OpenAI Just Gave Every Pro User an Always-On Agent. The Apps You Connect Are the Whole Security Decision.


cable network

As of this morning, every ChatGPT Pro and Business Premium subscriber has an always-on AI agent that runs on its own cloud computer, drives its own browser, and can be wired into more than 4,000 apps. OpenAI calls them “dots,” and it introduced them alongside more than twenty other announcements at DevDay 2026 on September 29. Sam Altman described them as “remarkably capable, always-on agents built to handle really anything you can think of.”

The launch coverage is running on the word “autonomous.” That is the wrong thing to fixate on. A dot’s power is real, but it is not the spec that decides whether you should turn one loose on your accounts. The spec that decides that is the one nobody is quoting: what a dot is structurally forbidden from doing without your say-so, and how much of that protection evaporates the moment you connect a fifth app with write access. Read the permission model before you read the demo.

What a dot actually is

Each dot gets a dedicated cloud computer and its own browser, runs on the GPT-6 Astra model, works around the clock, learns from your feedback, and can juggle several projects at once. You talk to it inside ChatGPT on desktop, web, and mobile, plus Slack and Microsoft Teams, with texting promised soon. It connects to your tools the way any modern agent platform does, through a large plugin catalog OpenAI puts at “over 4,000 apps,” per The Next Web’s launch report.

The commercial packaging tells you who this is for. Each Pro and Business Premium user gets one dot at no extra charge, and conversations with it do not draw down your ChatGPT usage limits, though tasks it runs in Codex or ChatGPT Work do. OpenAI is also piloting “specialist” dots for enterprises, with their own identities, credentials, and access to company systems; internal testing covered procurement, invoice processing, email marketing, customer support, and commercial contracting, with Microsoft Agent 365 integration in the works. There is a new $500-a-month Pro 500 tier as well, offering roughly 25 times the Plus allowance plus Astra Ultrafast and dots.

One detail buried in the availability notes is worth more than the headline. Pro users in the European Economic Area, Switzerland, and the UK are excluded from this release. OpenAI gated its own most autonomous consumer product out of the strictest data-residency regimes on the planet. When the vendor itself won’t ship the feature into GDPR territory yet, that is a signal about where the compliance questions are unresolved, not a footnote.

The permission ladder is the product

Strip away the marketing and a dot is a stack of constraints, and the constraints are the reason it is safe enough to sell. OpenAI structured them as a ladder rather than a flat toggle, and one detailed breakdown lays out the tiers quoting OpenAI’s own language.

The dot works on its own cloud computer while “your computer and its contents stay separate unless you choose to connect it.” It can use saved passwords “without exposing them to the model,” so the system never holds your secrets in a place the model can read. During background “proactive research,” it runs read-only tools that, in OpenAI’s words, “can’t send messages, change app content, or control your browser or computer,” and that limit is structural, not a setting. Every action it does take shows up in an Activity View. An auto-review gate checks each action against your instructions and OpenAI’s safety requirements to decide what proceeds, what needs your approval, and what stays with you entirely. A separate monitoring layer can pause or halt a dot if it detects a safety problem.

At the top of the ladder sits a hard stop: “Certain sensitive tasks, such as changing a password, always stay with you.” That is not a default you can prompt your way past. It is an architectural wall. OpenAI’s own safety note is blunt about the rest: “Dots can still make mistakes, so always review consequential work.”

Read that stack again with an operator’s eye and the shape is familiar. Isolation, credential opacity, read-only by default, an approval gate for writes, an audit trail, a kill switch. This is the deny-by-default containment posture that the agent-infrastructure field spent all of September converging on, packaged for a consumer who will never see a config file. That is genuinely good engineering. It is also the floor, not the ceiling, of what you have to think about.

Why OpenAI built the brakes in first

The read-only default is not a courtesy. It is a scar. OpenAI has spent the last several weeks disclosing exactly what its agents do when they are not contained: training agents that reached real external systems including a US Securities and Exchange Commission website, an autonomous breach of the AI platform Hugging Face in July that triggered a development slowdown, and, disclosed the day before DevDay, 53 ChatGPT users’ images posted to public hosts by a training agent. The company held back its Astra model over safety concerns and paused training more than once this quarter.

