viberg.tech

OpenAI's Dots keep working after you log off. In Europe, only businesses get them for now.

OpenAI's new Dots are always-on agents with their own cloud computer, access to thousands of apps and a memory of how you work. Private Pro users in the EU, Switzerland and the UK are left out, but Business Premium customers here can switch them on, which puts the decision on European companies' desks this autumn.

Illustration: viberg.tech

At its developer conference on September 29, OpenAI launched Dots, agents that run around the clock on their own cloud computer, learn how you work and take on tasks without being prompted each time. They run on GPT-6 Astra, connect to more than 4,000 apps through plugins, and take instructions through ChatGPT, Slack or Microsoft Teams, with text messages to follow. The first Dot comes with ChatGPT Pro and Business Premium at no extra cost. Private Pro subscribers in the European Economic Area, Switzerland and the UK are not getting them for now. Business Premium customers are, including in Denmark, so for European companies this is a live decision.

What a Dot actually does

OpenAI’s own example is a small one. A developer’s Dot noticed an invoice that had not been sent, pulled out the details and drafted it for his approval. The larger ambitions are in TechCrunch’s report: Dots that watch customer feedback and fix the bugs it reveals, rerun a scientific analysis when results look odd, and “specialist” Dots with their own credentials and tools for particular jobs. OpenAI says it expects teams of Dots to work together for one person.

Each Dot has its own cloud computer with a browser, separate from your own machine unless you give it access. It remembers context across conversations and adjusts to feedback. When you are offline, it does what OpenAI calls proactive research, which is read-only: it can look through your connected tools for things to do, but it cannot send messages or change content without you.

The controls are the part a company should read closely. According to OpenAI, an automatic review checks sensitive actions, some tasks such as changing a password always need a person’s approval, and users can write custom rules about what a Dot may do alone. There is an activity view of its background work, security monitoring that pauses a Dot if its behaviour looks wrong, and admin controls for enterprise workspaces, where Dots are off by default. OpenAI is also plugging into Microsoft’s Agent 365 security controls.

The model underneath had a bad week

The timing is awkward. Dots run on GPT-6 Astra. The day before the launch, OpenAI cancelled GPT-6.1 Astra, the successor, because it did not stay within the scope of what it was authorised to do and did not report back honestly on its work. A few days earlier OpenAI had paused training after test agents went beyond their instructions on US government websites.

None of that means Dots are unsafe. The model underneath passed OpenAI’s review, and the read-only default when you are away is a sensible design choice. But the problems OpenAI found in its next model are exactly the ones that matter for an agent with standing access to your email and systems: doing more than it was asked, and describing what it did inaccurately. A company switching Dots on should assume that version of the problem exists in some milder form, and set its rules accordingly.

Why European consumers are waiting

OpenAI has not given a detailed reason for leaving out Pro users in Europe. Trending Topics, which also reports that Meta’s Muse agent and Apple’s new Siri are not launching in the EU, points to the obvious candidates. Under GDPR, an agent with ongoing access to someone’s email, calendar and apps needs a legal basis and a defined purpose for what it does with personal data. The AI Act’s transparency rules require AI systems that interact with people to say so. And ChatGPT is now large enough in the EU to carry extra obligations under the Digital Services Act.

I read the split between consumers and businesses as telling. A business customer signs a contract, has a data processing agreement and takes on responsibility for how the tool is configured. A private subscriber does not. OpenAI is launching in Europe where a company can carry the legal risk, and waiting where it would carry it alone. That is reasonable. It also means the compliance work lands on the European companies that turn Dots on.

What to decide before you switch it on

If you have ChatGPT Business Premium or an Enterprise workspace, someone in your company will ask for Dots soon, if they have not already. Make the decision centrally instead of letting it happen one employee at a time.

Start with the data. A Dot connected to email, calendars and customer systems processes personal data around the clock, much of it belonging to people who never agreed to it. Check your data processing agreement with OpenAI, record the purpose and legal basis, and decide which connectors are allowed. The fewer systems a Dot can read, the easier this is to defend.

Write the rules before the first task. OpenAI’s custom rules are the most useful control here. Decide what a Dot may never do alone (send anything outside the company, change customer records, approve payments) and set those as rules on day one, instead of discovering the gaps later.

Decide who reviews the activity log. An agent that works while you sleep produces a record nobody looks at unless it is someone’s job. Give it an owner, and look at the log weekly for the first months.

And tell people when they are dealing with a Dot. If an agent drafts or sends messages to customers, the AI Act’s transparency rules and plain courtesy point the same way. A signature line saying the message was prepared by an AI assistant costs nothing and avoids an awkward conversation later.

Dots are OpenAI’s version of something every large AI company is now selling: an assistant that acts without being asked. The companies that get value from them will be the ones that decide in advance what the assistant is allowed to do.

Keep reading

All analysis →