AI-Assisted Development

OpenAI Dots: What Always-On AI Agents Mean for the Future of Software

OpenAI’s Dots can keep working between conversations, use connected apps, and operate their own cloud computer. Here is what persistent AI agents could mean for businesses and software products.

Abdullah·· 14 min read

Sections

For most of the generative AI era, the interaction has been simple: you ask the AI for something, it produces an answer, and the session effectively ends until you come back.

OpenAI's new Dots product changes that model. Announced on September 29, 2026, Dots are persistent AI agents powered by GPT-6 Astra. Instead of waiting for another prompt, a Dot can keep working toward an ongoing goal, use connected applications, operate through its own cloud computer, and return when it has progress, a result, or a decision that requires human input.

The important part is not the animated character or another new ChatGPT interface. It is the change in responsibility. AI is moving from helping with individual tasks toward potentially owning parts of a workflow over time.

That is a much bigger product shift than simply making another language model smarter.

What Are OpenAI Dots?

OpenAI describes Dots as always-on agents powered by GPT-6 Astra. Each Dot has its own cloud computer and browser and can work with applications the user chooses to connect. OpenAI says its plugin ecosystem gives Dots access to more than 4,000 applications, depending on available integrations and permissions.

A user gives the Dot a goal, connects the tools it needs, and decides what it is allowed to do independently. The Dot can then continue working across longer tasks rather than requiring the user to manually restart the process every time another step appears.

OpenAI gives examples such as watching customer feedback and preparing product improvements, helping engineering teams migrate away from an old API, updating presentations when new information arrives, coordinating schedules, and turning creator transcripts into clips, notes, and social content.

The common pattern behind those examples matters more than any individual use case. A Dot is not being asked to produce one output. It is being given an ongoing responsibility.

The Real Shift Is From Tasks to Responsibilities

Traditional AI assistance is mostly task-based. Ask for a market summary. Generate some code. Draft an email. Analyze a spreadsheet. The AI performs the requested operation and hands the result back.

Agentic AI has already started extending that interaction by allowing models to use tools, browsers, code environments, and external systems. We discussed that broader transition in our article on ChatGPT Astra and the move from AI answers to AI action.

Dots push the idea further because persistence becomes part of the product. Instead of saying, "Analyze these customer requests," a team might eventually say, "Keep watching customer feedback, identify recurring problems, investigate them, and prepare useful changes for review."

The first instruction describes a task. The second describes responsibility.

That difference could become one of the defining changes in how businesses use AI. Much of knowledge work is not a collection of isolated prompts. It consists of responsibilities that remain active for weeks or months: watching metrics, following projects, checking customer feedback, coordinating people, maintaining documentation, reviewing incoming information, and making sure nothing important is missed.

If AI can reliably hold some of that context over time, the interface between people and software starts to change.

Persistent Context May Matter More Than Another Benchmark Gain

AI models have become extremely good at solving difficult individual problems. But real business work rarely resets after every conversation.

A product manager may spend months following a feature from customer feedback to requirements, design, engineering, testing, launch, and post-release analysis. A salesperson may manage an opportunity through several meetings, technical reviews, pricing changes, internal discussions, and follow-ups. An engineering lead may track a migration across dozens of services and pull requests.

The difficult part is often not answering one question inside those workflows. It is preserving context while circumstances keep changing.

Dots are designed around that problem. They can remember relevant context, work across scheduled and ongoing tasks, and communicate through different surfaces such as ChatGPT, Slack, and Microsoft Teams. Instead of making the user reconstruct the project every time, the agent is intended to maintain continuity.

For software product teams, this suggests that memory and persistent state may become as important to AI products as model intelligence itself. A powerful model without the right history, permissions, business data, and current project state can still make poor decisions.

Dots Are Also an Integration Layer Across Business Software

Another important part of the announcement is that OpenAI is not trying to make every business workflow happen inside one ChatGPT window.

Dots can work with connected tools and communicate through the environments teams already use. That includes ChatGPT itself, connected applications, Slack, Teams, browser-based systems, and other supported tools.

This creates an interesting possibility. Instead of businesses replacing every existing application with an AI-native alternative, an agent may increasingly sit across several systems and coordinate work between them.

Consider a simple customer issue. Relevant information could be spread across Slack, a CRM, analytics, product documentation, GitHub, and a project-management system. Traditional automation often requires predefined integrations and rigid workflows between each system. An AI agent can potentially interpret what is happening, gather the relevant context, decide which step should happen next, and use the appropriate tool.

That does not eliminate software. It increases the importance of well-designed software interfaces, permissions, APIs, data structures, and business rules. The agent needs reliable systems underneath it.

The Cloud Computer Is a Significant Part of the Architecture

Each Dot operates from its own cloud computer rather than automatically receiving access to the user's personal machine. Users can inspect what the Dot is doing, while access to a local computer is optional and must be explicitly enabled.

