OpenAI Dots Agent Looks Cute, but It Works Like Enterprise Software
OpenAI launched Dots on September 29, turning ChatGPT into an always-on agent that can keep working after a conversation ends. The OpenAI Dots agent has a friendly avatar, a customizable name, and enough access to order dinner. Yet its design, permissions, and strongest early results point firmly toward workplace software.
That tension matters because consumer agents usually compete on convenience. Meta’s Muse and similar products promise a personal shopper, travel planner, and universal checkout assistant. OpenAI instead gives its agent a cloud computer, connected applications, optional local computer access, and controls that resemble an IT administration console.
The difference becomes clear when Dots meets the open web. It can search email, prepare a purchase, or navigate a service, but security checks often force the user back into control. Give it a website, media files, or another environment you manage, and the product starts looking much more capable.
OpenAI is therefore testing a larger proposition than automated dinner orders. It wants people and companies to delegate ongoing responsibilities to software that can remember context, operate applications, and return completed work. The cute character is the invitation. The real product is an autonomous coworker.
The OpenAI Dots Agent Keeps Working Between Conversations
Dots changes ChatGPT from a destination for questions into a worker that can retain responsibility for an unfinished goal.
OpenAI introduced Dots during DevDay 2026 in San Francisco. The company describes a dot as an always-on agent powered by GPT-6 Astra. An agent is software that can plan and perform several actions toward a goal, rather than only generating a response.
Each dot receives its own cloud computer. It can use websites, run applications, consult connected services, and continue making progress between conversations. Users can inspect its activity, redirect it, or stop it while work is underway.
That persistent design separates Dots from a standard ChatGPT session. A chatbot normally waits for the next message. A dot can maintain context, decide what step comes next, delegate work, and notify its owner when judgment or approval becomes necessary.
OpenAI initially gives each eligible user one dot. The company says it plans to support additional dots later, creating the possibility of several specialized agents. One might manage research while another monitors projects or maintains a website.
The product is rolling out through ChatGPT on desktop and the web. Mobile access lets users communicate with an existing dot when available, although initial creation happens on a computer. Slack and Microsoft Teams can also become communication channels when organizations enable the required access.
Its interface presents the dot as a personable character. Users choose a name and interact through chat or voice. A separate view exposes the cloud computer, letting the owner watch the agent navigate software and websites.
That visual approach resembles Meta Muse, but the underlying framing differs. Muse presents the agent as an approachable personal helper. Dots looks more like a managed workstation operated by an AI employee.
The distinction appears in OpenAI’s enterprise controls. Workspace administrators can enable or disable Dots, connected applications, cloud browsing, network access, and local computer control. They can also decide whether members may add their agents to workplace messaging systems.
Enterprise access starts disabled by default. Local computer access and customizable action rules also require separate permission. According to OpenAI’s workspace controls, enabling the agent does not automatically grant every connected service or computer capability.
Those settings reveal OpenAI’s intended destination. Ordering food makes an accessible demonstration, but administering autonomous software requires identity, permission, auditability, and policy. Those are enterprise requirements.
The persistence also changes how users must formulate requests. A dot works best with a responsibility, relevant context, and clear boundaries. “Keep this project moving” fits the design better than a disconnected sequence of small prompts.
This is close to an AI workflow, where information, decisions, and repeated actions remain connected over time. The agent becomes valuable when it can carry context across those steps.
That is the first reversal behind Dots. OpenAI wrapped a serious delegation system in a charming character. The personality makes the software approachable, but its operational model belongs in the workplace.
Cute Avatars Hide a Workplace Operating Model
The most important contrast is not OpenAI against Meta as companies. It is managed delegation against consumer convenience.
Consumer agents sell a simple idea. Ask for an outcome, watch the software cross several websites, and approve the final transaction. Shopping, reservations, travel planning, and personal scheduling are natural demonstrations because everyone understands the friction.
OpenAI can support those scenarios. In one company demonstration, a dot noticed that its user would work through dinner. It then prepared two delivery choices, including estimated costs, and asked which meal should be ordered.
