Last updated: October 2026
What are ChatGPT Dots, and what do they change for ChatGPT agent security?
Dots are OpenAI's always-on agents. Each one runs on its own cloud computer, holds credentials and keeps working between conversations. That moves the ChatGPT agent risk from a supervised session to a standing identity, so enterprises need access, logging and approval rules before they switch Dots on.
TL;DR: Key Takeaways
- Dots launched on September 29, 2026. OpenAI describes them as always-on agents that can connect to over 4,000 apps, powered by GPT-6 Astra (OpenAI, 2026).
- Enterprise access is a beta, off by default. Enterprise, Edu and Healthcare workspaces get Dots only when an admin enables them, and three key settings ship off by default (OpenAI Help Center, 2026).
- OpenAI says protections do not eliminate injection. Its Dots FAQ says protections "do not eliminate it" (OpenAI Help Center, 2026), and in December 2025 it called prompt injection "unlikely to ever be fully 'solved'" (OpenAI, 2025).
- Vendor-reported model numbers still show residual risk. GPT-6 Astra scored an 8.5% attack success rate on Gray Swan's IPI Arena, against 27.0% for GPT-5.6 Sol (OpenAI, 2026).
- The beta has documented gaps. OpenAI says Dots do not support data residency, and exclude FedRAMP and EKM workspaces (OpenAI, 2026).
- Governance is the open problem. Gartner expects 25% of enterprise breaches to trace to AI agent abuse by 2028 (Gartner, 2024).
Dots, Work, Atlas and agent mode at a glance
| ChatGPT agent | ChatGPT Atlas | ChatGPT Work | Dots | |
|---|---|---|---|---|
| Launched | July 17, 2025 | October 21, 2025 | July 2026 | September 29, 2026 |
| Model of use | Task you supervise | Browser with agent mode | Multi-step task with approvals | Standing agent with its own cloud computer |
| Status on October 5, 2026 | "No longer available," replaced by Work | Retired August 9, 2026 | Available | Rolling out on Pro and Business Premium, beta on Enterprise |
| Main control | Watch mode and confirmations | Logged-out mode | Approval prompts, admin switches | Custom Rules, auto-review, admin switches |
Sources: OpenAI, OpenAI Help Center, OpenAI, OpenAI Help Center, OpenAI Help Center, OpenAI, Value Add Pulse (Work launch date, secondary). Retrieved October 5, 2026.
What are ChatGPT Dots?
A dot is "an always-on agent in ChatGPT that can take on ongoing responsibility and keep making progress between conversations," according to OpenAI. It has its own cloud computer and browser, remembers context, and works through apps you connect (OpenAI Help Center, 2026).
OpenAI uses the word "always-on," not "24/7." We found no stated uptime guarantee, so treat round-the-clock operation as the design intent.
Availability, pricing and limits
Dots are rolling out to Pro and Business Premium subscribers in eligible markets. Pro users in the European Economic Area, Switzerland and the UK are excluded for now, while Business Premium is available in all supported regions. Enterprise, Edu and Healthcare workspaces get a beta when the admin turns it on (OpenAI Help Center, 2026).
The first dot is included at no extra cost, with extended limits for the first month after launch. OpenAI plans paid options for more dots and more capacity but has not published prices. Business Premium seats cost $100 per user per month billed annually, or $125 billed monthly (OpenAI, 2026). Standard Business seats are not named among the eligible plans. Conversations with dots do not count toward ChatGPT usage limits, OpenAI says (OpenAI, 2026). We found no published permanent allowance for the work a dot does on its own, so budget for the limits to change after the first month.
Apps and connectors
According to OpenAI (2026), Dots "can readily connect to over 4,000 apps." Users choose which apps a dot can reach and manage permissions through existing ChatGPT app controls. In Enterprise workspaces, "enabling dots does not grant access to every app or website" (OpenAI Help Center, 2026). The 4,000 figure is vendor-reported and counts what is available, not what any one workspace allows.
