Definition
Dots are OpenAI's persistent agents for ongoing personal or organizational work. A dot maintains context, uses its own cloud computer and browser, and works through applications the user has connected. Authorized tasks can continue between conversations.
The launch identifies GPT-6 Astra as the underlying model. The dot is the deployed agent around that model, with execution environments, tools, stored context, and action controls.
Origin and attribution
OpenAI introduced dots on September 29, 2026. The company announcement documents the product and credits OpenAI, without naming a sole creator.
The launch distinguishes a user's primary dot from specialist dots being piloted for defined organizational responsibilities. Specialist deployments can have their own identity, credentials, and systems access. Their pilot description does not mean every personal dot automatically has that enterprise configuration.
Background work and action review
OpenAI distinguishes ongoing tasks the user has authorized from proactive research that looks for useful developments independently. Proactive research uses read-only tools and saves private notes. Those tools cannot directly send messages, change connected application content, or control a browser or desktop. Follow-up action goes through the usual rules.
Auto-review checks certain planned actions against the user's instructions, Custom Rules, and mandatory requirements. Its enforcement runs outside the environments a dot can modify. Permission to connect an application, authorization for a particular task, and a successful action review have separate roles.
Memory, privacy, and limits
OpenAI's FAQ, reviewed October 7, distinguishes shared ChatGPT Memory from a dot's own context. Disabling Memory stops further sharing without deleting information already received. Disconnecting a plugin also stops new access without clearing retained context.
The FAQ says users currently cannot inspect, edit, or delete individual dot memories directly. Deleting a dot removes its own context; separately stored files, conversations, and ChatGPT memories have their own lifecycle. A request to forget something needs to identify which stores to correct or delete.
Business, Enterprise, and Edu data is excluded from model training by default. Personal-plan settings govern eligible conversations and work. Proactive research and its notes are not trained on directly, but material brought into an eligible task can become part of its training data, depending on settings.
OpenAI acknowledges mistakes and prompt-injection risk. Model safeguards, sandboxing, and review reduce risk without proving a task correct or making every completed action reversible.
Distinguish it from nearby terms
- A personal agent describes the general pattern; dots identify OpenAI's implementation.
- GPT-6 Astra is a model. A model API call does not inherit a dot's computer, memory, or approval state.
- Proactive research has a narrower tool boundary than authorized background execution. Running unattended does not expand permission.
- Muse and Grok Bot are separate products with different memory and execution arrangements.
Check your understanding
A dot notices an invoice in a connected inbox and drafts a reply. Does the background research permission cover sending it? What authorization and review would be needed, and what happens to the learned context if the inbox is later disconnected?