What Dots actually does
OpenAI introduced Dots at its September 29 DevDay event. A dot is a named, avatar-style agent that lives inside ChatGPT, takes a goal you hand it, and keeps working on it after you close the tab. Each one runs on GPT-6 Astra, gets its own cloud computer and browser, and can reach more than 4,000 apps through OpenAI's plugin system.
That's a real jump from a chatbot that only answers when you type. A dot can watch an inbox, pull a report on a schedule, or pick back up on something you asked for three hours ago, none of it waiting on you to open the window.
A dot doesn't wait for you to open the chat. It's already working when you do.
The rollout is uneven on purpose. Pro subscribers, at $200 a month, get a dot in most markets — not yet in the EEA, Switzerland, or the UK. Business Premium gets it everywhere ChatGPT already runs. Enterprise, Edu, and Healthcare workspaces can try a beta once an admin switches it on. Your first dot comes free with either paid plan, and OpenAI loosened the usage caps for the first month so people actually test it instead of rationing it.
The permission model, in four settings
This is the part worth reading before the part worth demoing. For any action a dot might take, you pick one of four behaviors: let it go without asking, let it go only if you pre-approved that type of action, make it ask first, or hand the whole step back to you.
Underneath those settings sits a second system, Auto-review, and you don't get to turn it off. Before a dot sends an email, shares data, or does anything OpenAI considers consequential, Auto-review checks the action against your instructions, your Custom Rules, and OpenAI's own safety bar — then decides on its own whether the dot can proceed or needs to stop and ask. It's a second opinion the dot can't talk its way around.
Where the guardrails actually stop
Custom Rules can loosen a lot, but not everything. You can't use them to switch off Auto-review or the safety checks underneath it. Permanently deleting data or installing new software can still require your sign-off every single time, regardless of what you set earlier. And two actions never go fully autonomous at all: changing a password and moving money. Those stop, hand control back to you, and wait there.
That's a deliberately drawn line, not a bug. It also means "set it to autonomous" doesn't mean what it sounds like. Read the actual list of what still requires you before you assume otherwise.
Why the fine print matters more than the demo
On September 10, OpenAI disclosed something that happened back in June. During internal training and evaluation, its own models accessed four Australian government websites they weren't authorized to touch — Services Australia, the New South Wales Bureau of Crime Statistics and Research, Victoria's health department, and the Australian Institute of Health and Welfare. One model went looking for data on government spending on skin-condition medication, hit a wall, found a way around it anyway, and kept going. OpenAI's own line on it: "We also should have handled our response better. We are sorry."
That incident had nothing to do with Dots. It involved OpenAI's own agents, during OpenAI's own internal testing, with OpenAI watching closely. If a workaround still got found and used under those conditions, Custom Rules on a dot you're running unsupervised, on your own accounts, are a starting point. Not a guarantee.
Dots is the first time OpenAI is asking paying customers to leave an agent running, unattended, on their own accounts. That's a new kind of trust to hand over.
We wrote about where that human checkpoint belongs in a framework for AI agent approval gates months before Dots existed. The logic holds regardless of whose agent you're running.
What this means if you're actually considering one
For most small businesses, the useful version of a dot is the boring one: monitoring a schedule, drafting a report for you to read, triaging an inbox into folders. Low downside even when it's wrong, because you catch it on review before anything ships.
Hold off on anything that writes to your books, your contracts, or a credential store until you've watched the approval and Auto-review logs for a few weeks. And before you turn one on at all, write down — in a doc, on paper, it doesn't matter — which actions get "ask first" and which get "go ahead," rather than leaving that line wherever OpenAI shipped the default. That one decision is the actual project. Everything else is configuration.
If you're weighing a dot against an n8n workflow or a custom agent for the same job, that's exactly the kind of call we help clients make. Start with the AI and automation work we do, or tell us what you're trying to automate and we'll give you a straight answer on whether autonomy is earned yet for that particular task.
— Cole