In brief: OpenAI is introducing Dots, persistent GPT-6 Astra agents that work between conversations. Personal Pro accounts in the EEA, Switzerland and the UK are excluded at launch. OpenAI's safety data shows substantial safeguards, but not flawless control across long task chains.
An agent with its own computer and persistent context
A dot can run several projects, use Slack and Teams, read connected apps, and operate tools on its cloud computer. Proactive research is restricted to read-only tools: it cannot send messages, change app content, or control a browser or computer. Follow-up actions return to the normal permission, confirmation and Auto-review rules.
The rollout differs by plan and region. Personal Pro accounts initially receive Dots only outside the EEA, Switzerland and the UK. Business Premium is included across supported ChatGPT regions; Enterprise, Edu and Healthcare begin with an admin-disabled beta. The first dot costs no extra, but its deeper-work allowance is unspecified. Dot conversations do not count against ChatGPT limits; delegated Work and Codex tasks do.
Disconnecting is not deletion
Disconnecting a plugin ends new access, but information already incorporated into the dot's context remains. Individual dot memories cannot be viewed, selectively modified or deleted. Removing them requires deleting the entire dot, while separately stored files, Codex threads and ChatGPT conversations may remain.
OpenAI's tests expose the weakness of long chains
In OpenAI's internal attack tests, 16,600 malicious emails across 100 long runs and 2,638 iteratively refined attempts produced no scored prompt-injection success. That is a strong vendor signal, not an independent replication. The system-card appendix also records moderate violations of intended task scope: the flag rate was 8.6 percent with five intervening tasks and 19.7 percent with ten. No severe breach or exfiltration occurred in that evaluation.
On a deliberately difficult workplace subset, the Dots harness showed a 0.84 percent severe-misalignment rate; OpenAI says it is not representative of production. Reuters also observed failed voice-update commands during the live demonstration. This separates a product launch from demonstrated everyday reliability.
Pandorex Analysis
Dots shifts agent risk from one click to long-term permission and context management. Auto-review, isolated computers and read-only research are meaningful controls. OpenAI's own series nevertheless shows scope boundaries blurring more often as task chains lengthen. This continues the development line around agentic misbehaviour and echoes the local access problem in Meta's Muse: the model matters, but so does whether access, memory and approvals remain auditable over time.
