OpenAI Intros Dots, AI Agents that Continue Working Between User Conversations

OpenAI has introduced Dots, GPT-6 Astra-powered agents that run on their own cloud computers, using connected applications to carry on with assignments between conversations and incorporating users' feedback as they go.

OpenAI is also previewing specialist Dots for organizations, with separate identities and credentials for defined responsibilities. Those enterprise deployments are beginning with focused pilots. The company is working with Microsoft on integration with Agent 365's governance and security controls.

The broader ambition seems to be to make delegation last beyond a chat session. That change could reduce the need to repeatedly explain a project. It also makes supervision a continuing obligation: An instruction that was appropriate yesterday may no longer fit today's circumstances.

Access and Memory Have Different Lifecycles

One important distinction appears in OpenAI's privacy and safety FAQ. Disconnecting an application stops new access through that connection, but does not delete information already incorporated into a Dot's context.

Users currently cannot inspect or directly edit individual Dot memories. Deleting a Dot deletes its own context, while files and conversations it created remain separately stored. Plugin permissions are shared across Dots, ChatGPT, ChatGPT Work, and Codex.

For an organization, that creates two related governance questions: what an agent can retrieve now, and what it already knows. Revoking a connection addresses the first without necessarily resolving the second.

Background Work Has Boundaries

OpenAI's safety account distinguishes authorized tasks that continue in the background from unsolicited "proactive research." The latter uses tools restricted to reading permitted sources. Those research tasks cannot directly send messages, change connected application content, or control a browser or desktop. Any subsequent action must pass the usual rules and checks.

A separate system, Auto-review, checks certain planned actions against instructions and safety requirements. OpenAI says the agent cannot modify the controls enforcing those checks.

"Dots can still make mistakes," the company cautions.

Persistence Is Also a Testing Problem

OpenAI's Dots system-card appendix acknowledges that persistence and multi-agent systems are not new. Its evaluations examine how continuing work affects authorization boundaries.

In one test involving successive related tasks, moderate scope violations increased from 8.6% to 19.7% when the number of intervening tasks doubled from five to 10. Examples included carrying information between unrelated tasks or editing a shared document beyond the intended scope. The company reported no severe breaches or exfiltration in that evaluation.

These are controlled test results, not measured failure rates in customer deployments. They nevertheless identify a problem that a successful demonstration cannot settle: whether an agent keeps the right boundaries as its workload accumulates.

According to OpenAI's DevDay recap, Dots are available to Pro and Business Premium users in eligible markets. Enterprise, Edu, and Healthcare access is an administrator-enabled beta, off by default.

The operational question is how organizations will keep delegated authority current. A continuing assignment needs a human owner who can revise its scope and decide when to stop it. Otherwise, the convenience of leaving work with an agent can outlast the reason it was authorized.

For more information, go to the OpenAI site.

About the Author

John K. Waters is the editor in chief of a number of Converge360.com sites, with a focus on high-end development, AI and future tech. He's been writing about cutting-edge technologies and culture of Silicon Valley for more than two decades, and he's written more than a dozen books. He also co-scripted the documentary film Silicon Valley: A 100 Year Renaissance, which aired on PBS.  He can be reached at [email protected].

Featured

  • Neon blue security locks with a single red highlight

    With AI, Cybersecurity Focus Shifts from Finding Flaws to Fixing Them

    For decades, one of cybersecurity's biggest challenges has been finding vulnerabilities before attackers do. A growing number of security professionals now say artificial intelligence is changing that equation, shifting the focus from discovering flaws to fixing them quickly enough to prevent exploitation.

  • abstract smartphone translucent screen displaying AI interface

    Apple Unveils Redesigned Siri AI

    At its recent Worldwide Developers Conference, Apple announced Siri AI, a redesigned version of its voice assistant that Apple describes in its own announcement as "a profoundly more capable and personal assistant." The update is intended to make Siri more conversational, more context-aware, and more useful across iPhone, iPad, Mac, Apple Watch, and Vision Pro.

  • Blurred silhouettes of business people in a modern office with a glowing blue network overlay

    Open Secure AI Alliance Moving Under Linux Foundation

    Governance of the Open Secure AI Alliance has moved to the Linux Foundation, giving the initiative what the organizations describe as a neutral home for developing open source tools, shared standards and defensive practices. The Alliance was launched by NVIDIA in July to develop open security technologies for AI systems and agents.

  • Digital cloud security with protected data flow on a futuristic network background

    Security Researchers: Passkey Phishing Attacks Are Leading to Cloud Account Takeovers

    In an active social engineering campaign, cyber attackers are impersonating IT help desks and using fake passkey setup requests to compromise employee identities and gain access to enterprise cloud data.