From ChatGPT agent to Dots: how agent security evolved
The ChatGPT agent security model has shifted from a human approving each step to rules that decide in advance. Each generation gave the agent more autonomy and more access, and each replaced some manual review with automated checks.
| Stage | What the agent could do | How OpenAI controlled it |
|---|---|---|
| ChatGPT agent (July 2025) | Use its own virtual computer, browse, run code | Watch mode, confirmation before real-world actions, takeover mode for logins |
| Atlas agent mode (October 2025) | Act inside the user's browser session | Cannot run code or access the file system, pauses on sensitive sites, logged-out mode |
| ChatGPT Work (2026) | Multi-step tasks in cloud or locally | Approval prompts, separate browser and network controls |
| Dots (September 2026) | Persist, remember, act through connected apps | Custom Rules, auto-review, mandatory hand-offs, monitoring |
Sources: OpenAI, OpenAI, OpenAI Help Center, OpenAI.
2025: supervised agents
OpenAI launched ChatGPT agent on July 17, 2025, calling it the first time users could ask ChatGPT to act on the web. That meant the agent could work with data through connectors and logged-in sites (OpenAI, 2025). Atlas followed on October 21, 2025, with OpenAI warning that its "safeguards will not stop every attack" (OpenAI, 2025).
2026: Work, and the end of Atlas
OpenAI's help center now says the ChatGPT agent "is no longer available" and points to ChatGPT Work (OpenAI Help Center, 2026). Work is "an agent designed for longer, multi-step work and finished deliverables" with cloud and local modes. OpenAI announced Atlas retirement on July 9 and ended it on August 9, 2026, noting that a discontinued browser "may degrade or stop receiving security updates" (OpenAI Help Center, 2026). For how Atlas and Work compare with rival tools, see our Perplexity vs ChatGPT guide.
Why Dots are a different security object
A supervised session ends when you close it. A dot does not. It keeps memory, holds app permissions and can act on schedules. OpenAI's enterprise pitch goes further. Companies set up each specialist dot with "its own identity, credentials, and access to the systems it needs," starting with focused enterprise pilots (OpenAI, 2026). OpenAI's early testing covered procurement, invoice processing, email marketing, customer support and commercial contracting. Microsoft plans to add governance for specialist dots through Agent 365, which is a stated objective, not a launched feature (SiliconANGLE, 2026). That is closer to a service account than a chat feature.
How the Dots permission model works
OpenAI's design has four layers: Custom Rules, auto-review, mandatory hand-offs and monitoring. Together they decide what a dot may do without asking. They are vendor-described, and we did not test them.
| Layer | What OpenAI says | What to verify |
|---|---|---|
| Custom Rules | Per action: take action without asking, if pre-approved, ask first, or hand off. Built-in safety requirements always apply | Who sets rules, members or admins, and whether defaults suit your risk |
| Auto-review | A separate safety system checks planned steps against your instructions, Custom Rules and safety requirements | It is OpenAI's own system reviewing OpenAI's agent, so test it independently |
| Mandatory hand-offs | Password changes, money transfers between accounts, permanent deletion, unrecognized software and new security-sensitive access | Whether your own high-risk actions are on the list |
| Monitoring | OpenAI monitors for "acting outside your instructions" and can pause or stop a dot | Who is notified, and how fast |
Sources: OpenAI Help Center, OpenAI, 2026.
If auto-review blocks an action, OpenAI says it prevents the action and tells the dot why. It also says these controls sit outside the environments dots can change, so a dot cannot switch off a required check.
Two details matter for credentials. Dots can sign in to supported sites "without exposing" saved passwords to the model, but this does not cover passwords you pasted into a chat or document (OpenAI Help Center, 2026). And access to your own computer "starts turned off," while Enterprise admins also keep it off by default.
A third-party analysis from RedactSure makes a fair point. Custom Rules govern what a dot may do, not which fields reach its model. A connected CRM or finance system still shows the dot the whole record (RedactSure, 2026). That analysis relied on OpenAI's documentation, not hands-on testing.
The new risk surface of always-on agents
According to Gartner (2026), the high-risk mix is access to sensitive data, exposure to untrusted content and external communication. Always-on agents combine all three. A single injected instruction can then travel from an inbox to an outbound action without a person in the loop.
Indirect prompt injection (OWASP LLM01)
According to OWASP (2025), indirect prompt injection arrives through external sources such as websites and files. Its mitigations include least privilege and human approval for privileged operations. OpenAI agrees on the limits. In December 2025 it wrote that prompt injection "is unlikely to ever be fully 'solved'" (OpenAI, 2025).
