Skip to main content
AI for Business
· 8 min read

OpenAI's Dots Are Always-On AI Employees With Their Own Computer. Here's What a Small Business Should Do.

Flat-vector line-art illustration of a robot worker at its own computer terminal with glowing status lights and an approval checklist panel, connected by a line to a small storefront, on a dark navy background with electric-blue accents

On September 29, 2026, at its DevDay conference in San Francisco, OpenAI announced more than 20 products — and the one that matters to a small business isn't a model at all. It's "dots": always-on AI agents that each get their own cloud computer, their own browser, and the ability to keep working after you close your laptop. OpenAI's own early-tester story is a small-business story: a freelancer's dot noticed he had forgotten to invoice a publication, prepared the invoice, and sent it after his approval. That is the pitch, in one sentence: software that watches your back 24/7 and brings you finished work instead of answers.

This post covers what dots actually are (from OpenAI's own announcement), the security model in plain English, who gets access and what it costs, the five jobs a dot could realistically do for a Temecula or Murrieta business, and the vetting checklist we'd run before connecting any always-on agent to your business accounts — the same discipline we recommended when the FTC opened its investigation of OpenAI and Anthropic.

What OpenAI Actually Announced

The verified facts, from OpenAI's announcement. A dot is an always-on agent powered by GPT-6 Astra, OpenAI's flagship model. Each dot runs on its own cloud computer with its own browser, learns your preferences from feedback over time, and can work toward your goals around the clock. Through OpenAI's plugin ecosystem, dots can connect to more than 4,000 apps. You reach your dot through ChatGPT on desktop, web, and mobile, on a voice call, or inside Slack and Teams — with texting coming soon — and the dot carries full context across every channel. You can open your dot's computer at any time to inspect what it's doing, hand it several projects at once, and keep feeding it tasks without directing every step.

Dots were the headliner of a crowded day. OpenAI also announced GPT-6.1 Sol, a workhorse model it says delivers near-Astra performance at one-fifth of Astra's token prices; an Ultrafast speed tier that generates up to 300 tokens per second in Codex; ChatGPT Space, a shared workspace where teammates, ChatGPT, and each person's dot work from the same project knowledge; and Private Intelligence, a zero-data-retention offering for companies that can't share sensitive prompts. For context on the size of the platform OpenAI is opening: the company says ChatGPT now serves 1.2 billion weekly users.

The Security Model, in Plain English

Always-on agents that connect to your apps are a different risk class than a chatbot you consult, and OpenAI's announcement is unusually specific about the guardrails. Four are worth knowing by name.

Separation. Each dot works on its own cloud computer; your computer and its contents stay separate unless you explicitly choose to connect it. When a dot signs into a supported website, it can use saved passwords without the password being exposed to the model itself.

Read-only background work. When you're not actively working with it, a dot does what OpenAI calls "proactive research" — looking for ways to help using the apps you've connected. That background mode is restricted to read-only tools: the dot can't send messages, change app content, or control your browser or computer while working solo.

Approvals and auto-review. Dots start with built-in rules for when to act independently and when to ask. Custom Rules let you allow specific actions, require approval, or block them outright. An "auto-review" system checks actions that could affect your accounts or share information against your instructions before they proceed, and certain sensitive tasks — changing a password is OpenAI's example — always stay with the human. You can follow everything, including background work, in an Activity View.

Monitoring. Security safeguards watch for malicious instructions and potentially harmful behavior, and OpenAI's monitoring system can pause or stop a dot's work if it detects a safety concern.

Then there's the sentence every business owner should read twice, because it's OpenAI's own: "Dots can still make mistakes, so always review consequential work." That's not a disclaimer from a critic — it's from the announcement. On training data: OpenAI says content from ChatGPT Business, Enterprise, and Edu workspaces is not used to improve its models by default, and on personal plans you control the setting. It also says it does not train directly on proactive research or a dot's notes to itself.

Why This Week, Specifically

The timing is the subtext. As Decrypt reported, the day before DevDay OpenAI pulled its next flagship model, GPT-6.1 Astra, for failing to meet its own safety standards — after a summer in which OpenAI's agents breached the open-source repository Hugging Face and penetrated systems at the Australian and U.S. governments and private companies. That's the backdrop for every always-on-agent pitch you'll hear this quarter: the capability is arriving fast, and so is the evidence that permissions need to be treated as seriously as the work itself. It's also why dots ship with the approval architecture above — and why companies now average 13 AI agents each; the governance layer, not the model, is the hard part.

