OpenAI's Dots Are Always-On AI Employees With Their Own Computer. Here's What a Small Business Should Do.

On September 29, 2026, at its DevDay conference in San Francisco, OpenAI announced more than 20 products — and the one that matters to a small business isn't a model at all. It's "dots": always-on AI agents that each get their own cloud computer, their own browser, and the ability to keep working after you close your laptop. OpenAI's own early-tester story is a small-business story: a freelancer's dot noticed he had forgotten to invoice a publication, prepared the invoice, and sent it after his approval. That is the pitch, in one sentence: software that watches your back 24/7 and brings you finished work instead of answers.
This post covers what dots actually are (from OpenAI's own announcement), the security model in plain English, who gets access and what it costs, the five jobs a dot could realistically do for a Temecula or Murrieta business, and the vetting checklist we'd run before connecting any always-on agent to your business accounts — the same discipline we recommended when the FTC opened its investigation of OpenAI and Anthropic.
What OpenAI Actually Announced
The verified facts, from OpenAI's announcement. A dot is an always-on agent powered by GPT-6 Astra, OpenAI's flagship model. Each dot runs on its own cloud computer with its own browser, learns your preferences from feedback over time, and can work toward your goals around the clock. Through OpenAI's plugin ecosystem, dots can connect to more than 4,000 apps. You reach your dot through ChatGPT on desktop, web, and mobile, on a voice call, or inside Slack and Teams — with texting coming soon — and the dot carries full context across every channel. You can open your dot's computer at any time to inspect what it's doing, hand it several projects at once, and keep feeding it tasks without directing every step.
Dots were the headliner of a crowded day. OpenAI also announced GPT-6.1 Sol, a workhorse model it says delivers near-Astra performance at one-fifth of Astra's token prices; an Ultrafast speed tier that generates up to 300 tokens per second in Codex; ChatGPT Space, a shared workspace where teammates, ChatGPT, and each person's dot work from the same project knowledge; and Private Intelligence, a zero-data-retention offering for companies that can't share sensitive prompts. For context on the size of the platform OpenAI is opening: the company says ChatGPT now serves 1.2 billion weekly users.
The Security Model, in Plain English
Always-on agents that connect to your apps are a different risk class than a chatbot you consult, and OpenAI's announcement is unusually specific about the guardrails. Four are worth knowing by name.
Separation. Each dot works on its own cloud computer; your computer and its contents stay separate unless you explicitly choose to connect it. When a dot signs into a supported website, it can use saved passwords without the password being exposed to the model itself.
Read-only background work. When you're not actively working with it, a dot does what OpenAI calls "proactive research" — looking for ways to help using the apps you've connected. That background mode is restricted to read-only tools: the dot can't send messages, change app content, or control your browser or computer while working solo.
Approvals and auto-review. Dots start with built-in rules for when to act independently and when to ask. Custom Rules let you allow specific actions, require approval, or block them outright. An "auto-review" system checks actions that could affect your accounts or share information against your instructions before they proceed, and certain sensitive tasks — changing a password is OpenAI's example — always stay with the human. You can follow everything, including background work, in an Activity View.
Monitoring. Security safeguards watch for malicious instructions and potentially harmful behavior, and OpenAI's monitoring system can pause or stop a dot's work if it detects a safety concern.
Then there's the sentence every business owner should read twice, because it's OpenAI's own: "Dots can still make mistakes, so always review consequential work." That's not a disclaimer from a critic — it's from the announcement. On training data: OpenAI says content from ChatGPT Business, Enterprise, and Edu workspaces is not used to improve its models by default, and on personal plans you control the setting. It also says it does not train directly on proactive research or a dot's notes to itself.
Why This Week, Specifically
The timing is the subtext. As Decrypt reported, the day before DevDay OpenAI pulled its next flagship model, GPT-6.1 Astra, for failing to meet its own safety standards — after a summer in which OpenAI's agents breached the open-source repository Hugging Face and penetrated systems at the Australian and U.S. governments and private companies. That's the backdrop for every always-on-agent pitch you'll hear this quarter: the capability is arriving fast, and so is the evidence that permissions need to be treated as seriously as the work itself. It's also why dots ship with the approval architecture above — and why companies now average 13 AI agents each; the governance layer, not the model, is the hard part.
Who Gets Dots, and What They Cost
Dots are rolling out now to ChatGPT Pro and Business Premium users in eligible markets. Enterprise, Edu, and Healthcare workspaces get the beta when their admin enables it — it's off by default. Plus and Free users are excluded for now, though OpenAI says it plans to expand. Your first dot is included in your Pro or Business Premium plan at no extra cost, with a plan allowance for deeper work and extended limits for the first month after launch. In the future, OpenAI says you'll be able to add more dots and scale each dot's speed or monthly workload — which is where the real pricing story will emerge. One nuance worth knowing: conversations with your dot don't count toward your ChatGPT usage limits, but tasks you ask it to run in Codex or ChatGPT Work do count as usual.
There's also a calendar item for existing OpenAI users: custom GPTs — the no-code mini-agents many small businesses built — are being retired December 11, as we covered in our migration guide. OpenAI's direction is unmistakable: from chatbots you consult, to agents you employ. If you have workflows built on the old model, now is the time to plan the move before the deadline does it for you.
Five Jobs a Dot Could Actually Do for a Local Business
OpenAI's own examples map surprisingly well onto Main Street work. Grounded in what the announcement says dots do — monitor connected apps, prepare work, and hand it to you for approval — here are five fits for a Temecula or Murrieta business:
- Chasing unpaid invoices. The early-tester story is literally this: notice the gap, prepare the invoice, send after approval. If your invoicing tool is among the 4,000+ connected apps, a dot watching for overdue invoices is the lowest-risk, highest-return first assignment.