That demonstration made the agent feel personal and proactive. However, OpenAI devoted substantial product architecture to responsibilities that extend far beyond a meal. Dots can use workplace applications, retain project context, access a local machine, and eventually divide work among multiple agents.
The company has also discussed specialist dots for enterprise customers. These agents would focus on defined areas such as accounting, marketing, or legal analysis. A specialist structure assumes organizations will assign responsibilities, evaluate outputs, and govern access by role.
That resembles a workforce management model more than a shopping assistant. The agent needs a job definition, resources, authority, escalation rules, and oversight. Its owner becomes a manager who decides what can proceed automatically.
OpenAI CEO Sam Altman described Dots as the kind of AI helper imagined in movies. The DevDay coverage also positioned Meta’s Muse as its visible competitor. Yet the products are making different initial bets about adoption.
Meta’s approach emphasizes broad familiarity and personal assistance. OpenAI is starting with users and organizations already willing to supervise complex AI work. This gives Dots a narrower opening, but potentially deeper responsibilities.
The rollout reinforces that decision. Access is concentrated among eligible professional and business users, with enterprise participation controlled by administrators. Dots is not initially presented as a universal feature for every casual ChatGPT user.
That gating matters without considering any particular subscription price. An agent becomes useful only when its completed work is worth the effort of connecting services, setting permissions, reviewing activity, and correcting mistakes. Professional workflows offer more chances to clear that threshold.
A website refresh can consume an afternoon. Combining and formatting several video files may require unfamiliar software. Researching a project across internal sources can produce hours of repetitive work. Those jobs create measurable value when delegated successfully.
Ordering dinner has a lower ceiling. Saving several minutes is useful, but a security challenge or failed login can erase the benefit. A person who must repeatedly rescue an agent may return to the ordinary app.
The consumer and enterprise routes also face different business pressures. A mass-market assistant must reach many users and find a sustainable commercial model. A workplace agent can justify itself through completed projects, reduced delays, or expanded capacity.
Neither route guarantees reliable performance. Enterprise environments contain sensitive information and consequential actions. Their structured software may help an agent operate, but mistakes can carry greater costs.
OpenAI appears to be betting that governance can make broader access acceptable. Administrators can restrict capabilities, while users can define custom rules for supported actions. Sensitive steps can trigger approval or require the person to take over.
This produces a less magical experience than complete autonomy. It also reflects how organizations adopt new operational software. Businesses usually want incremental authority, visible logs, and a way to stop a process.
The cute avatar softens that administrative reality. It encourages conversation and makes delegation feel less like configuring an automation server. However, the agent’s usefulness still depends on careful setup.
Dots therefore pressures both sides of the market. Consumer agents must show that convenience remains valuable when websites resist automation. Enterprise platforms must make controls usable without turning every task into a compliance project.
OpenAI’s strongest advantage may be the connection between those worlds. The same agent can receive a casual voice instruction, search business context, operate software, and send progress updates to a phone. That continuity is more significant than the avatar.
Dinner Orders Expose the Limits of Browser Agents
The open web remains hostile territory for autonomous agents, especially when identity, payments, and anti-bot systems enter the task.
A hands-on test by The Verge illustrates the problem. The reviewer asked Dot to schedule a home internet installation. The agent searched email, recovered a promotional offer, and navigated most of the registration process.
It then encountered a human verification control requiring a sustained mouse press. Dot reported that its browser tools could not complete the interaction. The user had to take control before the agent could continue.
The process reached another boundary at payment. Dot asked the reviewer to enter sensitive banking information into the virtual browser. The reviewer declined and completed the task elsewhere.
That reaction is rational. An autonomous browser combines broad access with imperfect judgment. Users must decide whether the convenience outweighs uncertainty about stored context, connected accounts, and irreversible actions.
Other personal tasks produced similar friction. Dot failed to locate a complimentary coworking trial and offered a paid day pass instead. A competing agent reportedly found the correct option and scheduled the visit.
Dot also became trapped in a security loop while trying to enter an Ikea account. A restaurant ordering page blocked its cloud browser. These failures suggest that browser identity and anti-automation systems remain central constraints.
