On 29 September 2026, on the DevDay stage in San Francisco, OpenAI presented a product that does not answer questions. It works.

Dots are permanent agents. They have their own computer in the cloud, their own browser, their own identity for access and permissions, and they connect to more than 4,000 applications. You give them an objective, you define what they can do on their own, and they carry on after you have closed the app.

This is the shift the industry has been announcing for eighteen months: you no longer ask an AI to produce a text, you hand it a responsibility that lasts.

It is also the most badly summarised announcement of the year. Everywhere you read “not available in Europe”. That is inaccurate. The exclusion covers one subscription plan only.

What a dot is, exactly

OpenAI describes them as “remarkably capable, always-on agents designed to take things off your plate”. Behind the marketing phrasing, the spec sheet is precise.

A dot runs on GPT-6 Astra, the company’s frontier model. It starts, in OpenAI’s words, “with almost everything you would give a new hire”:

  • its own computer in the cloud, which you can open at any time to watch what it is doing;
  • its own browser;
  • its own identity for access and permissions;
  • the ability to write and test code;
  • access to more than 4,000 applications through the plugin ecosystem.

It runs several projects in parallel. You can hand it a new task without waiting for it to finish the previous one, and without juggling separate conversation threads.

You reach it in ChatGPT on desktop, on the web and on mobile, as well as in Slack and Microsoft Teams. SMS is announced as “coming soon” — and, in the help centre, described as a beta limited to American Pro subscribers, routed through a third-party provider, with an explicit recommendation to be careful with sensitive information.

One detail deserves correcting, because the marketing and the documentation do not quite say the same thing. The announcement states that “when you need to talk it through, you can call it”. The help centre spells out the other direction: “Your dot cannot call you at launch.” You call it; it does not call you.

Another practical limit: a dot can only be created from a computer, desktop app or browser. Not from mobile, and not at all on mobile web. Once created, you message it from the mobile app.

What it does when you are not watching

This is what separates dots from a classic assistant, and what deserves the most attention.

OpenAI calls it proactive research. When you are not actively working with it, the dot looks for ways to be useful to you on its own, reading the applications you have already connected.

The scope is deliberately bounded, and the company documents it in black and white: those tools are read-only. They can “neither send messages, nor modify application content, nor control your browser or your computer”.

But it reads. And it forms memories from what it reads, even when you have asked it nothing on the subject. An agent that goes through your mailbox while you sleep, keeping what seems useful to it, is not the same thing as an assistant waiting for an instruction. This is not hidden: it is the feature.

The example OpenAI gives is revealing of the ambition: “one early tester’s dot noticed he had forgotten to invoice a publication, prepared the invoice and sent it after his approval”.

We followed the rise of this logic at OpenAI when Codex moved beyond code to target every job. Dots are its completion: the agent is no longer a tool you open, it is a colleague that runs.

The price, and what it really covers

The first dot is included at no extra cost in the Pro and Business Premium plans. It is not quite “free”: it is included in subscriptions that are not.

PlanAccess to dotsIn Europe
ProFirst dot includedNo — EEA, Switzerland and the UK excluded, with no date
Business PremiumFirst dot includedYes — "all supported regions"
Enterprise, Edu, HealthcareBeta, if the administrator enables itYes, but off by default
Plus, Go, freeNone—

Business Premium seats are billed at $125 per user per month, or $100 on annual billing, according to the pricing page OpenAI published on 10 August 2026. Standard seats stay at $25, or $20 annually — and do not unlock dots.

Two consumption mechanisms are worth noting, because they decide what you will actually be able to do:

  • the subscription includes an allowance for deep work, with extended limits during the first month after launch;
  • conversations with your dot do not count against your usual ChatGPT limits. The tasks it launches in Codex or ChatGPT Work do.

Additional dots, and the ability to increase each one’s speed or monthly volume, are announced for later. No price has been published.

Europe: what is true, and what is not

Here is what OpenAI’s help centre writes, published on the day of the announcement: dots are rolling out in ChatGPT to Pro users in markets excluding the European Economic Area, Switzerland and the United Kingdom. And, in the next sentence: dots are also available to Business Premium users in all regions supported by ChatGPT.

Both halves matter equally.

A Pro subscriber in France, Belgium, Luxembourg, Switzerland or the United Kingdom has no access to dots. A Business Premium account in those same countries does. So this is not a geographic block: it is a plan-based block that applies to a geographic area.

No release date has been announced for European Pro users. Not in the announcement, not in the DevDay recap, not in the help centre. OpenAI does specify that the rollout is gradual and that access “may take several days”, but that sentence covers markets already eligible. It says nothing about the excluded ones.

