OpenAI has unveiled Dots, a new generation of “always-on” AI agents designed to carry out tasks autonomously and continue working in the background after receiving instructions from users.
OpenAI CEO Sam Altman introduced Dots at the company’s annual DevDay conference in San Francisco on Tuesday, describing the technology as a new way of working with AI. The colorful, character-like assistants are designed to act more proactively than conventional chatbots and can work across applications and connected tools.
Powered by OpenAI’s GPT-6 Astra model, Dots can operate their own cloud computer and browser, use connected applications and tools, handle recurring tasks and follow up through services such as email, text messaging and Slack. The company says users can assign a task to a Dot and allow it to continue working with limited supervision.
What can Dots do?
Dots are designed to handle a broad range of tasks. Depending on the permissions granted by the user, they can help with software development, content creation, scheduling, research and other work across connected applications.
OpenAI has described the system as an AI helper that can remain active rather than requiring users to start a new conversation every time they need assistance. The company also plans to allow users to work with multiple specialized Dots in the future.
The system can also use connected applications, but access is governed by user permissions and additional safety controls.
Safety remains a major challenge
The expanded autonomy of Dots also creates new safety concerns. Unlike a conventional chatbot, an AI agent with access to applications, files and a browser can potentially take actions in the real world on a user’s behalf.
OpenAI says it conducted extensive automated and human red-team testing before launch. The company’s safety documentation says testers attempted to manipulate Dots through malicious emails, hidden instructions and other forms of prompt injection, as well as attempts to make the agents disclose sensitive information or take unauthorized actions.
OpenAI reported that Dots showed strong resistance to several of these attacks. In one large simulated test involving 50,000 emails, including 16,600 adversarial messages, the company said it recorded no scored attack successes. In another test involving 2,638 attempts, it likewise reported no successful attacks.
However, the testing also identified areas requiring additional safeguards. OpenAI said it strengthened its confirmation policies after finding situations in which Dots needed to handle sensitive disclosures or seek user confirmation more reliably.
The company’s evaluations also found some moderate violations of intended task boundaries when agents handled multiple chained tasks. In one test, the rate of flagged boundary violations increased from 8.6% to 19.7% when the number of intervening tasks was doubled from five to 10. OpenAI said these results were part of deliberately difficult safety evaluations rather than predictions of how often such behavior would occur in ordinary use.
Multiple layers of protection
OpenAI has introduced several safeguards for Dots. Users can control which applications and data sources an agent can access, while custom rules can establish additional restrictions.
An Auto-review system checks certain planned actions against the user’s instructions, custom rules and safety requirements before they are carried out. Safety monitoring also operates while a Dot is working.
For proactive research, Dots have additional restrictions: their research tools cannot independently send messages, modify content through connected applications or control a browser or computer. OpenAI says these safeguards are intended to reduce the risk of unauthorized actions, although they do not eliminate the possibility of mistakes.
The launch comes amid wider concerns about the safety of increasingly autonomous AI systems. OpenAI itself has emphasized that more capable agents require additional monitoring, permission controls and safeguards because they can act on users’ behalf rather than simply provide information.
A new phase in AI assistants
Dots represent OpenAI’s move toward AI systems that can perform long-running, multi-step tasks instead of merely responding to individual prompts. The company is initially making the technology available to selected paid users, including Pro, Business and Enterprise customers.
The launch also places OpenAI in competition with other technology companies developing autonomous AI assistants, including Meta, which recently introduced its own agent called Muse.
The central challenge for Dots—and for autonomous AI more broadly—is therefore not simply whether an AI can complete a task, but whether it can reliably understand the limits of the authority given to it while working independently.
OpenAI says it will continue testing and strengthening Dots’ safeguards as the system is deployed.