The failures do not mean the agent lacked reasoning ability. Dot often identified the objective and reached the relevant service. The breakdown occurred where external websites demanded proof of human presence or resisted cloud browser traffic.
That distinction matters. Model improvements alone cannot solve every obstacle. Agent developers also need reliable authentication, approved integrations, payment mechanisms, and cooperation from service providers.
Websites have good reasons to challenge automated traffic. Bots can abuse promotions, create accounts, scrape data, test stolen credentials, or flood limited inventory. A capable agent can resemble malicious automation from the website’s perspective.
Yet aggressive blocking also creates a fragmented user experience. An agent might complete nine steps and fail at the tenth. The person must then understand the agent’s state, take control, and avoid duplicating an action.
The hands-on testing showed that Dots required more intervention than some consumer-oriented rivals. That result supports the enterprise interpretation because controlled environments reduce these external obstacles.
Inside a company-owned website, a local computer, or an approved connected application, the agent operates with clearer authority. It encounters fewer anti-bot challenges and can work from data explicitly provided by the user.
In the same test, Dot became more effective when it received access to the reviewer’s personal website. The reviewer described requested changes by voice, then left while the agent produced another version.
Dot also combined several desktop video files into a social-media-ready clip. It deployed website changes after receiving extensive permissions. Those tasks produced usable results with less dependence on hostile third-party websites.
This contrast explains the product’s character. Dots is not simply a universal browser robot. It is closer to Codex for general knowledge work, especially when the user controls the files, tools, and destination.
That framing does not eliminate consumer value. Dot eventually ordered the reviewer’s meal after receiving help with account access. It can still bridge personal and professional tasks when users accept occasional handoffs.
However, the dinner example should not become the standard for judging the entire platform. Commerce introduces specialized integration problems that differ from document work, software operation, or project research.
A better test asks whether the agent can own a meaningful result. Can it update a site after receiving feedback? Can it prepare a research package and identify missing evidence? Can it monitor a project without repeating completed work?
Those scenarios depend on persistent context more than checkout optimization. They also align with OpenAI’s broader strategy of making ChatGPT a place where work is delegated, reviewed, and continued.
For users, the lesson is practical. Assigning a dot a bounded project inside a trusted environment offers a better first test than handing it an unrestricted purchasing mission. Reliability should expand before authority does.
Permissions Are the Product, Not Administrative Overhead
An always-on agent becomes useful only when users understand what it remembers, where it can act, and which decisions remain human.
Dots can access unusually sensitive context. Connected applications may expose correspondence, calendars, documents, contacts, and account activity. Local computer access can extend that reach to files and commands on a personal machine.
Persistence increases both value and risk. A dot can remember enough context to continue a project without repeated explanations. The same memory can preserve information that a user later wants to remove.
OpenAI says users cannot currently inspect, edit, or delete individual items within a dot’s context. Deleting the dot removes its own context, but separately stored conversations, files, and Codex threads remain.
Disconnecting an external service stops new access. It does not automatically remove information already incorporated into the dot’s context. That behavior deserves attention before users connect broad archives.
Data treatment also varies by account type and settings. OpenAI says it does not use Business, Enterprise, or Edu workspace data for model training by default. Personal accounts rely on the user’s model-improvement setting.
The company’s privacy guidance says limited human review can still occur in safety-related circumstances. Users should read those controls before placing confidential material inside an agent’s working context.
Action permissions create another layer. Some sensitive operations require approval, while the most consequential actions can require the user to take over. Custom rules let users define supported boundaries, but they cannot disable core safeguards.
OpenAI also uses an automated review system before certain planned actions. For example, it can inspect an email recipient and message against the user’s instructions. This aims to catch unintended disclosure before sending.
Those checks are necessary because agents interpret both user commands and external content. A malicious webpage or document can contain a prompt injection, meaning instructions designed to redirect the agent or reveal information.
OpenAI says Dots is designed to distinguish external content from authorized user instructions. Tool restrictions, approvals, monitoring, and automated reviews add further defenses. The company also acknowledges that these protections do not eliminate every mistake.
