News analysis · Published

OpenAI Dots: Give Always-On Agents an Authority and Recovery Test

By the ELYMENT AI editorial team · Free to read

OpenAI launched Dots on 29 September 2026 as always-on agents that can keep working across projects, cloud computers and connected apps. OpenAI also describes Custom Rules, activity monitoring, separate action review and mandatory human handoffs for some sensitive tasks. For business leaders, availability is not the same as production readiness. Give one bounded workflow a 30-day test that proves authority limits, approval behaviour, evidence quality, recovery and a clean shutdown path before expanding access.

A polished silver agent sphere moves through an amber approval gate on a stone control deck, representing authority limits for always-on AI agents.
Original ELYMENT.AI editorial illustration.

What OpenAI launched with Dots

OpenAI says Dots are proactive assistants that can continue work between conversations, use their own cloud computer and browser, and operate through connected apps. They can be reached through ChatGPT, Slack and Teams, while specialist enterprise pilots are intended to use dedicated identities, credentials and systems access. The initial rollout covers eligible Pro, Business Premium and Enterprise users, with enterprise access controlled by workspace administrators.

The examples are broader than a scheduled chatbot. OpenAI describes agents that monitor product feedback, prepare tested fixes, revise launch materials when scope changes, update analysis as evidence arrives and maintain proposals as requirements evolve. Reuters reported that the live launch demonstrations also experienced voice-update failures, a useful reminder that capability and operating reliability need separate evidence.

Built-in controls do not replace buyer evidence

OpenAI’s published safeguards include isolated cloud workspaces, read-only tools for proactive research, app permissions, Custom Rules, Activity View and Auto-review before certain consequential actions. OpenAI says some actions need confirmation each time, while password changes and financial transfers require the user to take over. It also says prompt-injection protections reduce risk but do not eliminate it, and that Dots can still make mistakes.

Those controls are important, but a business still owns the workflow design. A vendor safeguard cannot decide which customer record an agent should touch, what evidence is sufficient to change a proposal, how quickly a mistaken edit must be reversed or who is accountable when work crosses departments. Production approval should depend on observed behaviour in your systems, not a feature list.

Run a 30-day authority and recovery test

Choose one reversible workflow with a named owner and a measurable baseline. Keep access narrow, then collect an evidence pack across five gates.

  • Authority: list every system, data class and action the agent may read, draft, change or never touch.
  • Approval: test whether each high-impact action stops for the right person, recipient, amount and context.
  • Evidence: require source links, before-and-after records and a clear reason for every material recommendation or change.
  • Recovery: rehearse wrong-recipient, wrong-file, stale-context and prompt-injection scenarios; measure detection, containment and reversal time.
  • Shutdown: prove that disabling the agent, disconnecting apps and rotating credentials stops new access without losing the audit trail.

What leaders should approve after the test

Approve expansion only when the workflow beats its baseline without widening authority by accident. Track completion quality, supervision time, blocked actions, incorrect actions, recovery time and exceptions per completed outcome. A fast agent that creates more review work or cannot explain its changes is not cheaper automation.

Version the agent’s rules, connections and acceptance tests together. Any new app, data source, recipient class or write permission should trigger targeted retesting. Keep irreversible actions and sensitive identity changes outside the agent until the evidence supports a deliberate exception. ELYMENT AI can help teams turn agent capability into governed workflows with visible ownership, approvals and proof before scale.

Sources

Continue learning

Frequently asked questions

What are OpenAI Dots?

Dots are OpenAI’s always-on agents. OpenAI says they can continue projects between conversations using a cloud computer, connected apps and channels including ChatGPT, Slack and Teams.

Can a Dot take actions without approval?

Some supported actions can proceed within the user’s instructions and Custom Rules. OpenAI says other actions require approval, and certain highly sensitive steps must be completed by the user.

How should a business pilot an always-on agent?

Start with one reversible workflow and test authority, approvals, evidence, recovery and shutdown. Expand access only after the agent meets measurable acceptance criteria.

Explore ELYMENT AI