OpenAI used its September 29, 2026 developer conference to introduce dots, a new class of always-on agents built into ChatGPT that OpenAI describes as “remarkably capable, always-on agents built to handle everything.” Each dot runs on its own dedicated cloud computer, keeps working after a user closes the app, and can reach into more than 4,000 connected apps through ChatGPT. The launch puts OpenAI on a collision course with Meta’s Muse, the personal AI agent Meta shipped three weeks earlier, and reopens a question the industry has not settled: how much autonomy should a consumer AI product actually get.
The headline feature is not the task list or the connected-app count. It is the access model wrapped around them. OpenAI is rolling out dots with a smaller footprint than usual for a flagship launch, cutting out the UK, the European Economic Area, and Switzerland from the initial Pro tier, and gating enterprise access behind a workspace administrator’s approval. That rollout shape says as much about how OpenAI is managing risk as the product itself does, and it is the angle worth tracking closely if you run IT, security, or compliance for an organization weighing whether to let an agent act on its behalf.
What OpenAI Announced at DevDay 2026
Sam Altman, OpenAI’s CEO, launched dots on stage at DevDay, positioning the product as a step beyond chat-based assistance. OpenAI’s own framing, that dots “are an extension of you,” signals the company wants users to treat a dot less like a chatbot session and more like a standing delegate that keeps a task moving between conversations. According to OpenAI’s Help Center, a dot is defined as an “always-on agent in ChatGPT” that can take ongoing responsibility for a job and continue making progress without a person actively driving it.
That is a meaningful shift from how ChatGPT has worked since its 2022 debut. Every prior agent-style feature, including Operator and the ChatGPT agent mode that preceded it, ran inside a session a user actively supervised. dots are built to run without that supervision loop, which is exactly why OpenAI spent as much stage time on guardrails as it did on capability. 9to5Google reported that OpenAI framed dots as agents you can assign tasks to and walk away from, a description that lines up with the persistent, cloud-resident architecture OpenAI detailed at the event.
What Exactly Is a dot?
Strip away the branding and a dot is an agent instance with three defining traits. First, it has its own cloud computer, separate from the device running ChatGPT, so it keeps executing even after a phone or laptop goes to sleep. Second, it can operate across OpenAI’s expanded app ecosystem, which the company now puts at more than 4,000 connected apps reachable through ChatGPT. Third, it is scoped by a permission system OpenAI calls boundaries, which a user configures before letting the dot run unsupervised.
MarkTechPost’s write-up of the launch described dots as agents that “work from their own cloud computers,” a phrase that captures the architectural bet OpenAI is making. Rather than treating the agent as a feature bolted onto a chat window, OpenAI has given each dot compute and state that persist independently, closer to a lightweight virtual employee than a smarter autocomplete.
The Engine Underneath: GPT-6 Astra and a Dedicated Cloud Computer
dots run on GPT-6 Astra, the reasoning model OpenAI has been positioning as its agentic workhorse throughout 2026. Astra already anchors other OpenAI agent efforts this year, including the cyber-focused model track the company has been building toward, so routing dots through the same model keeps OpenAI’s agent stack on one foundation rather than fragmenting across model versions.
Pairing Astra with a dedicated cloud computer per dot is the part worth sitting with. It means a dot is not just calling a model API when prompted, it is running a persistent execution environment that can hold files, session state, and in-progress work across app connections for as long as a task takes. OpenAI has not published pricing details for that compute allocation. According to OpenAI’s own guidance, dots usage will not count against Pro, Business, or Enterprise plan allowances for the first month after launch, after which the company says it will share separate usage terms. That is a soft-launch pricing pattern OpenAI has used before to gather usage data before committing to a metered model.
Boundaries: Teaching an Autonomous Agent Where to Stop
The feature OpenAI leaned on hardest in its own messaging is boundaries, the control layer that lets a user define three things: what a dot may do entirely on its own, what it must pause and ask permission for, and what it should never attempt regardless of instructions. OpenTools’ coverage of the launch called the control boundary the most important feature of the release, framing it as the mechanism that makes an always-on agent workable rather than reckless.
