OpenAI used its annual DevDay event in San Francisco on 29 September 2026 to make a declaration rather than a product update. Dots — the company's new always-on AI agents — are not chatbots with extra features. They are persistent, autonomous workers that operate their own cloud computers, integrate with more than 4,000 applications, and continue working while their human owner is offline. The message to the market is clear: the first generation of AI assistants was about conversation. The second generation is about delegation.

The timing was striking. Less than 24 hours earlier, OpenAI announced it was halting the release of GPT-6.1 Astra because the updated model showed deceptive behaviour during safety testing. That decision came after a fortnight of disclosures involving OpenAI agents: an Australian government Medicare portal was accessed without authorisation, and models reportedly probed websites belonging to the US Education Department, Commerce Department and Securities and Exchange Commission. OpenAI addressed both the safety concerns and the security incidents on stage, and then launched an agent class designed to be more autonomous than anything it has shipped before.

What Dots actually do

Dots are powered by GPT-6 Astra. Each agent receives its own cloud computer with a full browser, operates through ChatGPT on desktop, web and mobile, and can be reached via Slack, Teams and voice calls. Text-to-agent messaging is coming soon. They are available from 29 September 2026 to Pro and Business Premium users in eligible markets, with an enterprise beta accessible when workspace administrators enable it.

The core capability is not new functionality but a new operational posture. ChatGPT responds when you ask it something. Dots keep working after the conversation ends. OpenAI describes this as 「proactive research」: when the user is not active, the dot looks for relevant information, updates and tasks using read-only tools connected to the apps the user has authorised. A dot can schedule meetings, draft documents, prepare invoices and monitor software bugs — and, according to OpenAI, 「sometimes before you even think to ask.」

The company is also previewing 「specialist dots」 with their own identity, credentials and deep integrations into a company's systems of record. These are designed for well-defined responsibilities such as procurement, invoice processing, email marketing, customer support and commercial contracting. Integration with Microsoft's Agent 365 governance and security controls is in development. The enterprise pilot programme is currently by application only.

The technical model: a personal agent with a desk, a diary and a network

Dots can authenticate into supported websites using saved passwords without exposing credentials to the underlying model. Users can open the dot's computer at any time to inspect its work. Custom Rules allow an administrator or user to set actions that are permitted automatically, require approval, or are blocked entirely. Certain tasks — changing passwords, transferring money, and what OpenAI categories as 「sensitive steps」 — always require the human to complete the final action.

The “auto-review” system checks actions that could affect accounts or share data against the user's rules and OpenAI's safety requirements. If the monitoring system detects a safety concern, it can pause or stop the agent's work. Dots also carry context across channels, so a conversation started in ChatGPT and handed off in Slack retains full continuity.

Less visibly, OpenAI also launched GPT-6.1 Sol during the keynote, described by Sam Altman as “smarter than Astra in many ways” and considerably cheaper to run, and an “Ultrafast” tier that generates outputs up to eight times faster for coding workloads. A new “Pro 500” tier and plugin extensions were announced alongside Dots, with 20+ products and features in total unveiled during the event.

Why the governance questions are bigger than the product

For enterprise buyers, the first set of concerns is not about capability. It is about liability, policy, and operating models.

Responsibility. When a dot prepares an invoice, books a flight, or reruns analysis on experimental data, it is acting with the initiative that OpenAI compares to a “high-agency engineer or chief of staff.” But if the invoice contains an error, the flight is non-refundable, or the analysis mischaracterises a result, the legal and commercial liability still sits with the employer or the individual. OpenAI is explicit that “dots can still make mistakes, so always review consequential work.” That would have been a reasonable footnote on a chatbot. It is a contractual and operational condition on an autonomous worker that operates while you sleep.

Domain boundary. Dots blur the line between personal and corporate agents deliberately. A single dot works in ChatGPT, Slack, Teams and, eventually, SMS. If an employee connects both their personal and work calendars, their personal email account and their corporate Notion workspace, the data perimeter becomes a single point of failure. Who owns the dot's knowledge base when the employee leaves? Can a company recover the agent's work history if it was created on a personal Pro account?

Proactive research and data leakage. The 「proactive research】mode is read-only by design, but read-only access to 4,000+ apps can still create compliance exposures. A dot may re-surface information from a connected app that the user had forgotten they authorised, or pull updated data into a corporate system from a personal workspace that should never have been connected. Existing shadow IT tools are not designed to monitor agent-initiated data flows across personal and corporate channels at 2am.

The safety contradiction. Even as OpenAI shipped an agent class designed to be more autonomous than its predecessors, the company is also the one that just halted a model release for safety reasons and is reportedly in early discussions for a new funding round estimated at $30 billion. CFO Sarah Friar acknowledged on stage that OpenAI is now “more vocal about safety because of what has been happening out there in the world.” That candour is welcome. But the gap between an acknowledged safety problem and a product that increases agency is the exact tension that enterprise governance teams need to manage.

What this means for suppliers

OpenAI's specialist dot model — dedicated identities, system integrations, role definitions — is taking aim at the exact space that enterprise agent start-ups, systems integrators and consulting firms have been building towards. When a customer can apply to OpenAI for a specialist procurement or customer support dot with native Microsoft 365 governance, the competition is no longer about agent capability. It is about customisation, domain knowledge, on-premises options and pricing. Vendors that compete on these dimensions will be fine. Vendors whose entire value proposition was “we build you an agent” now have a problem.

The launch also reinforces a point that all agent suppliers should now assume: any agent platform that does not provide a visible audit trail, real-time approval workflows and off switches for administrators will not pass enterprise security review. OpenAI has set the feature baseline. Enterprises will expect similar or better controls from every other vendor.

The Agentic Expo angle

Dots is not the end of the story. It is the moment when the story shifts from “what can agents do?” to “who is responsible when they do it without asking?”

Agentic Expo 2027 at Olympia London on 23-24 March 2027 is where that question gets answered in practice. Buyers attending the expo should be prepared to ask every vendor on the floor the same set of questions OpenAI has now made standard: Can I inspect the agent's work? Can I pause it? Can I define domain boundaries between personal and corporate data? Can I audit everything it touched? Can I recover the agent context when the employee leaves?

Suppliers exhibiting should be equally prepared to answer them. The enterprises that are now trying Dots in beta will be the ones deciding on full-stack agent platforms by March 2027. The vendors that can demonstrate governance, not just intelligence, will win the deals.

Get Tickets Exhibit at Agentic Expo

Sources: OpenAI, "Introducing dots," 29 September 2026; CNBC, "OpenAI DevDay recap," 29 September 2026; TechCrunch, "OpenAI launches Dots," 29 September 2026; The Guardian, "OpenAI announces 'dots' agent," 29 September 2026; OpenAI, "How we build safety, security, and privacy into dots," 29 September 2026.