The numbers improved but did not reach zero. OpenAI reports a 99.79% defender success rate for GPT-6 Astra on its internal indirect injection tests, against 96.23% for GPT-5.6 Sol. On Gray Swan's external IPI Arena, with 1,810 attacks and up to 15 attempts each, Astra's estimated attack success rate with safeguards was 8.5%, against 27.0% for GPT-5.6 Sol (OpenAI, 2026). These are vendor-reported model results, not tests of Dots. For model-level cyber capability, see our GPT-6 Astra CISO guide.
Excessive agency and credentials (OWASP LLM06)
According to OWASP (2025), excessive agency means damaging actions performed in response to "unexpected, ambiguous or manipulated outputs" from an LLM, caused by excess functionality, permissions or autonomy. Dots touch all three. A specialist dot with its own credentials and a Custom Rule set to act without asking has the autonomy and the permissions. Wiz researcher Rami McCarthy framed it as "autonomy multiplied by access" (TechCrunch, 2025).
Persistence and memory
Persistence turns a one-off injection into a standing one. According to Radware (2026), its ZombieAgent research showed attackers planting rules in ChatGPT's Memory so it "always: reads Memory, executes the attacker's leakage step, only then responds to the user." OpenAI fixed it on December 16, 2025, before public disclosure on January 8, 2026. Dots add their own memory, and OpenAI says users currently cannot view, delete or edit individual dot memories (OpenAI Help Center, 2026).
Data exfiltration and sandbox boundaries
| Date | Target | Finding | Outcome |
|---|---|---|---|
| Jun to Sep 2025 | ChatGPT Deep Research | Radware's ShadowLeak: zero-click Gmail data theft via hidden email instructions | Reported June 18, fixed early August, patched before disclosure on September 3 |
| Sep 2025 to Jan 2026 | ChatGPT connectors and Memory | Radware's ZombieAgent: exfiltration and persistence | Reported September 26, fixed December 16, disclosed January 8 |
| Oct 24, 2025 | Atlas | NeuralTrust researchers showed prompts disguised as URLs in the omnibox | No OpenAI response in the coverage we read |
| Sep 9, 2026 | ChatGPT code execution | Check Point found a hidden cross-account channel reaching connected apps | OpenAI confirmed and decommissioned the internal service |
| Sep 25, 2026 | OpenAI internal research agents | 53 user images posted to image-hosting sites | OpenAI called it "not an appropriate use of this data" |
Sources: The Record, Radware, SecurityWeek, CSO Online, TechCrunch.
The last row involved internal research agents, not a ChatGPT product, and TechCrunch attributes it to network access gaps. It still shows what happens when agents can reach the open internet. We found no public vulnerability report specific to Dots as of October 5, 2026, six days after launch.
Shadow agents
Personal Pro plans sit outside workspace settings, so an employee can connect a dot to work apps without an admin seeing it. A Cloud Security Alliance survey sponsored by Zenity (April 15, 2026) found 54% of organizations had 1 to 100 unsanctioned AI agents. It also found 47% had a security incident involving an agent (Cloud Security Alliance, 2026). That is a vendor-sponsored survey, so read it as directional.
Enterprise controls for Dots: what exists and what is missing
Admins get meaningful switches, all defaulting to off or restricted. The gaps are in residency, audit coverage and visibility into what a dot remembers. Several are labeled beta limits by OpenAI, so recheck them before rollout.
| Area | Available | Gap or open question |
|---|---|---|
| Access | "Use dots (Beta)" is off by default for Enterprise | Enterprise model settings do not apply to dots |
| Local computer | "Allow local computer access" is off by default | Unavailable where Codex or Work policies target specific operating systems |
| Cloud computer | Separate controls for browser, network, desktop use and password manager | Cloud computers do not automatically inherit member VPNs or device policies |
| Apps | Plugin controls decide which apps are reachable | Members connect apps they already use, so scope needs review |
| Residency | None in beta | Dots do not support data residency or inference residency; FedRAMP and EKM workspaces are excluded |
| Audit | Compliance API for supported cloud records | OpenAI does not list which orchestration events count as supported |
| Messaging | Slack and Teams, if the admin allows | Phone messaging is unavailable for Enterprise |
Sources: OpenAI Help Center, OpenAI.
Messaging channels deserve their own review. When allowed, dots join Slack and Teams with their own identity. In our assessment, anyone who can write in a channel a dot reads can put text in front of it, and the pages we read do not say who may instruct a dot in a shared channel.