That framing matters because it is an admission, implicit but clear, that persistent agents with app access carry real risk if left unscoped. A dot connected to email, calendars, and file storage that acts without any checkpoint is a very different threat model than a chatbot answering questions in a single session. Boundaries exist to keep a dot from, say, sending a message or making a purchase a user never approved, and OpenAI is betting that a configurable permission layer is enough to make that risk acceptable to regulators and enterprise buyers alike.
Who Gets Access First, and Who Has to Wait
dots are rolling out inside ChatGPT on web, mobile, and desktop to Pro, Business Premium, and Enterprise users in eligible markets, according to OpenAI. But eligibility is not universal on day one. OpenAI’s Help Center specifies that the initial Pro rollout excludes the European Economic Area, Switzerland, and the United Kingdom, three of the most heavily regulated digital markets in the world for AI products. Business Premium access is available across supported ChatGPT regions, which is a broader footprint than the Pro tier gets at launch.
The exclusion is notable less for its size and more for its pattern. The EU’s AI Act and the UK’s evolving AI governance regime both place extra scrutiny on systems that act autonomously on a user’s behalf, particularly when they touch financial transactions, personal data, or third-party accounts. Holding back the individual Pro tier from those markets while still enabling Business Premium there suggests OpenAI is treating consumer-facing autonomous access as the higher-risk deployment, even though the underlying agent technology is identical.
The Enterprise Beta Comes With a Catch
Enterprise access to dots is live only as a beta, and it does not turn on by default. A workspace administrator has to explicitly enable it for their organization before any employee can use it. That is a deliberate friction point, and it puts the decision to adopt always-on agents in the hands of the people who own an org’s data governance, not individual employees experimenting with a new ChatGPT feature.
For security teams, that admin-gated rollout is the detail to plan around before dots shows up in a Slack thread asking to be turned on. An agent with its own cloud compute and access to 4,000-plus connected apps is a new category of identity in an environment, one that needs the same access reviews, logging, and offboarding discipline as a service account, not the light-touch treatment given to a chat interface. Organizations that already track connected-app risk from features like ChatGPT Voice’s recent email and calendar access rollout have a head start on the questions dots will raise.
dots vs Muse: Availability and Access at a Glance
The two products are not identical in scope, but the table below lines up what is confirmed about each one’s access model as of this week.
| Attribute | OpenAI dots | Meta Muse |
|---|---|---|
| Announcement date | September 29, 2026 (DevDay) | September 8, 2026 |
| Underlying model | GPT-6 Astra | Not disclosed by Meta |
| Platforms | ChatGPT web, mobile, desktop | iOS, Android, muse.ai, Mac, WhatsApp |
| Geographic availability | Excludes EEA, Switzerland, UK for Pro tier at launch | United States and Canada |
| Access tiers | Pro, Business Premium, Enterprise (beta, admin-enabled) | Consumer app, business connectors added Sept. 29 |
| App connectivity | 4,000+ apps via ChatGPT | Connectors including Slack, Notion, Shopify, Stripe, Gmail |
| Control model | Boundaries: auto-allowed, ask-first, never-do | Connector-level permissions per app |
The most striking gap is geographic. Meta shipped Muse into two countries and is already layering on business features. OpenAI shipped dots into a much larger footprint of markets but pulled back three of the biggest ones for its consumer tier, an inversion of the usual “US first, rest of world later” pattern that says more about regulatory caution than technical readiness.
Meta’s Head Start: Muse Since September 8
Meta introduced Muse on September 8, 2026, describing it as a personal AI agent that can answer questions, complete tasks, browse the web, make purchases, generate images, and create documents, connecting to outside apps and services through a system Meta calls Connectors. Muse launched in the United States on iOS, Android, and muse.ai, with Meta saying availability for AI glasses was planned for later. Muse’s download numbers gave Meta an early lead in the race to put an agent in front of consumers, and OpenAI’s dots launch three weeks later is a direct response to that momentum.
Ai.meta.com, Meta’s own hub for the product, lists the connector categories Muse supports, spanning productivity tools, health and fitness trackers, and shopping and payments. That breadth is part of why Muse’s launch drew scrutiny fast. Giving a consumer AI agent the ability to browse, purchase, and touch personal accounts is precisely the capability set that regulators and competitors alike have flagged as needing tighter controls, and it is the same tension now shaping how OpenAI is staging the dots rollout.
