On September 29, 2026, OpenAI dropped Dots during its DevDay keynote. The press images show a small, cartoonish character that looks like it wandered out of a mid-2000s messaging app update. Ignore the aesthetic. The product underneath is a real architectural shift for people building software that needs to do things, not just answer questions.

What Dots actually is

Per TechCrunch and The Verge, Dots is a package of always-on agentic assistants running on GPT-6 Astra. TechCrunch frames it as a personal agentic assistant; The Verge calls it a suite. In practice, the distinction matters less than the operational model: each Dot gets its own dedicated cloud computer, accesses a web browser, and integrates with over 4,000 apps. That last number comes from The Verge and is the single most relevant spec for anyone evaluating whether this maps onto their existing toolchain.

You launch a Dot from ChatGPT. After that, you message it through Slack, Microsoft Teams, or a text-message-like interface inside ChatGPT on web, desktop, or mobile. The Verge reports voice-call interaction is also supported. The Slack and Teams integrations carry context across sessions, devices, and apps, so a Dot you've been working with in a channel can pick up where it left off in a private thread without you re-prompting the setup.

One practical detail that will matter for cost modeling: The Verge reports that conversations with a Dot do not count toward your ChatGPT usage limits.

The control stack, which is the actual story

Every agent product announcement ships with a capability list. For builders, the capability list is the least interesting part. What you need to know is: where does it run, what can it touch, and who gets to veto it?

Where it runs. Dots operate from their own cloud computer (per The Verge). TechCrunch describes Dots as operating independently of specific hardware or interface, but that phrasing is single-source and somewhat hand-wavy. What you can rely on is the dedicated cloud instance plus the app integrations. There's no local process you're babysitting.

What it can touch. 4,000+ app connectors. OpenAI is also integrating Dots with Microsoft's Agent 365 security controls, per TechCrunch. That's the enterprise-relevant hook: your security team gets a layer of policy enforcement on top of whatever the agent does through those connectors.

Who vetoes. This is the part The Verge details most clearly. Dots use an auto-review feature that checks actions against user-defined safety rules before executing. You can set rules that block specific actions or require explicit permission for sensitive operations. The Verge gives the example of a password change triggering a handoff to the human. Exactly which actions trigger handoffs by default, and how granular the rule configuration gets across enterprise deployments, isn't spelled out in either piece of coverage. That's a question to put in front of your security review before you roll this into a production workflow.

Current limits (i.e., what you can't do yet)

  • One Dot per user. The Verge is explicit: users are currently limited to creating one Dot. OpenAI has described future plans for multiple agents, specialist Dots with specific identities and credentials, and even teams of Dots coordinating on a shared task. None of that is available at launch.
  • Direct text messaging is "coming soon." TechCrunch says text-message support hasn't shipped yet; The Verge describes a text-message-like interface as part of the interaction surface. The discrepancy suggests the messaging surface may be partially available or in staged rollout. Don't write integration code against a text SMS endpoint until you confirm the exact API.
  • Enterprise access is not uniform across sources. The Verge includes Enterprise in the initial September 29 rollout. TechCrunch names only Pro and Business Premium. If you're an enterprise buyer, confirm your tier directly with OpenAI before planning migration timelines.
  • "Learns your preferences over time" is a stated goal, not a verified mechanism. OpenAI says Dots will adapt and act before you ask. Neither outlet provides detail on what data is stored, how long preferences persist, or what credential or permission boundaries apply across sessions. For a technical audience, that's a gap, not a feature.

The Muse comparison, handled carefully

Both TechCrunch and The Verge position Dots against Meta's Muse agent. TechCrunch notes the branding overlap; The Verge draws a direct competitive line. The Verge also references a reported incident in which Meta's Muse disclosed a user's address to a Facebook Marketplace buyer without the user's knowledge. OpenAI has not claimed Dots is safer than Muse. It has shipped an explicit auto-review and custom-rules system, which is a differentiator in mechanism, but "we have guardrails" is not the same as "ours work better." If you're making a build-vs-buy or vendor-selection call, test the permission model in your own environment rather than trusting the keynote slide.

What this means if you're building

Three things jump out for developers and technical founders:

  1. The unit of work is shifting from prompt to task. A Dot that persists across sessions, has its own cloud compute, and carries context through Slack channels isn't a chatbot with a longer context window. It's closer to a junior ops engineer with a laptop and a Slack DM. If your product has repetitive multi-step workflows—monitoring dashboards, triaging tickets, updating docs after a deploy—this is the category of work that maps onto an always-on agent rather than a one-shot API call.
  1. The app-integration layer is the moat, not the model. GPT-6 Astra is the brain. The 4,000-app connector surface and the Slack/Teams context carry-over are the hands. If you're evaluating whether to build your own agent stack or lean on this, the question isn't "is the model good enough" (you can already call GPT-6 Astra through other interfaces). The question is whether the connector surface and the cross-session context model save you enough engineering time to justify the dependency.
  1. The safety rules are the product for enterprise buyers. The auto-review system, the Agent 365 integration, and the custom permission rules are the parts that let a CISO sign off. If you're selling to enterprise, the buyer's question won't be "what can the agent do?" It will be "show me the rule that stops it from doing this specific thing in our environment." Build your demo around that answer.

What we still don't know

  • The exact criteria that trigger auto-review handoffs, and how configurable those thresholds are per enterprise tenant.
  • The data retention model: what credentials, session data, or app permissions persist between Dot sessions.
  • A concrete timeline for multiple Dots, specialist Dots, and team-of-Dots coordination.
  • Whether the 4,000+ app integrations include your specific stack, or whether custom connector development is in scope and what it looks like.

Hacker News picked up the announcement, which tells you the developer community is watching. But the thread is thin on functional detail, which is fair—the product is still rolling out. The next two weeks of hands-on posts will be more useful than the keynote.

Start with one workflow. Give a Dot a narrow, well-scoped task in a Slack channel. Set the auto-review rules so anything touching production credentials or customer data requires your explicit OK. Run it for a week. Then decide if the architecture fits your stack.