OTWopentechwire
Tech Intelligence, Openly Wired
AI

OpenAI Bets on Autonomous Agents That Work While You Sleep

Dots, the company's new always-on AI assistants, can manage tasks across thousands of apps with minimal oversight - raising fresh questions about control and liability in agentic systems.

AS
Arjun S. Mehta
AI Correspondent · Bengaluru
Oct 1, 2026
6 min read
OpenAI Bets on Autonomous Agents That Work While You Sleep
Credit: OpenAI

The Always-On Agent Arrives

OpenAI has launched Dots, a new class of AI agent designed to operate continuously across a user's digital workspace. Announced at the company's DevDay conference in San Francisco on 29 September 2026, Dots represent a shift from conversational assistants toward autonomous systems that initiate tasks, manage workflows, and make decisions with limited human supervision.

The timing is notable. OpenAI has faced mounting criticism in recent weeks over agent behaviour in earlier releases, yet the company is now expanding access to agentic capabilities rather than pulling back. The calculus appears straightforward: the race to deploy production-ready agents is accelerating across the industry, and OpenAI believes it can address safety concerns through permission frameworks rather than restricting functionality.

Dots are positioned as proactive rather than reactive. Unlike traditional chatbots that wait for prompts, these agents monitor context, identify tasks, and act on behalf of users. OpenAI describes scenarios in which a Dot notices an unbilled invoice and prepares it for approval, or integrates fresh laboratory data into a research paper as results arrive. The promise is ambient productivity - work completed in the background, surfaced only when approval is required or a task is finished.

Integration Depth and Scope

The technical foundation rests on OpenAI's plugin ecosystem, which now spans more than 4,000 applications. Dots can authenticate into services, retrieve information, and in some cases execute changes. New integrations with Slack and Microsoft Teams extend the agent's reach beyond ChatGPT into enterprise communication platforms, allowing users to interact with their Dot wherever they work.

Each Dot operates with what OpenAI calls a "cloud computer" - a virtualised browser environment that users can inspect at any time. This transparency mechanism is intended to build trust: if a Dot is researching competitor pricing or drafting an email, the user can open the virtual desktop and observe the agent's activity in real time. OpenAI also supports direct connection to a user's own machine, enabling the agent to control local applications and work alongside the user on the same desktop.

At launch, Pro, Business Premium, and Enterprise subscribers in select markets receive one primary Dot, which can be named and customised. The company has signalled that future releases will support multiple agents - what it terms "teams of Dots" - each specialised for different roles or projects. The vision is a multi-agent orchestration layer in which one Dot handles customer feedback, another manages code deployment, and a third monitors financial reconciliation, all running in parallel.

Permission Architecture and Safety Claims

OpenAI has built a permission model that distinguishes between read-only research and write actions. When a Dot operates in the background - what the company calls "proactive research" - it is restricted to read-only access. It can browse connected apps, pull data, and prepare summaries, but it cannot send messages, modify documents, or trigger transactions without explicit approval.

For authentication, Dots can access saved passwords to sign into services, but OpenAI states that credentials are not exposed to the underlying language model. This architectural separation is critical: if passwords were visible to the model, they could theoretically be logged, retrieved, or leaked through prompt injection. OpenAI has not disclosed the technical implementation - whether credentials are handled by a separate secure enclave or passed through an isolated API - but the company insists that the model itself never "sees" the password in plaintext.

Users can define custom rules that specify which actions require approval. A developer might allow a Dot to create draft pull requests but require sign-off before merging. A finance professional might permit invoice preparation but block any actual payment initiation. These rules are managed through ChatGPT's existing app control interface, which now extends to Dot behaviour.

Despite these safeguards, the architecture introduces new attack surfaces. A Dot with read access to email, calendars, and internal documents holds a comprehensive view of an organisation's operations. If prompt injection or model jailbreaking techniques evolve, an attacker could potentially manipulate a Dot into exfiltrating sensitive information under the guise of legitimate research. OpenAI's track record on security - including recent incidents involving unauthorised agent actions - makes this a live concern rather than a theoretical one.

Enterprise Implications and the Multi-Agent Trajectory

The immediate target market is knowledge workers in technical and creative fields. OpenAI highlights use cases in software development, scientific research, and content production - domains where task decomposition and iterative refinement align well with agent capabilities. A developer could delegate bug triage: the Dot collects user-reported issues, categorises them by severity, and drafts fixes for review. A scientist could task the agent with updating a manuscript as experimental data arrives, maintaining version control and citation accuracy.

The enterprise angle is deliberate. By integrating with Slack and Teams, OpenAI positions Dots as workplace infrastructure rather than consumer novelty. The ability to audit a Dot's activity through the cloud computer interface addresses compliance requirements in regulated industries, though the extent to which Dot actions create audit trails - and who is liable when an agent errs - remains an open question.

Looking ahead, the multi-agent vision introduces coordination complexity. If a user manages five Dots, each with different permissions and contexts, the cognitive overhead of orchestrating them may negate the productivity gains. OpenAI will need to build meta-controls: dashboards that show what each agent is doing, conflict resolution when two Dots attempt contradictory actions, and rollback mechanisms when an agent makes a mistake that propagates across systems.

The Agentic Shift and Its Discontents

Dots exemplify a broader industry pivot toward agentic AI - systems that set their own subgoals, iterate on plans, and operate with partial autonomy. This shift has been building since late 2025, as foundation model capabilities plateaued in raw reasoning and companies sought differentiation through deployment patterns rather than parameter counts. Agents became the next frontier: not smarter models, but models embedded in workflows with the authority to act.

The trade-off is control. A chatbot that generates a draft leaves the human in the loop at every step. An agent that generates a draft, sends it for review, incorporates feedback, and schedules a follow-up meeting compresses multiple decisions into a single approval. The efficiency gain is real, but so is the risk of unintended consequences when an agent misinterprets context or executes a task in a way the user did not anticipate.

OpenAI's decision to expand agent access despite recent controversies suggests confidence - or competitive pressure - outweighs caution. The company is betting that permission frameworks and transparency tools will be sufficient to manage risk, and that users will tolerate occasional errors in exchange for ambient productivity. Whether that bet pays off depends on how Dots behave in production, how quickly users adapt to supervising rather than directing AI, and whether the industry can establish norms around agent liability before a high-profile failure forces regulation.

For now, Dots are live for Pro and Business Premium subscribers in select markets. The first agent is included at no additional cost, with usage limits applied in OpenAI's Codex and Work environments. The rollout is cautious - restricted geography, gated access, built-in approval prompts - but the trajectory is clear. OpenAI is moving from tools that assist to agents that act, and the rest of the industry is following close behind.

Read next
AI

OpenAI Ships GPT-6.1 Sol at One-Fifth the Cost as Astra Upgrade Gets Shelved Over Safety Flags

Mei-Lin Tan · 4 min
AI

Alibaba Unveils Zhenwu V900 Chip to Anchor 20 GW Data Centre Push

Wei Zhang · 6 min
AI

Technology Firms Report More AI Friction Than the Sectors They Sell To

Valerie Nguyen · 9 min
Spot something wrong? Email corrections@opentechwire.com. We log every correction publicly.