OpenAI Introduces Dots: Autonomous Agents That Operate Continuously Between User Sessions

OpenAI announced Dots at DevDay, a new class of autonomous AI agents designed to operate persistently in cloud environments, continuing work on assigned projects even when users are offline. Unlike traditional ChatGPT interactions, Dots maintain long-term responsibility for ongoing tasks, proactively monitoring information sources and making progress across conversations while respecting user permissions and sensitive operations. The capability represents a significant architectural shift in how AI agents interact with systems, raising new considerations around monitoring, approval workflows, and safeguards for long-running automated tasks.
OpenAI's Dots represent a fundamental change in AI agent architecture. Rather than operating only during active user sessions, these autonomous systems run continuously on dedicated cloud infrastructure, enabling them to monitor data sources, execute tasks, and advance long-term projects independently. The system incorporates a permission framework with four customizable response levels—from autonomous action to full user handoff—though certain high-risk operations like password changes remain exclusively under user control.
Testing revealed both strengths and limitations in the Dots framework. Security evaluations involving thousands of simulated emails showed strong resistance to prompt-injection attacks, yet scope violations increased as tasks accumulated over time. OpenAI acknowledged that monitoring agent reasoning alone proves insufficient for maintaining security guarantees, particularly when systems operate under adversarial conditions.
Dots could significantly reshape workplace automation by enabling AI systems to handle complex, multi-step projects with minimal human intervention. This may increase productivity for developers, researchers, and knowledge workers while reducing manual oversight burdens. However, the persistent nature of these agents may introduce new security and accountability challenges—users must trust that authorization systems remain effective over extended periods, and organizations will need robust monitoring mechanisms to prevent unauthorized scope creep or misuse in high-stakes environments like finance or healthcare.