Logging and retention
OpenAI's local-access guide says to use the Compliance API for supported cloud records. It warns that audit tools do not cover "every internal subagent path." Beri's analysis of the same guide reports that cloud orchestration events do not reach an existing OpenTelemetry collector (Beri, 2026). A dot retains context "for as long as you keep your dot," and files and conversations it created are stored separately. OpenAI says it does not train directly on proactive research or a dot's notes to itself (OpenAI, 2026).
The related ChatGPT Work cloud page adds that endpoint monitoring "can't inspect actions inside the hosted execution environment" and that zero data retention is not provided (OpenAI, 2026). That page covers Work, not Dots specifically, but the two share cloud infrastructure in OpenAI's own guide. We found no Dots-specific compliance certification statement on the pages we read.
How we compared
We did not test Dots. We read OpenAI's launch post, help center and enterprise documentation, plus named security research and press reports, between September 29 and October 5, 2026. Pages for a six-day-old beta change often, so recheck admin settings and limits on the day you roll out.
ChatGPT agent security checklist for enterprises
Use this checklist before enabling Dots for any group. It maps OpenAI's controls to the OWASP risks above and shows what to add yourself.
| # | Control | Why it matters | How to apply it |
|---|---|---|---|
| 1 | Pilot group only | Beta, six days old | Enable "Use dots (Beta)" for a named group |
| 2 | Keep local access off | Removes file and command reach | Leave "Allow local computer access" off |
| 3 | Restrict cloud network | Limits exfiltration paths | Decide browser, network and desktop use separately |
| 4 | Least-privilege apps | LLM06 excess permissions | Read-only scopes and dedicated accounts |
| 5 | Review Custom Rules | Autonomy is set per action | Require "ask first" for sends, purchases, deletions |
| 6 | Treat passwords separately | Protection covers supported sign-in only | Restrict the password manager for high-value systems |
| 7 | Exclude regulated data | No residency, FedRAMP or EKM support | Block those workloads from Dots |
| 8 | Add your own logging | Compliance API coverage is undefined | Log tool calls outside OpenAI's cloud |
| 9 | Plan for memory | Cannot view or edit memories | Reset dots on role change, avoid sensitive sources |
| 10 | Inventory every agent | Shadow agents on personal plans | Record owner, apps and permissions per dot |
| 11 | Red team before launch | OpenAI says injection is not eliminated | Plant test injections in connected inboxes and docs |
Security and governance: how NeuralTrust addresses always-on agents
Dots run on OpenAI's infrastructure, so you cannot install a runtime agent inside them. What you can control is what they reach: the tools, MCP servers and APIs behind connectors, the identities they use and the evidence you keep. NeuralTrust works at that layer, as the Runtime Security Mesh across your agents.
Agent Gateway (TrustGate) enforces policy on the tool and API traffic that passes through it, and ships with 200+ pre-built MCP servers. Agent Runtime Security (TrustGuard) inspects prompts, tool calls and outputs for agents you operate. Agent Posture Management (TrustLens) discovers which agents hold which permissions, which is the inventory step in the checklist above. AI Red Teaming (TrustTest) lets you run your own injection tests before approval instead of relying on a vendor's numbers.
NeuralTrust holds four Gartner Hype Cycle 2026 recognitions in AI Runtime Defense. Learn more about AI agent security, Agent Posture Management and the AI Gateway. For how ChatGPT compares with Grok on security, see Grok vs ChatGPT.
Should you turn on Dots? A decision table
Decide by data sensitivity and by how well you can inventory and log what a dot does. The right answer today differs by role.
| If you are... | Recommendation | Why |
|---|---|---|
| A CISO in a regulated or residency-bound firm | Keep Dots off | No data residency, FedRAMP or EKM support in beta |
| A platform lead running a pilot | Enable for a small group | Off by default, admin toggles, easy to reverse |
| A team lead on Business Premium | Pilot with read-only apps | First dot is free, but Custom Rules are set per action |
| A security architect | Add external logging first | Compliance API coverage is undefined |
| An individual on a personal Pro plan | Do not connect work data | Outside workspace controls and audit |
Conclusion
ChatGPT agent security has moved from approving each step to governing a standing identity. Dots bring useful admin switches, hand-offs and monitoring, and OpenAI itself says protections reduce but do not eliminate injection. Treat each dot as a service account, pilot it behind least privilege, keep residency-bound data out and log outside the vendor.