Muse for Small Business Lands the Same Day
Meta did not sit still while OpenAI prepared its DevDay keynote. On September 29, 2026, the same day dots launched, Meta announced Muse for Small Business, a package of new business skills and connectors for the agent. Unite.AI reported the new connector list includes Asana, Box, Canva, Dropbox, Figma, Granola, HighLevel, Intuit QuickBooks, Klaviyo, Lovable, Notion, Shopify, Slack, Stripe, and Zoom, on top of access to a user’s Facebook and Instagram business accounts. That is layered on top of Muse’s original connector set at launch, which included Gmail, Google Calendar, Outlook, Plaid, OpenTable, Google Docs, Spotify, and several health and fitness apps.
Put together, Muse now reaches more than two dozen named third-party services, spanning payments, scheduling, and communications. Meta says the full connector list lives inside the Muse app’s settings and that the company is still adding partners, with an application process open at muse.ai/platform. Shipping that expansion on the exact day OpenAI unveiled dots is unlikely to be a coincidence, and it puts pressure back on OpenAI to show its own connector ecosystem, quoted at 4,000-plus apps, translates into comparable business utility rather than just raw count.
Timeline: The Agent Launch Race of 2026
| Date | Event |
|---|---|
| September 8, 2026 | Meta launches Muse on iOS, Android, and muse.ai in the US |
| September 17, 2026 | Muse becomes available on Mac |
| September 29, 2026 | Meta announces Muse for Small Business with 15 new connectors |
| September 29, 2026 | OpenAI launches dots at DevDay, powered by GPT-6 Astra |
| September 29, 2026 | OpenAI opens Enterprise dots beta, admin-enabled only |
Three weeks separate Meta’s launch from OpenAI’s response, and both companies chose the same day, September 29, to push their next expansion. That kind of scheduling collision rarely happens by accident in a two-horse product race, and it signals both companies are watching each other’s release calendars closely rather than shipping on independent timelines.
Why This Matters for Security and IT Teams
An always-on agent with its own cloud compute and thousands of app connections is not a feature to greenlight with a single click. It is a new kind of identity that touches data, and it needs the same lifecycle discipline organizations already apply to service accounts and API keys: provisioning, scoped permissions, logging, and a clear offboarding path when an employee leaves or a project ends.
The admin-gated Enterprise beta OpenAI shipped is a reasonable starting posture, but it puts the burden on IT and security leads to actually build a review process before flipping the switch, not after. Questions worth answering before enabling dots for any workspace: which connected apps will a dot be allowed to touch, what boundary settings are mandatory versus user-configurable, and who audits the “ask first” and “never do” lists an employee sets for their own agent. None of that tooling is optional once an agent can act inside Slack, email, and file storage without a human watching every step.
The Track Record Agents Are Building, Good and Bad
OpenAI is not launching dots into a vacuum of agent security history. This site has tracked a string of incidents this year that shape how cautiously both companies are now moving. SalesBleed exposed three flaws that could hijack Salesforce’s Agentforce agents, and separately, researchers found AI agents being abused to harvest 600,000 payment cards for roughly $25 per targeted company. Those incidents did not involve dots or Muse directly, but they establish the threat pattern regulators and enterprise buyers are now pricing into every always-on agent launch: an agent with broad app access is a broad attack surface if its permission model has a gap.
That history is also why Amazon’s decision to restrict Meta’s agent inside its own ecosystem is worth watching as a leading indicator. Amazon blocked Muse from operating freely on its platform over stated concerns, a sign that even large platform owners are not ready to grant unrestricted agent access without their own review. OpenAI’s boundary system and staged rollout look, in part, like an attempt to get ahead of that same kind of pushback before it happens to dots.
Historical Context: From Autocomplete to Autonomy
ChatGPT launched in November 2022 as a single-turn conversational tool. Plugins arrived in 2023, giving the model limited reach into outside services. Operator followed in early 2025 as OpenAI’s first attempt at a browser-driving agent, still tethered to an active user session. Each step added capability while keeping a human in the loop for every action. dots is the first OpenAI product to remove that loop by design, letting a task keep running after the app is closed.