This is where the workplace comparison becomes most important. Traditional productivity software usually acts when a person presses a button. An agent selects and sequences actions, so permission cannot remain a simple yes-or-no switch.
The relevant question becomes conditional authority. A user might allow draft creation but require approval before publishing. They might permit calendar analysis while prohibiting messages to clients.
Organizations need even finer distinctions. A marketing agent may read campaign files without accessing payroll records. A finance agent may prepare a report but lack authority to move money or change account credentials.
These controls can make Dots appear cumbersome beside a frictionless consumer assistant. They also create the foundation for serious delegation. Businesses cannot rely on personality or good intentions when software touches operational systems.
Auditability matters for the same reason. Activity View lets users examine current and delegated tasks, see status, add context, correct misunderstandings, or stop work. Visibility turns autonomy into something closer to supervised operations.
The difficult part is making that supervision efficient. If users must approve every routine click, the agent becomes remote-controlled automation. If they approve too much, one mistaken interpretation can spread across several systems.
OpenAI must therefore prove that its default boundaries fit real work. Customization cannot become a requirement for basic safety. People often accept default settings, especially when they do not understand every connected service.
The product also needs clearer memory management. Deleting an entire dot is a blunt response to one unwanted detail. Granular inspection and deletion would give users more control over persistent context.
Trust will grow through predictable behavior, not increasingly human presentation. A friendly name can encourage interaction, but it does not answer where data travels or what an agent can reverse.
Teams evaluating Dots should begin with low-risk, recoverable work. Drafts, research, file organization, and internal prototypes offer useful tests. Account changes, external publishing, and financial actions deserve stricter review.
This approach resembles building an AI knowledge base. Access rules and source boundaries shape the reliability of every answer or action produced from stored context.
The skeptical case against Dots is therefore not that agents will never work. It is that their value may depend on permissions users find exhausting and context controls they cannot yet manage precisely.
OpenAI Is Turning ChatGPT Into a Work Layer
Dots places OpenAI in competition with productivity platforms, automation vendors, and consumer assistants at the same time.
ChatGPT began as a conversational interface. Dots pushes it toward an operating layer that connects goals, context, applications, and execution. That expansion changes who OpenAI pressures.
Meta Muse is the most visible consumer comparison. Both products use approachable characters, accept broad requests, and operate across services. Muse emphasizes personal convenience, while Dots initially emphasizes sustained work.
Microsoft, Google, Salesforce, and other enterprise software companies also have strategic reasons to respond. Their applications already contain organizational data, permissions, and workflows. They can embed agents where employees already work.
OpenAI approaches from the opposite direction. It owns a widely used AI interface and wants to connect outward into business systems. Dots becomes the persistent identity that carries context across those systems.
This creates a contest over the primary work interface. If users begin a project with their dot, individual applications can become resources in the background. If platform vendors keep agents inside their suites, ChatGPT remains one tool among many.
OpenAI is preparing for both possibilities. Dots can communicate through Slack and Microsoft Teams, while enterprise administrators retain controls over access. The company has also discussed integration with Microsoft’s agent management systems.
The long-term vision includes teams of dots. That idea raises the stakes because organizations would manage portfolios of agents, not one assistant. Agents could specialize, exchange work, and escalate decisions to people.
Such a model resembles an organization chart rendered in software. It requires clear ownership, shared context, performance evaluation, and conflict resolution. Multiple agents can amplify confusion as easily as productivity.
OpenAI’s early availability strategy gives it a controlled place to study those problems. Professional users tend to have concrete projects and stronger motivation to tolerate setup. Enterprise administrators can restrict exposure during a beta.
Evidence of growing agent use also supports the timing. OpenAI reported that agentic activity represented 64 percent of combined Codex and ChatGPT output tokens among enterprise customers by June 2026. The company defines that measure using Codex activity, so it should not be read as independent market data.
Still, the figure shows why OpenAI is expanding the Codex pattern. Coding agents demonstrated that users will delegate multistep work when outputs can be inspected and corrected. Dots attempts to apply that pattern beyond software development.
