Skip to main content

← All articles

ChatGPT Dots: always-on agents for business

What OpenAI announced on 29 September 2026 with ChatGPT Dots, who gets them, what the Agents API can do and what IT and data protection should clarify before launch.

Sebastian LangSebastian LangOctober 6, 202611 min read
ChatGPT Dots: always-on agents for business

On 29 September 2026, OpenAI presented "dots" at DevDay, agents in ChatGPT that run continuously. ChatGPT Dots are the most visible part of a wave of announcements that also includes the Agents API for building your own agents. For companies, the question is less about whether this is impressive than about who is allowed to switch such an agent on, what it can see and how you keep it under control.

This post summarises what OpenAI's documentation says and separates it from what it does not say. The technical details are based on the OpenAI sources cited, as of 6 October 2026. Our own recommendations and statements about our offering are marked accordingly.

As of 6 October 2026

TL;DR

  • Dots are agents with their own cloud computer: According to OpenAI, a dot keeps working even when your computer is off, and gets in touch with results or decisions you need to make. It runs on GPT-6 Astra.
  • Access is limited: Pro 100, 200 and 500 for users over 18 outside the EEA, the United Kingdom and Switzerland, Business Premium rolling out worldwide, Enterprise (including Edu and Healthcare) worldwide as a beta, off by default and only after admin approval.
  • Governance comes before launch: A register, permission levels, human approval for consequential actions and a decision on connectors should be in place before the first dot runs in your company.

What OpenAI presented on 29 September

On 29 September 2026, OpenAI published the post "Introducing dots". The same day, the "DevDay 2026 Recap" appeared with more than 20 announcements, including GPT-6 Astra, ChatGPT, Codex and APIs (OpenAI News feed). The announcement post was not reachable in our retrieval attempts. The content of this post is therefore based on the documentation at developers.openai.com.

According to OpenAI, a dot is an "always-on agent" that keeps work going across tools and projects. It runs on GPT-6 Astra, lives in the cloud and has its own computer including a browser. It can research, analyse data, prepare documents and build software (OpenAI, Meet dots).

In parallel, OpenAI has extended the Agents API, which companies use to build their own agents. The two belong together: dots are the ready-made product for individuals and teams, the Agents API is the toolkit for your own agents.

Template

AI policy with an agent annex

Request the template

What a dot can and cannot do

The documentation describes the capabilities in fairly specific terms. A few of them in brief:

  • Work between conversations: A dot tracks progress, considers what comes next and can decide for itself when to pause and wake up again. You do not need a fixed schedule for every follow-up. For recurring tasks, you describe the schedule, including time zone and, where applicable, a duration or end date (OpenAI, Tasks and memory).
  • Memory: It uses the conversation, relevant ChatGPT memories and its own saved notes on preferences, decisions and ongoing work. According to OpenAI, these notes are separate from the saved ChatGPT memories (OpenAI, Tasks and memory).
  • Channels: You reach the same dot in ChatGPT, Slack, Teams or by phone call. The admin notes, however, state that access to Microsoft Teams is limited to an invitation-only alpha.
  • Its own computer: The dot works in a cloud browser; you can take control ("Take over") and then hand control back. Some websites block cloud browsers or require additional verification.
  • Your computer: You can connect exactly one personal computer. It must be online with the ChatGPT app open, otherwise the dot cannot use it.
  • Plugins: A dot uses plugins that are installed and enabled for your account, with their existing permissions. Connecting a channel such as Slack does not automatically open your mailbox, other apps or your computer.

The limits matter. According to OpenAI, proactive research, in which a dot searches connected apps for useful next steps, is write-blocked: the tools used for it cannot send messages, change app content or control a browser or computer. Every follow-up action is subject to the same permissions. In addition: creating a draft is not permission to send. And OpenAI itself writes that a dot can make mistakes and that stopping a task does not undo actions already completed (OpenAI, Meet dots, Control your dot).

