 ChatGPT plan at DevDay
- BetaNews: OpenAI launches dots, always-on ChatGPT agents with their own computers