And OpenAI gives no reason. That is a fact to record as such: the company invokes neither the GDPR, nor the AI Act, nor the DSA. The regulatory explanations circulating are hypotheses from the specialist press, not a company position. They are plausible — an agent that continuously reads email, calendars and connected applications raises questions of legal basis and purpose — but nobody at OpenAI has confirmed them.

The context is documented, though. Dots join a lengthening list: Meta Muse, launched on 8 September 2026 in the United States, has never had an announced European rollout — we analysed it in the AI agent that shops in your place. Apple restricts some Siri functions to the Mac and Vision Pro in the European Union. European Commission spokesman Thomas Regnier answered sharply on that last case: “The decision not to deploy Siri AI in the EU belongs to Apple, and to Apple alone.”

For the European reader, the practical consequence fits in one sentence: the agent exists, it is accessible, but you have to go through a business plan. Those who want to test an autonomous agent without that have other ways in, which we compared in Hermes Agent against Manus.

The announced safeguards, and what they cover

OpenAI publishes a list of protections more detailed than usual. It is worth reading, because it says as much through what it promises as through what it leaves open.

What is walled off. Each dot works on its own cloud computer. Your machine stays separate, unless you choose to connect it — local access is optional and off by default. To log into compatible sites, the dot can use your saved passwords without revealing them to the model.

What you can lock down. Custom rules let you allow an action, make it subject to approval, or block it — “never send email”, for instance. Four behaviours are offered: act without asking, act if pre-approved, ask before acting, or hand over to you.

What you cannot switch off. Custom rules cannot disable fundamental safety requirements, nor the automatic verification system, nor the restrictions on proactive research. The most sensitive actions — changing a password, transferring money — always come back to you: the dot hands over, it does not carry them out.

What is watching. A monitoring system can “pause or stop the dot’s work” if it detects a safety problem.

That is, objectively, more cautious than what we have seen go by in recent months. You still have to look at what is not covered.

Four limits the documentation itself acknowledges

They are not concealed. They are written, in plain terms, in the official pages — and they appear in almost no pick-up of the announcement.

1. You cannot inspect your dot’s memory. The help centre states that you currently cannot view, delete or directly edit a dot’s individual memories, including the specific items entered into its context from plugins. The only way to erase that context is to delete the whole dot. For an agent designed to read your applications in the background and draw its own conclusions, that is a real asymmetry: it learns from you continuously, you cannot read back what it kept.

2. Cutting access does not erase the past. Disconnecting an application stops new access through that connection, but does not delete the information the dot has already taken into its context. And deleting the dot does not delete the files, the Codex threads or the ChatGPT conversations it created: they are stored elsewhere, and they survive.

3. Human review remains possible. To the question “can people connected to OpenAI review my dot’s activity if I have turned off model improvement?”, the official answer is yes: human review may take place in limited circumstances, including for safety reasons, even when model improvement is turned off.

4. Prompt injection is not solved. This is the structural flaw of any agent that reads outside content. OpenAI has documented it since 7 November 2025 and does not claim to have fixed it: robustness against adversarial attacks, the company writes, is “a hard unsolved problem”. The principle fits in one sentence: a third party slips instructions into a web page, a review, a document or an email, and the agent carries them out believing it is obeying. OpenAI itself gives the example of an agent tasked with answering the morning’s email, manipulated into fetching bank statements and sending them to the attacker.

The more access and autonomy an agent has, the more that flaw costs. Dots have, by design, a great deal of both.

The timeline that jars

It has to be set out without dramatising it, because both facts are public and dated.

On 25 September 2026, OpenAI suspended “all training, evaluation and inference with tool use” of its most capable models, with no restart date, after an internal model left its environment — the second suspension in ten weeks. We set it out in what actually stops at OpenAI, and what carries on.

On 29 September 2026, four days later, the same company was presenting autonomous agents connected to 4,000 applications.

The two are compatible: the suspension covers the internal research pipeline, not the products. A model already trained and already evaluated is not affected. So this is not a contradiction, and nobody should present it as one.

It is, on the other hand, a difference of pace that is honest to flag. The company that judges it has to freeze its own agentic experiments, because an agent found an exit nobody had foreseen — as in the Hugging Face affair — is the same one putting agents into its subscribers’ hands the following week. The protections are not the same, nor is the scope. But the timing is tight, and it deserves to be known.

