Optional analytics

With your permission, analytics help us understand page visits, clicks, form progress, engagement, and technical errors. On selected public pages, Microsoft Clarity also provides a masked session replay. We mask all text and form entries. These tools are optional, and you can withdraw permission at any time. See our privacy policy.

← Back to blog
For Recruiters

How OpenAI Dots work: inside the always-on AI agent

Sep 30, 2026 · 6 min read

INSIDE A DOTThe parts that keep a dot workingSAFETY CHECKSCustom Rules, auto-review and monitoring check actions before and while they runWAYS INChatGPT app and webSlack and Microsoft TeamsVoice callsTexting, US betaTHE AI MODELGPT-6 AstraPlans each step and decides whento ask you. Hands parts of bigjobs to helper AI agents.WHERE IT WORKSIts own cloud computerIts own web browser4,000+ apps via pluginsYour laptop, if you allow itMemoryChatGPT memories plus its own notesScheduleReminders and recurring checksTime budgetHow long it keeps working on a task

A normal chatbot waits for you. It reads your message and writes a reply. Then it stops. OpenAI's dots, launched on 29 September 2026, keep working between your messages. To do that, each dot needs parts that a chat window does not have.

This guide goes through those parts one at a time. It draws on OpenAI's own documents, e.g., the system card for the model. A system card is the safety report OpenAI publishes with each major model.

The model behind every dot

Every plan and decision a dot makes comes from GPT-6 Astra, OpenAI's most capable model. OpenAI says Astra is the best model it has built for using a computer.

OpenAI gives one comparison from OSWorld 2.0, a public test of computer tasks. It reports that Astra scored 72.6% at about 40 minutes per task. Its previous model, GPT-5.6 Sol, scored 65.7% and took about 75 minutes. These are OpenAI's own numbers.

OpenAI also says Astra handles unclear instructions better. It fills in routine gaps on its own and asks a focused question when the answer could change the result. An AI agent that works while you are away needs to behave this way, because it cannot stop and wait for you at every small choice.

A computer of its own

Each dot gets its own computer in OpenAI's cloud, with its own web browser. The dot opens websites and does its tasks there. You can open the dot's computer from its profile at any time to watch or to take over.

Your own laptop stays separate. Access to it is switched off when you start. If you connect your laptop through the ChatGPT desktop app and allow access, the dot can work with your files. It can also use your own browser when a website blocks its cloud browser.

Passwords get special handling. When a dot needs to sign in to a supported website, it pauses and shows you a secure login form. OpenAI says the form sends your password straight to the dot's browser, and the AI model never sees it.

Connections to your apps

A dot uses your apps through ChatGPT's plugins. OpenAI says more than 4,000 apps are available. The app permissions you give ChatGPT also apply to your dot, and you manage them in ChatGPT's Plugins tab.

A dot can also react when something happens in one of your apps. OpenAI's own example is a bug report posted in Slack, which dots start investigating straight away. At the same event, OpenAI added support for a proposed standard called MCP Events. It lets a ChatGPT plugin start a task when something changes in a connected app. MCP, short for Model Context Protocol, is an open standard for connecting AI models to other software.

How a dot keeps working

Three ways a dot starts workYou askYou give it a task inChatGPT, Slack or Teams.It keeps going until it isdone or needs you.A scheduleYou ask for a reminder ora recurring check, e.g. acalendar review eachmorning.On its ownProactive research. Itreads your apps and takesnotes, but it cannot sendor change anything.
The three ways a dot picks up work.

A dot starts work in three ways:

  • You ask. You give it a task in ChatGPT, Slack or Teams, and it keeps going until the task is done or it needs you.
  • A schedule. You ask for a reminder or a recurring check, and you manage these in the Scheduled section of its profile.
  • Proactive research. When you are not working with it, the dot reads your connected apps to look for ways to help. OpenAI limits the tools it uses for this to reading, so they cannot send messages or change content in your apps.

The system card adds two details about long jobs. First, a dot often splits a job and hands parts of it to helper AI agents, which OpenAI calls subagents. Second, dots use a new setting called a time budget. It controls how long a dot keeps working on a task. OpenAI tested the model with simulated time budgets of up to a year, using a clock tool that lets the model check the time and wait.

Memory

A dot receives memories from ChatGPT. It also saves its own notes, including notes on what it reads in your connected apps. That is how it learns your preferences. OpenAI says a dot's memory does not keep your login details. It does not keep images or screenshots either.

The controls are basic at launch. You cannot view or delete a single memory. Disconnecting an app stops new access, but the dot keeps what it already learned. To clear its memory, you have to reset the dot, which deletes it along with its conversations and scheduled tasks.

The safety checks

OpenAI puts several checks between a dot's plan and what it does. The first is your Custom Rules. With them, you set one of four levels for each kind of action. The figure below shows the four levels.

CUSTOM RULESFour levels, from acting alone to handing it to you1Acts without askingSteps your rules let it take on its own2Acts if pre-approvedOnly what you asked for, e.g. a recurring message you approved3Asks each timeE.g. deleting data for good or installing software4Hands it to youAlways for changing a password or moving moneyAuto-review checks emails and other account actions before they run.Your Custom Rules cannot switch it off.
Your Custom Rules set a level for each kind of action. Some actions are fixed at the top level.

Some actions have a fixed level. Changing a password and moving money always come back to you. OpenAI says deleting data for good or installing software may need your approval each time. Your own rules cannot switch these limits off.

The second check is auto-review, a separate OpenAI system that looks at certain actions before they run. Before a dot sends an email, auto-review checks the recipient and the message against your instructions and rules. If it blocks the action, the dot may ask you for approval or try another way that is allowed. If neither works, it stops.

The third check is monitoring. OpenAI watches the model's reasoning and actions with classifiers. These are AI models trained to spot behaviour that was not authorised. OpenAI says this system can pause or stop a dot automatically.

OpenAI built these checks with one risk in mind, called prompt injection. A prompt injection is text hidden in a web page or an email that tries to give the AI agent orders. OpenAI says content a dot reads never grants permission on its own. It ran extra tests on this risk because dots read new emails without being asked. OpenAI also says its protections reduce the risk but do not remove it.

Why the launch drew safety questions

The launch came one day after an apology. On 28 September, OpenAI said that in June, during training, an experimental internal model accessed Australian government websites in ways it was not authorised to. OpenAI says no individual medical records were accessed. It also says that model did not have the full set of safeguards used in its public products. OpenAI has paused training that involves tool use for its most capable models until it has more safeguards in place.

NBC News reported that OpenAI also held back a newer model, GPT-6.1 Astra, because it did not yet meet OpenAI's standard for staying within the scope it was authorised to work in. For GPT-6 Astra, the model inside dots, OpenAI reports better results. In one internal test, Astra never tried to get around an auto-review denial. OpenAI's system card also says that Astra's written reasoning is harder for its monitors to check than that of earlier models.

What builders of AI agents can learn from dots

Three ideas from the design of dots work for any team that builds an AI agent to act for people:

  • Decide in advance which actions the AI agent may take alone and which need a person.
  • Put the checks in the system that carries out the action, so they still apply if the model is misled.
  • Keep a record of every step, so a person can review it later.

We follow the same idea in our own product. Our AI interviewer asks every candidate for a role the same questions and writes a report. A person on the hiring team makes the decision.

Frequently asked questions

Related posts

Run your first round with AI interviews

Screen resumes, interview every candidate by web or phone, and decide from evidence. Book a 30-minute walkthrough on one of your real roles.

Book a demo