ChatGPT’s new dots are agents that keep working when you aren’t watching, with their own cloud computer and access to the apps you connect. OpenAI launched them at DevDay on September 29, 2026, rolling out to Pro users outside the EEA, Switzerland and the UK, to Business Premium, and as an admin-enabled beta on Enterprise. It also published detailed rules on what a dot may do alone. The short answer: a dot can research your connected apps with read-only tools and draft work for your review, some actions need your approval, and changing a password or moving money are steps you must complete yourself.
The short version
- Changing a password or transferring money always hands control back to you.
- Permanently deleting data or installing software may need your approval every time.
- When it works in the background, a dot’s research tools can’t send messages, edit app content or control a browser or computer.
- You currently can’t view, delete or edit individual dot memories; resetting or deleting the dot is the only way to clear them.
What a dot can do on its own, and what needs you
Every dot starts with built-in rules, and OpenAI’s privacy and safety FAQ sorts actions into tiers. An automatic check, which OpenAI calls auto-review, checks planned actions that could affect your accounts or share information against your instructions, custom rules and safety requirements before they run. It decides whether the action proceeds, needs your approval, or is a step you have to take yourself. OpenAI says dots have been instructed to follow these policies:
How dots handle different actions
| Action | What happens |
|---|---|
| Changing a password | You take over and do it |
| Transferring money | You take over and do it |
| Permanently deleting data | May need approval each time |
| Installing software | May need approval each time |
| Sending recurring messages | Can be approved in advance |
| Buying with a card saved on a shop’s site | Needs approval, possibly in advance |
| Researching your connected apps | Allowed, read-only |
Approval is narrow. Approving one message doesn’t let your dot keep contacting people, and asking it to draft replies doesn’t let it send them. OpenAI’s advice is to say who, what and when in any standing instruction. Before a dot sends an email, auto-review checks the recipient and message to help catch a wrong address or information you didn’t mean to share.
Custom rules: set your own limits for a dot
On top of the defaults, custom rules let you decide how your dot handles a specific kind of action. They sit under Settings → Personalization, in the Permissions section; on mobile, open Customize → Custom rules. For each rule you describe the action and pick one of four behaviors.
1 Take action without asking
The dot goes ahead without checking with you.
2 Take action when you say so
It proceeds when you explicitly request the action, and asks otherwise. OpenAI’s help center calls this option “Take action if pre-approved”.
3 Ask before taking action
It asks for your approval before taking the action.
4 Hand off to you
It asks you to take the action yourself.
Rules have limits of their own. They cover supported actions only, don’t grant access to an app or computer, and can’t turn off the built-in safety checks, override the password rule, or loosen the read-only limits on background research. If your workspace disables custom rules, saved rules stop applying. OpenAI also notes that a dot can make mistakes, including while following your rules.
What a dot remembers, and how to wipe it
A dot keeps context from your conversations and connected apps for as long as the dot exists. It shares memory both ways with ChatGPT: it receives your ChatGPT memories, and your chats with it can add to them. Turning off Memory in ChatGPT stops that sharing, but doesn’t delete what the dot has already received.
OpenAI’s memory controls are limited. It says you “currently cannot view, delete or directly modify individual dot memories”. Disconnecting an app stops new access but doesn’t remove what the dot already learned from it. The only way to clear a dot’s own context is to reset or delete the dot, which removes its conversations, saved memories and scheduled tasks. Files, Codex threads and ChatGPT chats it created are stored separately and stay.
Deleting doesn’t undo
Deleting a dot doesn’t reverse changes it already made in connected apps or recall messages it already sent. Pausing a dot stops its current main task, but it doesn’t stop every delegated task or cancel future scheduled runs, which you stop in Activity and Scheduled.
Passwords, sign-ins and training data
For supported sites, a dot pauses at the login screen while you type your password into a secure form. The password goes straight to the dot’s browser without being shown to the AI model. This doesn’t cover passwords you share separately in a chat or document, or through a plugin. A dot’s context doesn’t keep credentials, images or screenshots.
OpenAI doesn’t train on Business, Enterprise or Edu workspace data by default. On personal plans, the “Improve the model for everyone” setting decides whether a dot’s conversations and work can be used for training. OpenAI says it doesn’t train directly on a dot’s background research or private notes, though information from that research can be used if it enters an eligible conversation or task, depending on your settings. People associated with OpenAI may still review activity in limited cases, including safety, even with that setting off.
FAQs
Can a dot use my own computer?
Only if you connect it from the ChatGPT desktop app on that computer. Access is off by default and you can revoke it. Using your camera, microphone or screen also needs your device’s permission.
Are dots available to teenagers?
No. OpenAI says dots are not yet available to users under 18.
Can I text my dot?
OpenAI’s help center describes a limited texting beta for Pro users in the US only. Its launch post still lists texting as coming soon.
Related







Leave a Reply