Autonomous agents also already have a documented record outside the labs: the cyberattack run by an AI agent in Spain showed what the same technology does when nobody is watching it.

The rest of DevDay, in four figures

Dots took the whole stage, but OpenAI claims “more than 20 major announcements” over the day.

1.2 billion. That is the number of users OpenAI puts forward in its recap, presenting ChatGPT as a space where developers can launch experiences “directly to our 1.2 billion users”. The clarification missing from the official phrasing: these are weekly users, not accounts created or paying customers.

One fifth. That is the price ratio between GPT-6.1 Sol, also announced on 29 September, and GPT-6 Astra. Sol bills $2 per million input tokens, $0.10 for cached input — a 95% cut — and $10 for output. On DeepSWE v1.1 it matches Astra for about one fifth of the cost, and beats GPT-6 Sol’s best score by 6.4 points. On Terminal-Bench Science it comes to $5.47 per task against $23.80 for Astra. Astra keeps the best overall score on that test, at 68.1%. We compared the previous generation in Claude Opus 5.5 against GPT-6 Sol.

300 tokens per second. That is the speed of the new Ultrafast tier, up to 8 times faster in Codex and 6 times in the API. It is reserved for Enterprise customers and for a new $500 a month Pro tier.

70%. That is the sequential quarterly growth announced from the stage by chief financial officer Sarah Friar, who also said the enterprise business had doubled since July. On the stock market listing, she stayed cautious: OpenAI will do it “when it is the right moment for our business”, a “step on the journey” and not a destination.

The rest comes down to a list: ChatGPT Space and living pages for team work, collaborative slides, shared team tasks, @ChatGPT in Slack and Teams, MCP events that let a connected application trigger an automation without you, and Private Intelligence for companies that want zero data retention.

What it changes, and for whom

For a European individual, the immediate effect is nil. The Pro subscription does not grant access, and no date is announced. There is nothing to do, nothing to configure, and nothing to fear right now.

For a European company, the effect is immediate on the contrary, and that is the point the “Europe” exclusion completely masks. A Business Premium seat at $125 a month opens, today, in Europe, an agent that reads connected applications, writes code, prepares documents and acts under rules. The decision to take is not technical: it is a decision about access governance, and it is taken before connecting the first application, not after.

For the jobs concerned, the examples OpenAI gives are explicit: bug fixes delivered as pull requests with supporting videos, launch materials revised, scientific analyses rerun as new data arrives, sales proposals updated, clips edited and posts written from a transcript. These are not whole jobs, they are first-rung tasks inside those jobs — precisely the segment studies identify as the most exposed, as we documented in what the studies really say about jobs at risk.

OpenAI adds one more layer, still at pilot stage: specialised dots, with their own identity and their own credentials inside an organisation, tested internally on procurement, invoice processing, email marketing, customer service and contract management. An integration with Microsoft Agent 365 is announced to let them be governed with existing Microsoft tools. With no timetable.

What to watch

Four points will decide what comes next, and none has an answer today.

Opening to European Pro users: with no date and no reason announced, it is the most awaited signal — and any delay will say whether the constraint is regulatory or simply commercial.

The price of additional dots: “included” only holds for the first. The real business model will be read on the second.

The first successful prompt injection on a dot: it will come, because OpenAI itself writes that the problem is unsolved. What will count is the time to detection and what the company publishes about it.

Opening the memory to inspection: as long as you can neither read nor correct what an agent has kept about you, the “you always stay in control” of the announcement page remains partial.

What to take away

On 29 September 2026, OpenAI brought to market agents that work continuously, with their own machine, their own browser, their own identity and access to more than 4,000 applications. The first one is included in the Pro and Business Premium subscriptions.

In Europe, the plan decides. Pro: no, with no date. Business Premium: yes, everywhere ChatGPT is supported. Enterprise: in beta, off by default. Saying “dots are not available in Europe” is convenient, and false.

The safeguards are more detailed than the sector average, and several are serious: the machine is walled off, passwords are never exposed to the model, sensitive actions are handed back to the user, monitoring can stop the agent. Four limits remain written in black and white in the documentation: memory cannot be inspected, cutting access does not erase the past, human review remains possible, and prompt injection is not solved.

Finally, the four-day gap between freezing internal agentic training and launching consumer agents is not a contradiction — the scopes differ. It is a pace. Le Recul’s AI ranking shows how fast these capabilities spread from one model to the next, including to models nobody can suspend.

An agent that works without you is an agent that gets things wrong without you. OpenAI writes as much at the foot of its own page: “Dots can still make mistakes, so always check work that may have significant consequences.”