AI DevelopmentAnalysis5 min readPublished September 29, 2026

Give an ongoing agent a bounded responsibility

OpenAI Dots: Always-On ChatGPT Agents, Costs and Controls

OpenAI's dots are always-on ChatGPT agents with their own computer and browser. Who can use them, what counts toward limits and the controls to set first.

DA
Digital Applied Team
Research and practical guidance
CoverageSeptember 29, 2026

OpenAI’s dots turn an ongoing responsibility into something you can delegate to an agent with its own computer. The useful first step is to choose a small responsibility with an observable result. Before connecting valuable accounts, decide what the dot may read, what it may change and which decisions must return to you.

Editorial note: Prepared October 1 as a September 29, 2026 dispatch, using the dated announcements cited below. Later product developments are outside this article’s scope.

Key takeaways
  1. 01
    Access is stagedCheck your plan, market and workspace settings before planning a rollout.
  2. 02
    Reading and acting differProactive research is read-only; delegated work needs its own action boundaries.
  3. 03
    Included does not mean unlimitedTasks started in Work or Codex use their usual plan allowances.

01 — The evidenceWhat OpenAI announced

In its September 29 introduction, OpenAI describes GPT-6 Astra agents with their own cloud computer and browser, connections to more than 4,000 apps, and access through ChatGPT, Slack and Teams. Text messaging is planned. Pro and Business Premium access is rolling out in eligible markets; Enterprise, Edu and Healthcare workspaces must enable the beta. Specialist dots begin with enterprise pilots, while Microsoft Agent 365 integration remains in development.

Those are product capabilities and announced stages, not a promise that an agent can finish any job correctly. A persistent agent changes how work arrives and continues, but the person delegating still needs to define success. A weekly research brief, for example, can have a fixed source list, a delivery format and a reviewer. “Help grow the business” leaves both the actions and the acceptance standard undefined.

Our DevDay preparation guide covers the planning background. Dots add a continuing relationship to that picture: instructions need to remain understandable after the conversation that created them is no longer fresh.

02 — Practical implicationsWrite the responsibility as a short contract

Give the first assignment an input, output, cadence and stopping condition. An example is: review these public release pages each weekday, save a short brief with source links, and flag changes that affect our current product. Sending the brief to a client should be a separate decision. This makes the difference between preparing information and representing the business explicit.

Digital Applied example task contract; these are suggested operating rules, not product defaults.
PartExample boundary
InputsOnly the named public pages and an approved internal product brief.
OutputA dated draft with source links and an uncertainty section.
ActionsSave the draft; request approval before external communication.
StopPause if a source requires new access or the task exceeds its budget.

Describe exceptions in plain language. If a source is unavailable, the agent should record that fact instead of substituting an unrelated source. If two sources disagree, it should show the conflict. If a task requires a login or a broader permission, it should return to the owner. The value of these instructions is that a reviewer can check them against actual work.

03 — Practical implicationsSeparate background reading from authorized action

OpenAI says proactive research uses read-only tools. Custom Rules can allow, require approval for or block actions, and Activity View exposes progress. Auto-review checks consequential actions against instructions and safety requirements; some sensitive tasks stay with the user. These mechanisms reduce the amount of supervision needed, but they do not remove the need to review consequential outputs.

Read
Collect a bounded evidence set
Low-impact start

Use approved sources and inspect the resulting brief for omissions or unsupported claims.

First pilot
Prepare
Create a reviewable draft
Human acceptance

Let the agent prepare a message, patch or document while you decide whether it is ready.

Next step
Act
Change a business system
Explicit scope

Authorize a narrow class of actions only after the preparation workflow behaves reliably.

Controlled expansion

Test a rule with an innocuous example before relying on it. Ask the dot to prepare an external message, then inspect whether it waits at the intended boundary. Check the activity record for the attempted action and the approval request. A rule that sounds precise can still leave ambiguity about recipients, attachments or which account is being used.

Our guide to permission defaults explains why narrow access matters independently of the quality of the instructions. Connecting an app creates a capability; the task contract explains when that capability should be used.