This separation is important because computer-using AI creates a different risk profile from a chatbot. A chatbot can produce a bad answer. An agent with tools can potentially send information, edit documents, operate websites, modify software, or make other changes that affect real systems.

Giving the agent a separate execution environment creates another boundary between the AI and the user's personal device. It does not remove every risk, but it shows how AI agent architecture increasingly needs isolation and permission management rather than relying entirely on model behavior.

The Most Important Dots Feature May Be the Permission Model

The more useful an agent becomes, the more dangerous a simple "full access" switch becomes.

OpenAI has therefore built several layers around what Dots can do. Users choose which apps the Dot can access. Custom Rules can define whether supported actions can happen without asking, require prior authorization, require approval immediately before the action, or must be handed back to the user.

OpenAI also uses an Auto-review system for certain actions that could affect accounts or share information. The planned action can be checked against the user's instructions, existing permissions, Custom Rules, and built-in safety requirements before execution.

Some actions remain human-only. OpenAI uses changing a password as one example of an operation the agent must hand back to the user.

This may sound like a safety detail, but it is actually a major product-design lesson. As AI becomes capable of acting, permissions become part of the user experience.

A useful agent needs enough authority to avoid stopping every few minutes. A safe agent also needs boundaries around actions with financial, security, privacy, communication, or operational consequences. Finding the right balance between those two requirements will become a core problem for every serious AI agent product.

Proactive AI Does Not Mean Unlimited Autonomy

One of the most interesting Dots capabilities is what OpenAI calls proactive research. A Dot can review information from connected sources and look for things that may deserve the user's attention even without receiving a new request.

But OpenAI has intentionally limited what the agent can do during this proactive mode. The tools used for proactive research can read permitted information, but they cannot directly send messages, change application content, or control a browser or computer. If the agent identifies something that requires an action, the normal permission and approval process still applies.

This is an important distinction. The useful future of agentic AI is probably not an AI system silently taking every action it thinks might help. A more realistic architecture separates observation, recommendation, execution, and approval depending on the risk of the task.

OpenAI's Own Safety Testing Shows Why This Matters

OpenAI published additional safety evaluations specifically for Dots because persistent agents introduce risks that are less important in ordinary chat sessions. A system that works for long periods encounters more external information, more changing context, more potential prompt injections, and more opportunities to misunderstand the boundaries of its authorization.

In one automated prompt-injection evaluation, OpenAI exposed Dots to 50,000 simulated emails across 100 runs, including 16,600 malicious attack emails. OpenAI reported no scored successful attacks in that particular evaluation. The company also conducted adversarial testing involving malicious attachments, hidden instructions, attempts to disclose information, and attempts to manipulate the agent through external content.

However, the published results are not evidence that the problem has been solved. OpenAI also tested whether the agent could preserve authorization boundaries across chains of related tasks. The company reported moderate scope violations in 8.6% of samples with five intervening tasks and 19.7% when the number of intervening tasks increased to ten. OpenAI explicitly notes that these evaluations are designed to stress the system and should not be interpreted as representative production failure rates.

The lesson is more useful than either extreme interpretation. Dots are not evidence that autonomous agents are uncontrollable, but they are also not evidence that businesses can remove oversight. Persistence creates new engineering problems around scope, context, permissions, monitoring, and recovery.

This connects closely with the broader agent-safety issue we discussed after OpenAI's GPT-6.1 Astra safety tests. A system can become better at pursuing goals while still requiring stronger controls around which goals and actions are actually authorized.

What Dots Could Mean for Business Software

The most interesting business impact may be that software increasingly gets designed for two types of users: humans and agents.

Today, business applications are largely built around human interfaces. A person opens a dashboard, finds information, clicks through menus, updates a record, sends something, and moves to the next application.

As persistent agents become more capable, businesses will need systems that expose clearer permissions, better APIs, structured events, reliable data, detailed audit histories, and safe ways for software agents to perform bounded actions.

This means the opportunity is not simply to add an AI chat box to an existing application. Businesses may need to rethink workflows around what the agent should observe, what it can decide, which tools it can operate, which actions require approval, and how every important action is verified afterward.

That is also how we approach AI-assisted application development at Next Level Software. The model is only one part of the product. The surrounding application still needs to manage business rules, user permissions, data access, validation, costs, failures, and the experience around the AI.

Which Workflows Are Good Candidates for Persistent Agents?

Dots will probably be most useful where work is ongoing, information arrives over time, several digital systems are involved, and the desired outcome can be clearly described.

Examples could include reviewing customer feedback and identifying recurring themes, maintaining research on competitors, following engineering migrations, preparing recurring business reports, checking operational dashboards, organizing information before meetings, updating documents as new inputs arrive, and monitoring projects for unresolved work.

The strongest candidates also have clear boundaries. The business should know what the agent is responsible for, which sources it can access, which actions it may perform, which decisions require a person, and what should happen when the agent is uncertain.