The Verge’s description of Dots as “Codex, but for regular people” captures the strategy. Code offers structured files, tools, tests, and version control. General knowledge work lacks many of those safeguards.
Dots must recreate enough structure through permissions, activity logs, approvals, and connected applications. Its strongest tasks will likely be those with clear inputs and reviewable outputs.
That includes building a prototype, editing media, organizing research, or maintaining a controlled web property. Ambiguous purchasing decisions and adversarial websites remain harder.
The competitive question is therefore not which agent looks friendliest. It is which company can create the most reliable path from intent to inspected result.
Meta can use consumer reach and personal context. Workplace vendors can use embedded data and established permissions. OpenAI can combine a general AI interface with increasingly capable models and computer control.
Each position has tradeoffs. Consumer scale does not automatically produce workplace trust. Existing enterprise distribution does not guarantee a coherent cross-application assistant. Model capability does not remove integration barriers.
Dots gives OpenAI a credible route into this contest, but it also exposes the company to higher expectations. A chatbot can be wrong in a disposable answer. A persistent agent can make the wrong edit, contact the wrong person, or preserve unwanted context.
The quality standard must therefore include execution, recovery, and governance. Benchmarks for language generation cannot capture whether a task remained within authority or whether a mistake was reversible.
That is why early hands-on evidence matters. The successful website and video tasks reveal useful capability. The blocked purchases and login loops reveal the operational gap between a compelling model and dependable service delivery.
OpenAI’s advantage will strengthen if users repeatedly finish deferred work through Dots. It will weaken if the agent mostly creates another queue requiring supervision.
Three Signals Will Show Whether Dots Can Become a Coworker
The next stage should be judged by completed responsibilities, fewer rescue moments, and better control over persistent context.
The first signal is the rate of successful tasks without unplanned intervention. OpenAI has not published a broad completion measure for Dots. Real-world reliability will become clearer as more users test recurring projects.
A useful measure would distinguish planned approvals from failures. Asking before an external message is appropriate. Becoming trapped by a security check, losing task state, or selecting the wrong offer reflects a different problem.
Fewer browser takeovers would strengthen OpenAI’s claim that Dots can handle everyday responsibilities. Continued dependence on manual rescue would keep the product focused on controlled workplace environments.
The second signal is enterprise deployment beyond limited trials. Administrators need evidence that permissions, connected services, logs, and approval rules can support real teams without excessive configuration.
Watch for organizations assigning dots stable responsibilities rather than one-off demonstrations. Repeated use in research, operations, media production, or internal reporting would support the coworker thesis.
Also watch how OpenAI handles specialist dots. Clear role boundaries and measurable outputs would make multiple agents easier to govern. Vague personalities with overlapping access would increase operational risk.
The third signal is progress in memory and security controls. Users currently need more visibility into what persistent context contains. Granular review, correction, and deletion would make long-running delegation easier to trust.
Security performance matters just as much. Dots will encounter malicious instructions, phishing attempts, and misleading content while browsing. OpenAI’s safeguards must withstand those conditions without blocking ordinary work too often.
Independent testing will be essential because the company’s own demonstrations cannot represent every environment. WIRED’s agent overview correctly emphasizes both connected-app utility and the risks of sharing broad personal context.
If those three signals improve together, Dots can become more than an appealing DevDay demonstration. Reliable completion creates value. Enterprise adoption validates the work model. Better memory and security controls make persistent use defensible.
If only capability improves, trust may remain the limiting factor. If only controls improve, the product may feel too restrictive. OpenAI needs autonomy and supervision to advance together.
For knowledge workers, the sensible next step is not handing over an entire digital life. Choose one bounded responsibility with clear inputs, a reviewable result, and recoverable actions. Then track how often the OpenAI Dots agent finishes correctly, requests justified approval, or needs rescue.
That test answers the question behind the cute avatar. Is Dots another assistant that produces suggestions, or software that can genuinely own part of the work? The dinner order makes a memorable demo, but reliable delegation will decide the product’s future.



