Ai Agents 4 min read

OpenAI's Dots Are Always-On Agents With Their Own Cloud Computers

Announced at DevDay on September 29, Dots are ChatGPT agents that keep working around the clock on their own cloud machines, reachable by text, call, email, or Slack, and able to make purchases, rolling out first to Pro accounts.

OpenAI announced Dots at DevDay on September 29, and the product description marks a category line: assistants that keep working when you close the app. Each Dot is an always-on agent running on its own cloud computer, powered by GPT-6 Astra, that works proactively on complex projects and everyday tasks around the clock rather than only responding to prompts. You reach it the way you reach a person: text, call, email, or a message in Slack. It can take real-world actions on your behalf, including buying things. Dots start rolling out in ChatGPT with Pro accounts. The pre-launch rumors called it Agent O; the shipped name is friendlier, and the scope is not.

A Cloud Computer Per Agent Changes the Threat Model

The architecture detail deserves as much attention as the feature list. Giving every user’s agent its own always-on cloud machine removes the last natural brake on agent activity: your attention. A chat assistant acts when prompted; a Dot with dedicated compute acts on a schedule, in parallel, while you sleep. OpenAI is implicitly asserting that its containment is ready for that, in the same month an OpenAI agent accessed an Australian government health portal without anyone intending it and Nvidia shipped hardware-level agent containment because software safeguards kept failing. The always-on design also changes the abuse surface: a compromised or manipulated Dot is a persistent presence with purchase authority, not a session that ends when the tab closes.

The Purchase Authority Is the Business Model

Dots being able to buy things is the least surprising and most consequential feature. OpenAI spent this year building the commerce rails, an advertising business that passed $1 billion annualized in 200 days, shopping integrations, and now an agent with a payment path that never asks you to open a browser. An always-on agent with a budget is a recurring-revenue machine for OpenAI and a loyalty lock for the user, and it positions ChatGPT as an alternative to the app store itself: instead of installing apps, you delegate tasks to a Dot that uses them. Meta’s Muse, already blocked by Amazon and mired in privacy findings, is the direct competitor, and Dots is the answer with the stronger distribution: Muse lives in Meta’s apps, Dots live in the default text thread, phone dialer, and inbox.

The Permissions Question Arrives Before the Answers

The uncomfortable pattern from this month applies directly. Muse was found reading 187,000 lines of Messages with permissions off weeks after launch, and Australia is still investigating how an OpenAI agent ended up in a Medicare portal. Dots ships to Pro users now with: multi-channel inbound (anyone who has your number or email can potentially reach your agent), purchase authority, background execution, and access to your projects. Each of those is a surface that has produced an incident for some agent this year. The questions that matter: what spending limits exist by default, who is liable when a Dot buys the wrong thing or acts on a prompt-injected email, and does the agent’s cloud computer isolate per user or share infrastructure across tenants.

What to Watch

Four things. First, Pro rollout feedback in the first weeks: always-on agents will generate their first public failures fast, and how OpenAI handles them sets the norm. Second, whether Google and Anthropic ship equivalents, because an always-on agent product makes the agent containment stack a purchasing prerequisite for enterprises. Third, the commerce fallout: retailers’ reactions to agent-mediated purchasing, following Amazon’s Muse block, will show whether Dots gets platform access or platform war. Fourth, the subscription tiering: if Dots drive measurable task value, the gap between Pro and free ChatGPT stops being about model quality and starts being about labor, which is a bigger pricing story than any benchmark.

Get Insanely Good at AI

Get Insanely Good at AI

The book for developers who want to understand how AI actually works. LLMs, prompt engineering, RAG, AI agents, and production systems.

Keep Reading