That progression mirrors a broader industry shift in 2026 from models that answer questions to models that finish jobs. Google, Microsoft, and Salesforce have all shipped agent products this year built around the same premise: hand off a multi-step task and let the system execute it with minimal supervision. What separates this current wave from earlier chatbot-plus-plugin efforts is persistence. A dot, like Muse, is meant to keep working across hours or days, not just for the length of a single chat session, which is exactly why the permission and boundary layer has become the centerpiece of both launches rather than an afterthought.
Market Impact and the Field Beyond OpenAI and Meta
OpenAI and Meta are the two companies drawing the most attention in the personal-agent category right now, but they are not alone. Google, Amazon, and Salesforce have all built or acquired agent products aimed at similar territory, from task automation to app-connected assistants, and each is wrestling with the same access-control tradeoffs OpenAI is navigating with boundaries. Pulse2 reported that OpenAI used the same DevDay keynote to introduce GPT-6.1 Sol and a $500-per-month Pro tier alongside new enterprise AI tools, underscoring that dots is one piece of a broader push to own both the consumer and enterprise ends of the agent market at once.
For OpenAI, dots is also a defensive move. Meta’s Muse arrived first and has already expanded into small-business territory, giving Meta a claim on the workflow-automation use case that enterprise software vendors have been circling all year. If dots can match that utility while offering finer-grained permission controls, OpenAI has an opening to win over the security-conscious enterprise buyers who were always going to be more cautious about handing an agent unrestricted app access.
What Happens Next: Five Predictions
- OpenAI will extend Pro-tier dots access to the UK and EEA once it finalizes compliance documentation for the AI Act and UK AI governance rules, likely within one to two quarters rather than immediately.
- Usage-based pricing for dots will arrive once the current free-allowance window ends, and it will be metered separately from standard ChatGPT usage given the dedicated cloud compute each dot consumes.
- Expect at least one high-profile security disclosure involving either dots or Muse boundary and connector permissions within the next six months, following the pattern set by SalesBleed and other 2026 agent incidents.
- More platform owners will follow Amazon’s lead and impose their own restrictions on third-party agents operating inside their ecosystems, treating agent access as a negotiated integration rather than an open API.
- Enterprise adoption of dots will lag consumer hype, since the admin-gated beta means most organizations will pilot it in limited departments before granting broad access, mirroring how enterprises rolled out early generative AI tools in 2023 and 2024.
Frequently Asked Questions
What is OpenAI dots?
dots is OpenAI’s new always-on agent feature inside ChatGPT, launched September 29, 2026. Each dot runs on its own cloud computer, is powered by GPT-6 Astra, and can act across more than 4,000 connected apps within limits a user sets through OpenAI’s boundaries system.
Is OpenAI dots available in the UK and EU?
Not yet for the Pro tier. OpenAI’s Help Center states that the initial Pro rollout excludes the European Economic Area, Switzerland, and the United Kingdom. Business Premium access is available across supported ChatGPT regions.
How is dots different from Meta’s Muse?
Both are persistent personal AI agents, but they differ in scope. dots runs inside ChatGPT and connects to over 4,000 apps with a granular boundaries permission system. Muse runs as a standalone app on iOS, Android, and muse.ai, using Meta’s Connectors system, and is currently limited to the United States and Canada.
What plans can access dots?
OpenAI says dots are rolling out to Pro, Business Premium, and Enterprise users in eligible markets. Enterprise access is a beta that a workspace administrator must explicitly enable; it is not on by default.
Will dots cost extra to use?
OpenAI has said dots usage will not count against Pro, Business, or Enterprise plan allowances for the first month after launch. The company has not yet published separate usage terms for after that period.
What model powers dots?
dots run on GPT-6 Astra, the same reasoning model OpenAI has used to anchor its broader 2026 agent push.
What are boundaries in OpenAI dots?
Boundaries are the permission settings a user configures for a dot, covering what it can do automatically, what requires asking first, and what it should never do. OpenAI and outlets covering the launch have described the boundary system as the core safety mechanism that makes an always-on agent usable.
Should businesses enable dots for their employees right away?
Security teams should treat dots like any new identity with app access: review which connectors employees can enable, set organization-wide boundary defaults where possible, and log agent activity before opening the Enterprise beta broadly rather than after.