Secure ChatGPT Dots and Always-On Agents in Production with NeuralTrust
Put policy, inventory and red teaming around every agent your teams adopt, whichever vendor runs it.
Related Comparisons
- GPT-6 Astra: Security Implications for CISOs
- Perplexity vs ChatGPT: 2026 Benchmark & Pricing
- Grok vs ChatGPT 2026: Benchmarks, Pricing, Security
- Claude vs ChatGPT (2026): Benchmarks, Pricing & Verdict
FAQs about ChatGPT Agent
1. What are ChatGPT Dots?
Dots are OpenAI's always-on agents in ChatGPT, launched September 29, 2026. Each runs on its own cloud computer with GPT-6 Astra, keeps memory and works through connected apps between conversations. OpenAI says they can connect to over 4,000 apps (OpenAI, 2026).
2. Is the ChatGPT agent still available?
OpenAI's help center says "ChatGPT agent is no longer available" and directs users to ChatGPT Work for longer, multi-step tasks. Dots are a separate, newer product for ongoing responsibilities (OpenAI Help Center, 2026).
3. Who can use Dots, and what do they cost?
Dots are available to Pro and Business Premium subscribers in eligible markets, with an admin-enabled beta for Enterprise, Edu and Healthcare. Pro users in the EEA, Switzerland and the UK are excluded. The first dot is included, and Business Premium costs $100 per user per month billed annually (OpenAI, 2026).
4. Are Dots safe for enterprise use?
OpenAI documents Custom Rules, auto-review, hand-offs and monitoring, but says protections "do not eliminate" malicious-instruction risk. The beta lacks data residency and has unclear audit coverage. Pilot with least privilege and external logging rather than treating the vendor controls as sufficient (OpenAI Help Center, 2026).
5. Can prompt injection against a ChatGPT agent be prevented?
Not completely. OpenAI wrote in December 2025 that prompt injection is "unlikely to ever be fully 'solved.'" The UK NCSC has said it "may never be totally mitigated." The goal is to limit access and impact (TechCrunch, 2025).
6. Do Dots really run 24/7?
OpenAI calls them "always-on" and says they keep making progress between conversations. It does not publish a 24/7 uptime commitment on the pages we read. Plan for continuous background activity, and set limits on what a dot may do unattended (OpenAI Help Center, 2026).
7. Can admins turn Dots off?
Yes. For Enterprise, "Use dots (Beta)" is off by default, and admins separately control local computer access, custom rules, Slack and Teams, and cloud browser, network, desktop and password manager use (OpenAI Help Center, 2026).
8. Does OpenAI train on Dots data?
On personal plans, the "Improve the model for everyone" setting controls it (OpenAI Help Center, 2026). For Business, Enterprise and Edu, OpenAI says workspace content is not used to improve its models by default (OpenAI, 2026).
About the Author
Roger Howroyd is Head of Global SEO and AI at NeuralTrust, where he leads the company's search strategy across SEO, AEO, GEO, and LLM optimization. He specializes in AI-powered search, content strategy, and SEM. Connect on LinkedIn.
NeuralTrust is the leading platform for securing and scaling AI agents. Named a Pioneer in the Gartner Emerging Market Quadrant for AI Application Security 2026, recognized across four Gartner Hype Cycle reports in 2026, and featured in the Gartner Market Guide for Guardian Agents 2026, the Gartner Market Guide for AI Gateways 2025 and the KuppingerCole Leadership Compass for Generative AI Defense 2025. Headquartered in Barcelona with offices in London and New York. ISO 27001 certified.
Sources
- OpenAI, Introducing dots, September 29, 2026.
- OpenAI Help Center, Manage dots in ChatGPT workspaces, 2026.
- OpenAI Help Center, Dots privacy, security and safety FAQs, 2026.
- OpenAI, Hardening ChatGPT Atlas against prompt injection, December 22, 2025.
- OpenAI, GPT-6 Astra system card, prompt injection, 2026.
- OpenAI, Local computer access for Work Cloud and dots, 2026.
- Gartner, Top predictions for IT organizations 2025 and beyond, October 22, 2024.
- OpenAI, Introducing ChatGPT agent, July 17, 2025.
- OpenAI Help Center, ChatGPT agent, 2026.
- OpenAI, Introducing ChatGPT Atlas, October 21, 2025.
)
)
)
)
)
)
)