Who gets dots and what that means for companies in Germany

OpenAI is rolling out dots step by step; even with an eligible plan it can take a while. According to the documentation (as of 6 October 2026):

PlanAccess according to OpenAI
Pro 100, Pro 200, Pro 500For users over 18 outside the European Economic Area, the United Kingdom and Switzerland
Business PremiumRollout worldwide
Enterprise (including Edu and Healthcare)Beta, worldwide, off by default, must be enabled by a workspace admin

Source: OpenAI, Meet dots. The page names no other plans. Free and Plus are not listed there, nor is the Business plan without "Premium". Check for yourselves whether and for whom the feature is enabled in your workspace.

For companies in Germany, this means two things. First: according to the page, Pro access applies only outside the EEA; Germany is in the EEA, so a Pro account is not enough here. Second: for Business Premium and Enterprise, the page names no regional restriction. Whether the feature is available in your workspace is shown in the admin area, not in a press release.

On cost, the page names no separate price for the dot. According to OpenAI, conversations with the dot do not count towards ChatGPT usage limits; tasks the dot starts in Work or Codex count there as usual. In addition there is an allowance for more intensive work with extended limits in the first month after launch. We do not state plan prices here because we could not retrieve OpenAI's pricing page for ChatGPT plans today.

Agents API for your own agents

If you do not want a ready-made dot but your own agent, look at the Agents API. It has been in public beta since 10 September 2026 and gives access to the Codex harness through an API managed by OpenAI. OpenAI takes care of session management, context compaction and recovery; your application supplies tools and chooses the execution environment (OpenAI, API changelog, Agents API Overview).

The key points according to the documentation:

  • Sessions: Durable sessions in which an agent keeps working over several turns. Execution runs in a sandbox hosted by OpenAI or in your own environment.
  • Tools: Custom functions and MCP servers can be connected.
  • Computer use: Since 29 September 2026, agents can work in a browser hosted by OpenAI. The application receives approval requests for websites and takes care of sign-ins. According to the documentation, the browser requires the user's consent before visiting a new website origin, even for public pages (OpenAI, Computer use).
  • Price: Model usage is billed at the model's API prices. For GPT-6 Astra, the model page lists USD 10 per 1 million input tokens and USD 50 per 1 million output tokens (as of 6 October 2026). For prompts with more than 272,000 input tokens, twice the input rate and 1.5 times the output rate apply (OpenAI, GPT-6 Astra). For OpenAI tools used, their standard prices apply; sandboxes hosted by OpenAI are billed at standard container prices.

One paragraph of the documentation is particularly important for data protection: the Agents API currently supports data residency only in the US and does not support Zero Data Retention (ZDR). Your own sandbox does not make the API ZDR-capable (OpenAI, Agents API Overview). In the table on storage and retention, the /v1/agents endpoint is listed as: no use for training, abuse monitoring 30 days, application state until deletion (OpenAI, Your data). Sessions can be deleted. Whether and when EU data residency will come is not stated there.

What IT and data protection should clarify beforehand

The biggest difference from a chatbot: a dot can work over a longer period with approved access to accounts, even while you are not watching. That calls for rules before the first person switches it on. The following points are our recommendation (Sentient recommends), not a requirement from OpenAI or from any law.

1. Agent register. Every agent that works with company data or company systems should be in a register before its first use: name, purpose, responsible person, connected data and systems. This applies to dots just as to agents someone builds themselves via the Agents API.

2. Permission levels. Define what an agent may do on its own. Reading and drafts are something different from deleting, sending externally, triggering payments or making legally binding declarations. For the levels with external effect, a human should confirm in every individual case. OpenAI offers custom rules for this with four options: act without asking, act when you say so, ask before acting, or hand over to you. According to OpenAI, these rules are instructions the dot tries to follow, not enforced access controls, and they do not override built-in safety requirements (OpenAI, Control your dot).

3. Connectors and plugins. Decide deliberately which apps a dot may use. In Enterprise, admins control app access and permitted actions via plugin controls. The admin documentation names permissions for using dots, for Slack, for local computer access and for custom rules. A note on model controls: according to OpenAI, Enterprise model controls and presets do not apply to dots (OpenAI, Manage dots permissions).