Some workflows will still be better served by normal software automation. If a process is completely deterministic, a traditional workflow or API integration may be cheaper, faster, and easier to verify. AI agents become more useful when the work requires interpretation, changing context, unstructured information, or decisions that cannot be completely expressed through fixed rules.

Software Teams Should Start Thinking About Agent-Ready Architecture

Whether Dots themselves become widely adopted or not, the direction behind them is important for software teams.

Future applications may increasingly be operated partially by AI agents. Designing for that future means treating identity, permissions, observability, reversibility, and structured tool access as first-class architecture concerns.

An agent should not receive administrator access simply because it sometimes needs to update a record. Important actions should be logged. Destructive changes should be reversible where possible. Sensitive operations should have stronger approval requirements. Business rules should remain enforceable outside the language model rather than depending entirely on a prompt.

The same principle applies to the application's data. Agents become significantly more useful when information is structured, current, accessible through well-defined interfaces, and connected to clear authorization rules.

In other words, building for AI agents does not reduce the importance of software engineering. It increases the importance of the systems around the model.

Dots Could Change What We Mean by an AI Assistant

The term "AI assistant" has usually described software that waits for instructions and helps a person complete something.

Dots point toward a different relationship. Instead of only asking an assistant for help, users may begin assigning ongoing areas of responsibility to an AI system and checking in when judgment, approval, or strategic direction is required.

That does not mean every employee will soon be replaced by a collection of digital workers. Many important parts of business depend on accountability, relationships, domain expertise, negotiation, creativity, leadership, and decisions where the person making the choice matters.

But a large amount of work exists between those moments. Information needs to be collected. Systems need to be checked. documents need to be updated. Follow-ups need to happen. Changes need to be investigated. Routine progress needs to continue.

Persistent AI agents are increasingly targeting that layer.

Our View: The Bigger Story Is Persistent AI

OpenAI Dots are interesting because they combine several trends that have been developing separately: stronger reasoning models, computer use, connected applications, memory, scheduled work, coding agents, tool calling, and automated safety checks.

Putting those capabilities together produces something meaningfully different from a chatbot.

The important question for businesses is therefore not, "Should we get a Dot?" It is, "Which responsibilities in our business could an AI system continuously support without creating unacceptable risk?"

Once that responsibility is identified, the technical questions become much clearer. What context does the agent need? Which systems should it access? Which decisions can it make? What should require human approval? How will actions be logged? What happens when something goes wrong? And how will the business measure whether the agent is actually creating value?

Those questions will matter whether the underlying agent comes from OpenAI, another AI provider, or a custom product built around a company's own workflows.

The shift has already started. AI first learned to answer. Then it learned to use tools. Now it is starting to hold responsibility between conversations.

That may be the more important part of OpenAI Dots.

Frequently Asked Questions

What are OpenAI Dots?

OpenAI Dots are persistent AI agents powered by GPT-6 Astra. They can continue working between conversations, operate their own cloud computer, use connected applications, run scheduled work, and bring results or decisions back to the user.

How are Dots different from normal ChatGPT?

The biggest difference is persistence. A normal ChatGPT interaction usually begins with a request. A Dot can maintain responsibility for ongoing work, continue tasks after a conversation ends, monitor permitted information, and proactively surface useful updates.

Can OpenAI Dots access my computer?

Each Dot has its own cloud computer. Local computer access is optional and starts disabled. The user has to explicitly connect a computer and grant the required permissions before the Dot can use local files or applications.

Can a Dot send emails or make changes automatically?

Supported actions depend on the user's permissions, Custom Rules, and OpenAI's built-in safeguards. Users can define whether some actions are allowed independently, require prior authorization, need approval at action time, or must be completed manually.

Are OpenAI Dots safe?

OpenAI has added multiple layers including model safeguards, app permissions, Custom Rules, Auto-review, proactive-research restrictions, monitoring, and human approvals. Its published evaluations show encouraging results in several adversarial tests, but OpenAI also acknowledges that Dots can make mistakes. Businesses should therefore treat permissions, auditability, human review, and operational controls as essential parts of any agent deployment.

What should businesses do before adopting persistent AI agents?

Start with one bounded workflow. Define the outcome, required information, permitted tools, approval points, failure conditions, and success metrics. Test the agent using realistic scenarios before expanding its access or responsibilities.

Keep reading

Trusted US-Registered Development Agency✦
5.0 Client Satisfaction on Clutch✦
Recognized Top Rated Plus on Upwork✦
250+ Products Delivered✦
15+ Expert Developers & Designers✦
6+ Years of Development Excellence✦
Serving Clients Across the Globe✦
88% Client Retention Rate✦
Trusted US-Registered Development Agency✦
5.0 Client Satisfaction on Clutch✦
Recognized Top Rated Plus on Upwork✦
250+ Products Delivered✦
15+ Expert Developers & Designers✦
6+ Years of Development Excellence✦
Serving Clients Across the Globe✦
88% Client Retention Rate✦
Logo