OpenAI unveils 'Dots' for Pro plans, always-on AI agents
Serge Bulaev
OpenAI is gradually releasing 'Dots', always-on AI agents for Pro users that can keep working after a chat ends, connect to apps, and use custom identities. Experts warn that these agents may bring new security and privacy risks, such as hidden agents or too much access to data. Competing products from Meta, Google, and Microsoft show that the market may focus more on how well these agents fit into other tools, not just on how smart they are. The first Dot is available at no extra cost for paid users, though some regions may not have access yet. Observers suggest more features might come soon as the rollout continues.

OpenAI has officially entered the race for persistent AI assistants with the launch of 'Dots,' a new class of always-on AI agents for Pro and Business Premium users. These agents are designed to operate continuously, maintaining context and working on tasks even after a user closes the chat window. While this new capability promises enhanced productivity, it also introduces significant security and governance challenges that organizations must address. The initial rollout is bundled with paid plans at no extra cost, though regional availability is currently limited.
What are OpenAI Dots and how do they work?
OpenAI's Dots are always-on AI agents designed to function continuously in the background, a significant evolution from traditional prompt-based assistants. Announced recently, each Dot runs on its own cloud computer powered by OpenAI's latest models. This allows it to maintain long-term context and complete tasks without constant user interaction.
OpenAI Dots are persistent, always-on AI agents available to Pro users that operate continuously in the background. They can perform tasks after a chat session ends, connect to external applications like calendars, and be accessed across platforms like Slack and Teams, offering a more autonomous user experience.
Key capabilities include:
- Persistent Operation: Agents keep working on tasks even when you are not actively in a chat.
- App Connectivity: Dots can be granted access to connected applications like calendars, files, and other third-party tools.
- Cross-Platform Access: The agents are available within ChatGPT, Slack, and Microsoft Teams, with SMS integration in testing.
- Customization: Users can assign a unique name and avatar to their primary Dot.
Enterprise Security and Governance Risks of Always-On Agents
The autonomy of always-on agents introduces a new frontier of security and privacy risks. The current threat landscape shows a clear shift from simple prompt exploits to more sophisticated attacks. Security researchers note that attackers are now targeting the AI supply chain, where a single compromised data source can turn a trusted agent into an internal threat.
Industry research highlights the scale of the challenge:
- Many enterprises report discovering unknown AI agents in their environments, according to security surveys.
- Concerns are widespread, with a significant number of security professionals worried about the impact of AI agents.
- Key vulnerabilities include over-privileged access to data, the potential for privilege escalation, and persistent credentials that complicate security audits.
How Dots Compares to the Competition
OpenAI's Dots enters a fiercely competitive market for persistent AI assistants. Major technology companies are pursuing different strategies to embed these always-on agents into their ecosystems.
| Company | Initiative | Positioning |
|---|---|---|
| Meta | AI Agents | Consumer-focused personal agents that operate across apps and devices. |
| Gemini Agents | Personal AI agents integrated with Google Workspace tools. | |
| Microsoft | Copilot Studio | An enterprise-focused "agentic layer" emphasizing identity management and orchestration. |
Meta has set benchmarks in consumer AI agents, while Google's Gemini targets both consumer and professional users. Microsoft, in contrast, is prioritizing enterprise governance infrastructure. OpenAI appears to be targeting the middle ground, combining consumer accessibility with key business integrations.
Key Takeaways for Adopting Always-On AI
Organizations looking to adopt Dots or competing agents must shift their security posture. Security experts recommend treating these agents as privileged machine identities rather than simple chat applications. This involves focusing on four key governance pillars:
- Visibility: Maintain a complete inventory of all agents, their owners, and their data access.
- Sensitive Data Controls: Implement data restrictions outside the agent, as prompt-based rules can be misinterpreted or bypassed.
- Behavioral Governance: Establish clear policies to define the boundaries of autonomous decision-making.
- Audit Trails: Ensure all agent actions are logged to meet regulatory and security requirements.
For current OpenAI Pro and Business Premium users, the first Dot is available at no extra cost, lowering the barrier for experimentation. However, access is not yet available in the European Economic Area, Switzerland, or the UK. Security teams should immediately establish admin enablement protocols and define the integration scope before connecting agents to production systems.