4. Human oversight and logs. Define who reviews a dot's activity and how often. Members see running tasks in the activity view; according to OpenAI, admins can use supported Compliance API entries to trace messages and responses. OpenAI recommends checking the coverage of the entries before you rely on them in an audit.

5. Memory and data. A dot can create saved memories, including with information from connected apps. Disconnecting an app does not delete information already received. Clarify how sensitive data and departing staff are handled. Contracts, processing by a processor and the data protection impact assessment are something you settle with your data protection officer.

6. Prompt injection. A dot reads content from emails, websites and documents. Such content can contain instructions the agent should not follow. OpenAI describes built-in safeguards against malicious instructions that can pause or stop work. Our AI policy template assumes that prompt injection cannot currently be ruled out completely. That is why consequential actions require human approval.

For the first four points there is a practical template: our free AI policy template contains, in Annex A, an agent register (A1), permission levels 1 to 6, where levels 4 to 6 (deleting, sending externally, payments and legally binding declarations) run only with human confirmation in each individual case (A2), rules for connectors and MCP servers (A3), human oversight (A4), logging and spot checks (A5) and a section on prompt injection (A7). How much autonomy an agent should get is described in Human-in-the-loop. How OpenAI compares with Microsoft, Anthropic and Google is covered in the platform comparison for agents, and we explain the policy with an agent annex in AI policy for companies. The template is not legal advice.

If you start small, take a single agent with the lowest permission level that is sufficient for its purpose and enter it in the register. Prefer to talk directly? Book a 30-minute call.

FAQ

What are ChatGPT Dots?

According to OpenAI, dots are always-on agents in ChatGPT. They run on GPT-6 Astra in the cloud, have their own computer and browser and keep working even when your device is off. They get in touch with results or decisions you are meant to make.

Are ChatGPT Dots available in Germany?

That depends on the plan. According to OpenAI (as of 6 October 2026), Pro access applies to users outside the EEA, the United Kingdom and Switzerland, so not to Germany. Business Premium is rolling out worldwide. Enterprise (including Edu and Healthcare) is a beta, off by default and needs approval from a workspace admin. Check availability for your workspace.

How much do ChatGPT Dots cost?

The documentation names no separate price for the dot. According to OpenAI, conversations with the dot do not count towards ChatGPT usage limits, but tasks in Work or Codex do. This article does not list plan prices; OpenAI's pricing page is authoritative. For the Agents API, the model's token prices apply, for example USD 10 (input) and USD 50 (output) per 1 million tokens for GPT-6 Astra, as of 6 October 2026.

What is the OpenAI Agents API?

An API through which you can build agents on the Codex harness. OpenAI manages sessions, context and recovery; you bring tools and MCP servers and choose the environment. It has been in public beta since 10 September 2026.

Are always-on agents GDPR-compliant?

That cannot be said across the board, and neither OpenAI nor we certify it. It depends on your data, contracts, settings and purposes. For the Agents API, OpenAI currently names data residency only in the US and no Zero Data Retention. Clarify processing by a processor, data types and risks beforehand with your data protection officer.

How do I keep control over AI agents?

With an agent register, tiered permissions, human approval for consequential actions and regular spot checks. For dots, the activity view, custom rules, pause and ending individual tasks and schedules help. Note: pause only stops the current main task; you end delegated tasks and schedules separately.

Sources

Template

AI policy with an agent annex

An editable Word template for approvals, data classes, roles, AI literacy and AI agents. Free by email.

Sebastian Lang

About the author

Sebastian Lang

Co-Founder · Business & Content Lead

Co-Founder of Sentient Dynamics. 15+ years of business strategy (incl. SAP), MBA. Writes about EU AI Act compliance, ROI measurement and how Mittelstand CTOs actually adopt agentic AI.

Keep reading

Once a month. Only substance.

No motivational fluff. No tool lists. Only what CTOs, COOs and MDs in DACH really need to know about AI adoption.