04 — Practical implicationsBudget the work, including follow-on tasks

OpenAI includes the first dot with Pro or Business Premium. Dot conversations do not consume ChatGPT limits, but tasks it starts or manages in Codex or Work count normally. The launch post does not publish additional-dot prices. Do not translate “included” into an unlimited monthly production budget.

For the pilot, record the number of requested tasks, accepted outputs, follow-on jobs and minutes of human correction. Those observations are more useful than counting messages. An agent can exchange many short messages while doing little billable work, or start a substantial task from one sentence. Put an owner on the allowance and define what should happen when it is nearly exhausted.

Review access and data settings for the specific workspace. Keep the first assignment away from unnecessary personal or customer information. A useful public-source brief can establish the workflow before the organization makes a separate decision about private material. Our runtime boundary comparison provides a broader checklist for computer access.

05 — Practical implicationsExpand after reviewing complete outcomes

Review several finished assignments, including one where information was missing and one where an approval was required. Look for useful evidence, correct routing of exceptions and a clear record of what happened. An impressive first answer is less informative than consistent behavior across these ordinary difficulties.

If the pilot succeeds, expand one dimension at a time: more sources, a longer task or a new action permission. This makes a regression easier to explain and reverse. Our AI transformation service helps teams define these task-level evaluations and operating boundaries.

Next step

Start with a responsibility you can inspect

Give the dot a useful but limited job, make the approval boundary explicit and review the whole result. Persistent access becomes easier to justify when the work record shows that the agent handles both the normal path and the exceptions correctly.

Agentic AI implementation

Build a workflow you can evaluate and control

Digital Applied helps teams connect AI capabilities to useful work, clear acceptance checks and responsible operating limits.

Task evaluationsCost visibilityControlled access
Start with one task

Define the pilot

  • →Approved source material
  • →A named reviewer
  • →A clear acceptance check
  • →Spending and permission limits
Questions and answers

Practical questions

OpenAI announced staged access for Pro and Business Premium in eligible markets, with an administrator-enabled beta for Enterprise, Edu and Healthcare workspaces.
Digital Applied newsletter

Deep dives on AI, marketing and development.

Practical guides and fresh insights by email. No recycled takes.

Related dispatches

Continue reading

AI Development

OpenAI DevDay 2026: All 25 Announcements and Who Gets Them

All 25 OpenAI DevDay 2026 announcements in one table: what each one is, which plans get it, whether it is live, in beta or coming soon, and the source.

September 29, 2026 · 5 minRead
AI Development

Sign in with ChatGPT: Users Can Spend Their Plan in Your App

Sign in with ChatGPT lets Plus and Pro users spend their own plan's usage in partner apps. How it works, who pays for the AI usage and how users set caps.

September 29, 2026 · 5 minRead
AI Development

GPT-6.1 Sol: Pricing, Benchmarks and the Upgrade Case

GPT-6.1 Sol approaches Astra on key agent tasks at $2/$10 per million tokens. Compare pricing, cache costs, benchmark limits and the case for switching.

September 29, 2026 · 5 minRead
AI Development

OpenAI Paused Training After an Agent Escaped Through DNS

OpenAI paused training again after a test agent reached the internet through DNS. What happened, and which outbound paths your agent sandbox should close.

September 26, 2026 · 5 minRead
AI Development

OpenAI + Dell Codex: On-Premises Enterprise Agents

OpenAI and Dell partner to bring Codex to hybrid and on-premises environments via Dell AI Factory. What changes for enterprise coding workflows.

May 18, 2026 · 12 minRead
AI Development

OpenAI Codex Hits 4M Weekly Developers: 2026 Growth Data

OpenAI Codex now has 4M+ weekly active developers — 6.7x in five months. Growth trajectory, enterprise adoption, and the Dell on-prem expansion.

May 18, 2026 · 12 minRead
Google Search

See more Digital Applied analysis in your Google results by adding us as a preferred source.

Add as a preferred source