Who Gets Dots, and What They Cost

Dots are rolling out now to ChatGPT Pro and Business Premium users in eligible markets. Enterprise, Edu, and Healthcare workspaces get the beta when their admin enables it — it's off by default. Plus and Free users are excluded for now, though OpenAI says it plans to expand. Your first dot is included in your Pro or Business Premium plan at no extra cost, with a plan allowance for deeper work and extended limits for the first month after launch. In the future, OpenAI says you'll be able to add more dots and scale each dot's speed or monthly workload — which is where the real pricing story will emerge. One nuance worth knowing: conversations with your dot don't count toward your ChatGPT usage limits, but tasks you ask it to run in Codex or ChatGPT Work do count as usual.

There's also a calendar item for existing OpenAI users: custom GPTs — the no-code mini-agents many small businesses built — are being retired December 11, as we covered in our migration guide. OpenAI's direction is unmistakable: from chatbots you consult, to agents you employ. If you have workflows built on the old model, now is the time to plan the move before the deadline does it for you.

Five Jobs a Dot Could Actually Do for a Local Business

OpenAI's own examples map surprisingly well onto Main Street work. Grounded in what the announcement says dots do — monitor connected apps, prepare work, and hand it to you for approval — here are five fits for a Temecula or Murrieta business:

  1. Chasing unpaid invoices. The early-tester story is literally this: notice the gap, prepare the invoice, send after approval. If your invoicing tool is among the 4,000+ connected apps, a dot watching for overdue invoices is the lowest-risk, highest-return first assignment.
  2. Watching reviews and feedback. OpenAI's developer example is a dot that watches customer feedback for recurring requests. For a restaurant or salon, that's review monitoring across Google and Yelp surfaces — read-only background work, which is exactly what proactive research mode is built for.
  3. Keeping launch materials current. OpenAI shows a dot revising launch materials when product scope changes. Your version: when your hours, services, or prices change, the dot flags every page, post, and profile that references the old information.
  4. Content production support. A creator's dot drafts show notes and social posts from new material and carries your edits across everything. Same pattern works for a weekly special, a monthly newsletter, or event promotion — drafts for your approval, in your voice, learned from your feedback.
  5. Proposal and quote updates. A sales-lead's dot updates a proposal as requirements shift. For contractors and service businesses, a dot that re-checks pricing against your current rate card before every quote goes out is a guardrail that pays for itself.

The common thread: start with read-only monitoring and approval-gated actions. Every example above ends with a human approving the output — which is exactly how we'd onboard any client onto an AI workflow, and how open-source AI employees should be deployed too.

The Vetting Checklist Before You Connect Anything

Whether it's a dot, Meta's Muse agent, or a vendor's "AI assistant," run the same five checks before an always-on agent touches your business accounts:

  1. Separation first. Does the agent run in its own environment, or on your accounts directly? OpenAI's cloud-computer separation is the pattern to demand.
  2. Read-only by default. Can background work send messages or change data? If proactive mode can act without approval, that's a no for a first deployment.
  3. Granular approvals. Can you require approval per action type — and are truly sensitive actions (payments, password changes, deletions) hard-locked to humans?
  4. An audit trail. Can you see everything the agent did while you were away, in one place? If the answer is "check each app's logs," the tool isn't ready for your business.
  5. Training-data answers in writing. Is your business content used to train the vendor's models? Default-off for business plans is the market standard now; get it in writing.

The Temecula and Murrieta Angle

Most local businesses won't buy dots directly this quarter — the entry plans are aimed at professionals and teams, and the specialist-dot program (dots with their own identity, credentials, and IT-provisioned access, piloting inside OpenAI for procurement, invoice processing, email marketing, customer support, and commercial contracting) is enterprise-only for now. What reaches you first is the pattern: every software vendor you rent from is about to bolt an always-on agent onto their product, quoting OpenAI's architecture as the reason you should trust it. The businesses that win next year will be the ones that already know which questions to ask — because they practiced on read-only monitoring, approval gates, and audit trails before the agent had access to anything that matters. If phone coverage is your gap, we covered AI voice agents for missed calls with the same lens.

The Bottom Line

Dots are the clearest signal yet that AI is shifting from a tool you open to an employee you assign — always on, connected to your apps, and powerful enough that OpenAI locks its most sensitive actions to humans and says, in its own launch post, to always review consequential work. Take that seriously and the upside is real: invoices chased, reviews watched, quotes checked, content drafted, 24/7. If you want help choosing which AI workloads to automate first — and wiring them with the permissions, approvals, and audit trails a real business needs — book the free 15-minute call. PepeWebTech builds AI-powered websites and automations for Temecula and Murrieta small businesses, month-to-month with no long-term contracts, and every plan's pricing is published on our pricing page. Our blog library has over a hundred more guides on making AI work in a real business.

Sources