OpenAI says Dots are rolling out gradually to eligible Pro and Business Premium subscribers aged 18 and older. Pro access initially excludes the European Economic Area, Switzerland, and the United Kingdom. Availability is consequently narrower than ChatGPT’s overall subscriber base, and eligibility does not mean every qualifying account receives access immediately.
Enterprise access is being offered as a beta and is disabled by default. That gives workspace administrators a role in deciding whether employees can use the service. Individuals create their agent through the ChatGPT desktop application or desktop web, rather than beginning the setup process on a mobile device.
The release notes also describe a temporary usage arrangement: Dots usage will not count toward eligible Pro, Business, and Enterprise users’ plan allowances during the month following launch. OpenAI says it will provide plan-specific usage terms afterward. This leaves customers awaiting further detail about the ongoing allowance arrangements once the introductory period ends.
OpenAI’s safety documentation sets limits on the financial actions agents can perform. Dots may make purchases using cards already saved on a merchant’s website, but those purchases require approval. Transferring money between financial accounts requires the user to take over and complete the sensitive step, even when an agent assists with surrounding work.
Other consequential actions have separate controls. Permanently deleting data, running software from an unrecognized source, or granting new security-sensitive access requires confirmation each time. Before actions such as sending an email or changing a file, a separate system called Auto-review checks the proposed step against the user’s instructions, custom rules, and mandatory safety requirements.
Background research has narrower permissions. Its tools can read authorized connected sources and save notes, but cannot directly message other people, modify application content, or operate a browser or desktop. Any subsequent action must pass the normal checks. OpenAI acknowledges that these safeguards reduce risk without preventing every mistake, including errors that could expose information or affect a user’s work.
The company explains that disconnecting an application stops new access through that connection. It does not erase information an agent has already incorporated into its context. Similarly, switching off ChatGPT Memory stops memory sharing but does not remove information previously received by a Dot.
Users currently cannot inspect, delete, or directly edit individual Dot memories. Deleting the agent removes its own context, while files, ChatGPT conversations, and coding threads created elsewhere remain subject to separate storage arrangements. Information shared with ChatGPT Memory must also be managed through that service’s memory controls.
Data treatment differs between business and personal accounts. OpenAI says Business, Enterprise, and Edu workspace content is excluded from model training by default. Personal subscribers’ settings determine whether eligible conversations and work may be used. Background research is not used directly for training, although information drawn from it can become eligible when incorporated into another conversation or task.
Dots arrived within a wider package of more than 20 announcements at DevDay. OpenAI’s event recap also outlined ChatGPT Space, a shared environment where employees and agents can work with organizational knowledge. Pages, another announced feature, provides documents that people can develop collaboratively with AI.
The package extends into recurring work. OpenAI described team tasks for assignments such as scheduled project updates, with connected tools gathering information and acting on a schedule or in response to application events. These offerings place ongoing agents within a broader collection of workplace services, rather than presenting Dots as an isolated application.