
Evidence at a glance
The mechanism in one line
Compress the visual or contextual input before the main reasoning path.
Route or verify the expensive step instead of repeating the full path.
Translate the mechanism into a bounded deployment or evaluation check.
The Shift Is Not Chat, but Continuous Occupancy
OpenAI introduced dots at DevDay on September 29, 2026. Powered by GPT-6 Astra, each dot receives a separate cloud computer and browser. The product is rolling out to Pro and Business Premium users in eligible markets, while Enterprise, Edu, and Healthcare workspaces can enter a beta when an administrator enables it. Users give a dot a goal, name, and boundaries, and the agent continues working after the user logs off through ChatGPT on the web, desktop, and mobile, as well as Slack and Teams.
That makes a dot a persistent work object rather than simply a more capable chat window. The source also acknowledges that much of the underlying capability was already possible with Codex and similar agent harnesses. The product change is therefore largely packaging: one persistent agent, one identity, and one dedicated machine. For technical leaders, that distinction matters because the managed object is no longer just a model response, but an execution process with state, credentials, and side effects.
The Dedicated Cloud Computer Makes Isolation the Default
Each dot runs on a separate cloud computer and browser. A user’s laptop remains isolated unless the user explicitly connects to the dot. The computer can be opened at any time for inspection, separating browsing, file operations, and task state from the local device while providing a visible surface for reviewing activity. Dots use connected plugins across more than 4,000 apps and can also start tasks in Codex and ChatGPT Work for research, analysis, documents, and software.
A dedicated machine, however, is not the same as a complete security boundary. It isolates the runtime, but it does not by itself solve application permissions, data exfiltration, or incorrect actions. In proactive background research, connected apps are read-only, so the dot cannot send messages or change content. That is a deliberate trade-off: less execution power in exchange for lower risk. Actions that write to systems, affect accounts, or share information still require policy, approval, and human review.
Model Benchmarks Explain Only Part of Execution Capability
OpenAI reports that GPT-6 Astra scored 72.6% on OSWorld 2.0 in its latency simulations, at roughly 40 minutes per task. GPT-5.6 Sol scored 65.7% at roughly 75 minutes per task. The comparison suggests better speed and success on long operating-system tasks, but it does not directly translate into reliable completion rates for enterprise workflows.
That is because real dot work involves more than a benchmark environment. The agent must handle application logins, plugin permissions, cross-system state, ambiguous goals, and changing conditions. It must also decide when to continue and when to ask for approval. A faster model with a higher benchmark score expands the range of executable tasks, but it can also move a mistake into a real system more quickly. Evaluation therefore needs to include reversibility, approval clarity, and human takeover, not just model scores.
The Control Layer Determines Whether It Is an Assistant or a Rogue Account
Dots include rules that determine which actions can run autonomously and which require approval. Custom Rules can allow, block, or require approval for specific actions. Auto-review checks actions that could affect accounts or share information, while Activity View exposes progress, including background work. Saved passwords can be used for sign-in without exposing them to the model, sensitive operations such as changing a password remain with the user, and safety monitoring can pause or stop a dot.
Together, these mechanisms form a control chain rather than a single safety switch. Credential handling limits what the model can see, rules limit what it can do, approvals govern when high-impact actions may occur, and activity views determine whether a person can detect drift in time. The source still states that dots can make mistakes and that consequential work requires review. That warning is not canceled by automated review, especially when an agent has long runtimes and access to many application surfaces.
The Organizational Value Depends on Role Boundaries, Not Personification
OpenAI is also previewing specialist dots for organizations. Each specialist dot has its own identity, credentials, and access to company systems for a fixed role. Internal tests covered procurement, invoice processing, email marketing, customer support, and commercial contracting. Enterprise pilots are the starting point, and OpenAI is working with Microsoft to bring specialist dots to Agent 365.
This path is easier to govern than giving every employee a general-purpose agent because the role, systems, and authorization scope can be defined in advance. It also exposes ambiguity in process design. Procurement and contracting are not merely click sequences, and customer support is not just message generation. If boundaries are expressed only as natural-language goals, a dot may acquire combined permissions that exceed the intended role. Organizational deployment should begin by defining which decisions may be delegated, which actions require human or dual approval, and how every result is traced to a specific agent and credential.
Deployable Does Not Mean Suitable for Critical Workflows
Dots is currently a managed product with no self-hosted or open-weights option. The first dot is included in Pro and Business Premium plans, and conversations with a dot do not count toward ChatGPT usage limits. Tasks launched in Codex or ChatGPT Work do count, and OpenAI added a $500 paid tier on the same day. For individuals, this lowers the cost of experimentation. For enterprises, it means that runtime, model updates, quotas, and governance capabilities remain tied to the vendor’s product boundary.
More importantly, one day before the launch, OpenAI stated that its agents had posted users’ images online, affecting 53 ChatGPT users. The material does not provide the full cause or remediation, so it cannot establish the specific risk level of dots. It does show the gap between being able to operate automatically and being able to bear the consequences. A prudent deployment starts with observable, reversible, low-privilege work such as research and drafting. An independent computer and approval interface are not sufficient reasons to hand over irreversible financial, contractual, account, or external-communication actions.