What can OpenAI's always-on dots do—and when must they ask?
OpenAI's 29 September agent launch puts ongoing work and permission boundaries at the centre of its product pitch. The announcement establishes capabilities offered, not independently verified reliability.
Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern
At a glance
- 1Ongoing agents make the boundary between research and action more consequential.
- 2Launch eligibility varies by plan and geography.
Living evidence record
Impact record IAI-17IUQ9F
Evidence stage
Announced
Confidence
Supported
Reporting basis
Source analysis
Independent support
Not yet
Record status
Monitoring
Last checked
30 September 2026
Source trail
3 direct sources across 1 source type.
People impact
Documented in this record.
Uncertainty
Limits and next checks are explicit.
Stages describe the evidence available—not whether a technology is good or bad. See the public method.
Related-source reporting disclosure
This record analyses 3 linked source records around the same underlying development. The extra records add method, date or context, but they do not by themselves constitute independent replication of every performance claim or predicted outcome.
The launch and its boundaries
OpenAI introduced dots on 29 September 2026 as persistent agents powered by GPT-6 Astra, with their own cloud computer and access to connected applications. The company describes ongoing tasks, communication through ChatGPT, Slack and Teams, and a gradual rollout to eligible paid plans. Specialist enterprise agents are being piloted rather than offered as a demonstrated replacement for whole departments.
The geographic restriction matters to readers of this UK-based portal. The dated release notes say the Pro rollout initially excludes the UK, European Economic Area and Switzerland. Enterprise access is a beta controlled by workspace administrators. Product examples in a launch post do not establish that every user can obtain every feature, or that a workflow will finish reliably in their own applications.[1][3]
What permission means in an ongoing task
OpenAI says proactive research uses connected-app tools restricted to reading: it cannot send messages, change app content or operate a browser or computer in that mode. Actions with consequences are subject to rules and review. Users can define permissions, while some sensitive actions remain for them to complete. The provider also describes isolated workspaces, monitoring and protections around sign-ins. These are design claims, not published rates of successful prevention across all real-world situations.
Our analysis is that the distinction between investigating and acting will determine much of the product's value. An assistant researching an overdue invoice is handling a different responsibility from one sending that invoice, altering its amount or contacting a customer. A useful handover should make the proposed action and its destination visible. Otherwise, a user may agree to a broad goal without noticing the concrete commitment being made on their behalf.[1][2]
A practical test for a small organisation
A small team could begin with a reversible task: assemble a weekly account of public competitor announcements, retaining links and dates. Success would mean a correct, complete report delivered within an agreed interval, with uncertainty stated when access fails. The team should also record interruptions and the time spent checking the work. A polished summary is not enough if it leaves out the most consequential development or silently relies on old information.
Moving from research to operations requires a different test. Before an agent can update a customer record, the organisation should specify which fields it may change, how conflicting information is handled and who can undo a mistake. A useful trial includes incomplete requests and contradictory source material, because routine demonstrations tend to make the desired path obvious. These are proposed assessment steps, not findings that OpenAI's product has passed an external trial.
People, accountability and evidence still missing
The potential benefit for workers is less coordination and fewer repetitive follow-ups. The possible cost is an additional stream of approvals that demands attention without making the underlying decisions clearer. Managers should ask whether the tool reduces total effort after checking and correction, rather than counting how many actions it attempts. A system that frequently needs rescue can shift work around without reducing it, especially when only a few staff understand how its permissions operate.
The announcement does not provide a representative denominator of ordinary organisations using the product, nor an independent estimate of errors per completed workflow. Our assessment would improve with external studies reporting successful tasks, failed tasks, unauthorised actions and recovery time on the same basis. Results should distinguish countries and application environments where access differs. Until those data exist, the launch is a material change in the available product category, while its lasting effect on workplace productivity remains to be measured.
What this means for people
- Teams need understandable approvals and recoverable actions before delegating consequential work.
Global context
Launch access differs by geography; the dated Pro announcement excludes the UK, EEA and Switzerland.
What the evidence does not yet show
- Provider descriptions and selected examples are not independent effectiveness evidence.
- No representative real-world workflow error rate is established here.
What to watch next
- External trials measuring completed work, correction time and permission failures together.
Evidence trail
Sources used for this report
Links checked 30 September 2026
This report is labelled source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.
Continue the story
Related reporting
Technology
Does self-hosting keep an AI coding agent away from sensitive source code?
IBM has made a customer-managed version of its Bob development agent generally available, including supported air-gapped deployments. Local inference can keep code inside an approved environment, but the announcement does not prove that every integration, model or generated change is secure.
6 min · 2 sources
Technology
Meta’s Muse gains downloads while Amazon challenges its shopping access
A third-party estimate puts the agent at 2.8 million downloads in its first 12 days. Amazon says the service was not authorised to access its store, raising questions about consent and credentials.
6 min · 2 sources
Technology
What does beating a Stratego champion prove about AI under hidden information?
Ataraxos won 15 of 20 games against one of Stratego's most decorated players and transferred its methods to three other games. The peer-reviewed Nature paper shows a real advance in efficient game strategy—not that the system can already run negotiations, markets or military decisions.
6 min · 3 sources
Reader discussion
Add evidence, experience or a question
No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.
Published reader notes
0No published reader notes yet. You can start the evidence-led discussion above.
Prefer a private correction or response? Contact the newsroom.