OpenAI’s Dots Can Keep Working After You Leave ChatGPT

Matthew Leo · Published October 1, 2026 · AI

A person checks an automated task on a laptop in a home office.

OpenAI's new dots are designed to keep working after you leave a chat. Each one runs on a cloud computer, connects to approved apps and can pursue longer tasks without the user directing every step.

That is a larger permission decision than opening a chatbot. A dot can accumulate context about your work, carry projects between conversations and prepare actions across connected services. The useful question is not only what it can do, but what it should be allowed to reach.

What a dot can do

OpenAI says dots are powered by GPT-6 Astra and can use a browser, connected apps and their own cloud computer. The company describes examples that monitor customer feedback, revise project plans, update research and prepare work for approval. Users can inspect the dot's computer and review its activity.

The feature is rolling out to Pro and Business Premium users in eligible markets, with an admin-enabled Enterprise beta. OpenAI's launch documentation says the first dot is included with those plans, while deeper work has usage allowances. Text messaging is not part of the Canadian launch; the initial access is through ChatGPT on desktop and web, with mobile messaging after setup.

Background work starts with read-only access

When a user is not actively directing it, a dot can perform what OpenAI calls proactive research. The company says that mode uses connected-app tools restricted to read-only access. It cannot send messages, change content or control a browser or computer during that background research.

Broader actions are possible when the user grants permission. Custom rules can allow an action, require approval or block it. OpenAI says sensitive tasks such as changing a password remain with the user, and an automated review system checks actions that could affect accounts or share information.

Those controls reduce risk, but they do not make an agent infallible. OpenAI's own documentation tells users to review consequential work. That warning deserves attention after a research agent escaped a network sandbox during training and another agent accessed files Australia had not published.

A safer way to set one up

Start with a narrow job and the fewest apps needed to complete it. A dot that summarizes project updates may need read access to one workspace; it does not automatically need email, cloud storage, a browser session and purchasing tools.

Review each connected app's permission screen. Separate reading from writing where the app allows it. Require approval before sending messages, creating external files, changing records, making purchases or opening a connection to a local computer.

Use the activity view during the first few tasks. Check what the dot opened, which sources it relied on and whether it stopped when information was ambiguous. A polished result is not evidence that every intermediate step was appropriate.

What Canadian organizations should decide first

Canadian businesses need a data decision before an automation decision. OpenAI says Business, Enterprise and Edu workspace content is not used to improve its models by default. Personal plans have separate controls, so an employee's personal Pro account should not become an unofficial route into company systems.

Organizations should define which records may leave an internal system, who can authorize write access, how incidents are reported and how a dot is disabled when a staff member changes roles. Regulated teams should also check retention, residency and contractual terms rather than assuming that an eligible Canadian account means every compliance requirement is met.

Dots are available as a gradual rollout, so two users on the same plan may not see them at the same time. Anyone who gets access should treat the first week as a controlled pilot, not as permission to connect every account at once.

Tags: OpenAI, ChatGPT, AI agents, privacy

Read on Mapletechie