jsonscraper

OpenAI Introduces dots — ChatGPT Agents for Long-Running Tasks

OpenAI introduced dots, ChatGPT agents for long-running background tasks with access to apps and their own memory. We look at how to manage their permissions and data, and what the company’s published safety tests show.

Asking an assistant to check your calendar every morning and keep an eye on project emails is no longer just a question for a chatbot. OpenAI introduced dots, agents within ChatGPT that can be assigned long-running tasks: they can continue working between messages, access connected apps, and come back to the user for a decision.

The announcement came on Tuesday, September 29, 2026, at DevDay in San Francisco. The main change is not a new way to get an answer, but the ability to delegate work over time. That makes boundaries around access more important: what the agent reads and remembers, what actions it takes on its own, and how to delete information it has already obtained. OpenAI lists the DevDay date, and the Associated Press reports that the conference took place in San Francisco on September 29.

What dots can do

Man holding a mouse and iPhone while using a MacBook Pro
Zan Lazarevic

The user gives a dot a goal and sets what it is allowed to do. According to OpenAI’s description, an agent can research a topic in the background, review connected information, set reminders, and run regular checks. Active and scheduled tasks can be reviewed and paused. The system runs on GPT-6 Astra; each dot has its own cloud computer and browser. Details are available in OpenAI’s dots help guide and the GPT-6 Astra system card.

These documents describe the stated features, but they do not, by themselves, show how reliably an agent handles them in everyday use. Access is rolling out gradually, so even an eligible plan does not mean dots are already available in an account.

Availability depends on both the plan and the region. According to OpenAI’s help guide, Pro users are gradually getting dots in supported markets, excluding the European Economic Area, Switzerland, and the United Kingdom. Business Premium includes the feature in all supported regions; Enterprise teams can enable the beta through an administrator, and it is turned off by default. OpenAI does not explain the reason for the regional exclusions.

During the first month, dots usage does not count toward the limits of eligible Pro, Business, and Enterprise plans. The company says it will share details about what happens afterward later. This is a temporary condition, not a promise of permanently free or unlimited access.

The novelty is in the long-running task

OpenAI does not claim that the idea of persistent agents or multi-agent systems is new. In its system card, the company notes that dots build on existing model and agent capabilities. One distinguishing detail is a configurable time budget that determines how long an agent works on a task. The document also says a dot can use tools and delegate some work to subagents.

For users, this means a shift from the familiar scenario. In a typical conversation, an assistant responds to a request, and then the person decides what to do next. With a dot, you need to set a longer-term goal and its boundaries: which sources it can read, what it can do on its own, and when it should stop and ask. The longer an agent works and the more the context changes, the more important it is that it does not lose sight of the original task.

At DevDay, dots were introduced alongside other personal AI agents. AP described the product as a competitor to Meta Muse. The arrival of another player in this category does not, by itself, prove that OpenAI has created fundamentally new technology. The more important question is whether the company can make long-running tasks understandable and manageable for ordinary users.

Control means permissions, memory, and data deletion

My desk
Nikita Kachanovsky

Each dot has a cloud computer. Access to the user’s local computer is off by default: it can be enabled through the desktop app so the agent can work with files, and revoked later. For some actions, users can set rules: allow them without asking again, require prior approval, tell the agent to ask, or hand the task off to a person. OpenAI warns that a dot can make mistakes, including when following these rules.

Connected apps give the agent access to information it can proactively review and use to form memories, even if the user has not sent a new request. That means disconnecting a source and deleting data already obtained are two different operations. According to OpenAI’s help guide, disconnecting an app does not delete information the dot has already obtained. To delete an agent’s saved memories, you need to delete the dot itself; resetting it also deletes its conversations and scheduled tasks.

If a dot is connected to work email or other sources, it is important to understand not only which permissions were granted, but also what the agent has processed and saved. The convenience of background work depends on how clearly users can see the agent’s activity, pause it, and manage its saved context.

What the safety tests show

Programming
Jefferson Santos

OpenAI published its own dots test results in the GPT-6 Astra system card. One test used 100 scenarios involving 500 simulated emails each—50,000 emails in total, of which 16,600 were adversarial. The company reports that no successful attacks were recorded in these scenarios. In another test, consisting of 100 attack chains, no successful cases were recorded among 2,638 valid attempts. These are results from specific OpenAI tests, not an assessment of every possible threat in real-world email environments.

In another test, the agent had to respect permission boundaries across a sequence of related tasks. When the number of intermediate tasks increased from five to ten, the share of runs with recorded moderate-severity violations rose from 8.6% to 19.7%. OpenAI describes these violations as going beyond the task’s scope without signs of severe consequences—for example, transferring information between unrelated tasks or editing a shared document. The company found no high-severity violations or data exfiltration in this test.

The figures should not be interpreted as the rate of errors users will experience: they are OpenAI’s assessment under specified test conditions. The company also notes that some of its evaluations assess model behavior without the full set of production safeguards. As a result, recording no successful attacks in individual tests does not guarantee that an agent will respect permissions flawlessly in every situation. And the increase in recorded violations in the longer task sequence highlights why long-term memory and changing context need to be tested separately.

What to check before using dots

Before assigning a dot regular work, it is worth checking which apps are connected, what permissions they grant, and which actions the agent can take without seeking approval again. OpenAI’s help guide explains how to review active and scheduled tasks, change approval rules, and pause an agent. The apps and features available may vary.

OpenAI says a dot can be connected to Slack and personal email. However, the existence of an integration alone does not answer how much data the agent will process or what it will save in memory. A separate limited beta for text messaging is available to some Pro users in the United States. It uses a third-party provider, and standard charges may apply for messages and data transmission.

The value of dots lies in moving from individual requests to delegating a process. OpenAI has described background tasks, memory, and approval rules, but availability still varies, conditions after the first month are unknown, and the published safety tests are the company’s own assessments. So what matters is not only what a dot can do, but also how clearly it shows what it has read, remembered, and done.

Related

Turn what you read into a working integration

Explore jsonscraper's social-data APIs, test requests and build your next workflow.

Explore APIs