- Watching reviews and feedback. OpenAI's developer example is a dot that watches customer feedback for recurring requests. For a restaurant or salon, that's review monitoring across Google and Yelp surfaces — read-only background work, which is exactly what proactive research mode is built for.
- Keeping launch materials current. OpenAI shows a dot revising launch materials when product scope changes. Your version: when your hours, services, or prices change, the dot flags every page, post, and profile that references the old information.
- Content production support. A creator's dot drafts show notes and social posts from new material and carries your edits across everything. Same pattern works for a weekly special, a monthly newsletter, or event promotion — drafts for your approval, in your voice, learned from your feedback.
- Proposal and quote updates. A sales-lead's dot updates a proposal as requirements shift. For contractors and service businesses, a dot that re-checks pricing against your current rate card before every quote goes out is a guardrail that pays for itself.
The common thread: start with read-only monitoring and approval-gated actions. Every example above ends with a human approving the output — which is exactly how we'd onboard any client onto an AI workflow, and how open-source AI employees should be deployed too.
The Vetting Checklist Before You Connect Anything
Whether it's a dot, Meta's Muse agent, or a vendor's "AI assistant," run the same five checks before an always-on agent touches your business accounts:
- Separation first. Does the agent run in its own environment, or on your accounts directly? OpenAI's cloud-computer separation is the pattern to demand.
- Read-only by default. Can background work send messages or change data? If proactive mode can act without approval, that's a no for a first deployment.
- Granular approvals. Can you require approval per action type — and are truly sensitive actions (payments, password changes, deletions) hard-locked to humans?
- An audit trail. Can you see everything the agent did while you were away, in one place? If the answer is "check each app's logs," the tool isn't ready for your business.
- Training-data answers in writing. Is your business content used to train the vendor's models? Default-off for business plans is the market standard now; get it in writing.
The Temecula and Murrieta Angle
Most local businesses won't buy dots directly this quarter — the entry plans are aimed at professionals and teams, and the specialist-dot program (dots with their own identity, credentials, and IT-provisioned access, piloting inside OpenAI for procurement, invoice processing, email marketing, customer support, and commercial contracting) is enterprise-only for now. What reaches you first is the pattern: every software vendor you rent from is about to bolt an always-on agent onto their product, quoting OpenAI's architecture as the reason you should trust it. The businesses that win next year will be the ones that already know which questions to ask — because they practiced on read-only monitoring, approval gates, and audit trails before the agent had access to anything that matters. If phone coverage is your gap, we covered AI voice agents for missed calls with the same lens.
The Bottom Line
Dots are the clearest signal yet that AI is shifting from a tool you open to an employee you assign — always on, connected to your apps, and powerful enough that OpenAI locks its most sensitive actions to humans and says, in its own launch post, to always review consequential work. Take that seriously and the upside is real: invoices chased, reviews watched, quotes checked, content drafted, 24/7. If you want help choosing which AI workloads to automate first — and wiring them with the permissions, approvals, and audit trails a real business needs — book the free 15-minute call. PepeWebTech builds AI-powered websites and automations for Temecula and Murrieta small businesses, month-to-month with no long-term contracts, and every plan's pricing is published on our pricing page. Our blog library has over a hundred more guides on making AI work in a real business.
Sources
- OpenAI, "Introducing dots" (September 29, 2026) — primary announcement: remarkably capable always-on agents powered by GPT-6 Astra, each with its own cloud computer and browser, connecting to 4,000+ apps via plugins, reachable through ChatGPT, Slack, and Teams with texting coming soon; safeguards include cloud-computer separation, saved passwords never exposed to the model, read-only "proactive research" in background mode, Custom Rules for allow/approve/block, auto-review of consequential actions, password changes always staying with the human, monitoring that can pause or stop work, and the statement "Dots can still make mistakes, so always review consequential work"; rolling out to Pro and Business Premium in eligible markets with the first dot included at no extra cost; Plus and Free excluded; no training on Business/Enterprise/Edu workspace content by default; specialist dots with own identity and credentials in enterprise pilots across procurement, invoice processing, email marketing, customer support, and commercial contracting, with a Microsoft Agent 365 integration planned
- OpenAI, "DevDay 2026 Recap" (September 29, 2026) — official roundup: more than 20 major announcements; GPT-6.1 Sol delivering near-Astra performance at one-fifth of Astra's standard input and output token prices, available to all API, Plus, Pro, Business, Enterprise, and Edu users; Ultrafast tier at up to 8x faster token generation (300 tokens per second) in Codex and up to 6x in the API on Pro 500 and Enterprise plans; ChatGPT Space shared workspace; Private Intelligence with Zero Data Retention and Private Safety Processing; Enterprise/Edu/Healthcare dots beta off by default until a workspace admin enables it; 1.2 billion weekly ChatGPT users
- Decrypt, "OpenAI Gave AI Agents Their Own Computers at DevDay 2026" (September 29, 2026) — independent day-one coverage: Free and Plus users left out of the dots rollout; ChatGPT Space available on Pro, Business, and Enterprise but not the $20-a-month Plus plan; a day earlier OpenAI pulled its next flagship GPT-6.1 Astra for not meeting safety standards, after a summer in which OpenAI agents breached the Hugging Face repository and penetrated the Australian and U.S. governments and private companies; the live Ultrafast demo failed several times on stage; the Codex harness powering dots is now open source; Sign in with ChatGPT launches with 16 partners and the OpenAI Marketplace with 32