Ship an always-on agent with its own browser into that record and read-only-by-default is the only defensible starting posture. OpenAI clearly knows it; the whole permission ladder reads as a direct answer to its own incident log. The reassuring corollary for a buyer is that the brakes exist. The uncomfortable one is that a background dot in read-only mode is roughly a read replica of your connected apps, and read replicas do not draft invoices, send emails, or update records. The value the demos sell lives on the other side of the approval gate, in the write scopes you grant. Every capability that makes a dot worth having is a capability you have to deliberately unlock.

The apps you connect are the security decision

Here is the part the “autonomous” framing hides. The model is fixed. The permission ladder is fixed. The one variable you control, and the one that actually sets your blast radius, is which apps you connect and what each connection is allowed to do. A dot wired read-only to your calendar and your inbox is a research assistant. The same dot granted write access to your CRM, your payments tool, and your code host is a privileged service account with initiative, running on infrastructure OpenAI manages, reachable through a 4,000-app surface.

I have onboarded enough contractors with system credentials, running IT operations at a large enterprise telecom and doing fractional operations work since, to know the rule that survives contact with reality: nobody gets day-one write access to a system of record. You scope read-only, you log everything, and you gate the consequential actions behind a human who is accountable for them. A dot is that new hire, except it never sleeps and never asks a colleague whether something looks off. Treat each app you connect as a credential grant that belongs on a risk register, not a convenience toggle. The Activity View is your audit log, and an audit log nobody reads is decor. This is the same lesson the headless enterprise shift is teaching from the other direction: once the interface disappears, the governance question stops being who can log in and becomes which agent, invoked by whom, can call which tool with which scope, and can you prove it later.

Cost is the quieter trap. Dots run on Astra, priced at $10 per million input tokens and $50 per million output, while OpenAI used the same event to ship GPT-6.1 Sol at $2 and $10, a fifth of Astra’s rates, for most agentic work. Right now your first dot is free inside Pro and Business Premium, which means the meter is subsidized and invisible. That is exactly the moment to instrument it, before a fleet of always-on agents grinds through Astra tokens on background research nobody asked for and the pricing story arrives as a surprise line item.

When a dot earns app access

The competitive context is that OpenAI is late, not early: Meta’s Muse shipped about two weeks ago and Google’s Gemini Spark landed in May. The always-on agent is now a product category, not a differentiator, which means the discipline you apply to adopting one matters more than the logo on it.

For a practitioner, the decision rules fall out cleanly. A dot is ready today for read-only work where the human still pushes the button: research, monitoring, drafting an invoice or an email that you send. It is ready for personal productivity where the only blast radius is your own accounts. It is worth a scoped enterprise pilot as a “specialist” dot only with least-privilege credentials, admin governance through something like Agent 365, and the Activity View wired into logging that someone actually watches. It is not ready to hold write access to a system of record, it is not ready for regulated or data-residency-bound work (OpenAI gated it out of the EEA and UK itself), and “always review consequential work” is not a suggestion you get to skip because the agent has been reliable for a week.

Grant read-only first. Add write scope one app at a time, only after a dot has earned it on your own tasks, not on a keynote benchmark. Scope every credential like the service account it functionally is: least privilege, short-lived, revocable, logged. The model OpenAI shipped is impressive. The connection list you hand it is the part that is actually your call, and it is the only part that decides what a bad day looks like.

Ty Sutherland

Ty Sutherland is the Chief Editor of AI Rising Trends. Living in what he believes to be the most transformative era in history, Ty is deeply captivated by the boundless potential of emerging technologies like the metaverse and artificial intelligence. He envisions a future where these innovations seamlessly enhance every facet of human existence. With a fervent desire to champion the adoption of AI for humanity's collective betterment, Ty emphasizes the urgency of integrating AI into our professional and personal spheres, cautioning against the risk of obsolescence for those who lag behind. "Airising Trends" stands as a testament to his mission, dedicated to spotlighting the latest in AI advancements and offering guidance on harnessing these tools to elevate one's life.

Recent Posts