\n\n\n\n Cute Blobs, Serious Plumbing — What OpenAI's Dots Actually Ship - AgntBox Cute Blobs, Serious Plumbing — What OpenAI's Dots Actually Ship - AgntBox \n

Cute Blobs, Serious Plumbing — What OpenAI’s Dots Actually Ship

📖 4 min read•797 words•Updated Sep 30, 2026

Dots are the most interesting thing OpenAI has shipped in a while, and almost none of that has to do with the blobs.

Let me back that up. At DevDay 2026 in San Francisco on Tuesday, OpenAI announced Dots — always-on agents that run in ChatGPT, take multi-step projects, crawl the web on your behalf, and chase goals across apps without you babysitting each step. They’re powered by GPT-6 Astra. They have their own cloud computers. They’re depicted as customizable blobs you can name and personalize. And they’re rolling out now to Pro and Business Premium users in eligible markets, with a beta for enterprise.

The blob thing is the part everyone will screenshot. It’s also the least important detail in the announcement. Skip past it and you find something more consequential: Dots plug into Microsoft’s enterprise governance and security controls in Agent 365, which means businesses can manage them with Microsoft tooling they already run.

Why the governance hookup matters more than the mascot

Every toolkit reviewer has watched this pattern play out. A vendor ships an autonomous agent, it demos beautifully, and then it dies in procurement because nobody can answer basic questions. Who authorized this thing to touch the CRM? What did it access at 3 a.m.? How do we revoke it across 4,000 seats without filing a ticket per user?

Agent 365 integration is OpenAI’s answer to that question, and it’s a pragmatic one. Rather than asking enterprises to adopt a parallel identity and policy system just for AI agents, Dots slot into the controls IT already administers. That’s not exciting to write about. It is the difference between a pilot and a deployment.

It also tells you who Dots are really for. Reuters framed the launch as an enterprise push and a shot at Meta, and that reading holds up. Consumer Pro users are getting access, sure. But you don’t build governance integration for people automating their grocery lists.

What “always-on” actually asks of you

Here’s where I get cautious, because “always-on” is a bigger ask than it sounds. An agent that only acts when prompted has a natural containment boundary: your attention. An agent that constantly crawls the web and pursues goals across apps does not. It’s working while you sleep, and every hour of unsupervised operation is an hour of decisions you didn’t review.

That’s not a reason to avoid it. It is a reason to be specific about scope before you turn one loose. The questions I’d want answered before assigning a Dot anything that matters:

  • What can it write to, versus only read? Research and monitoring are low-stakes. Sending email, updating records, or moving money are not.
  • What does the audit trail look like in practice, not in the marketing? Agent 365 suggests the hooks exist. Whether the logs are granular enough to reconstruct a bad decision is a different question.
  • How does it behave on web content that contains instructions? An agent that crawls the open web is an agent that will eventually read a page telling it to do something else. This is the failure mode I’d stress-test first.
  • What’s the stop button, and how fast is it?

OpenAI hasn’t given us enough public detail to answer these from the outside, and I’m not going to pretend otherwise. This is a launch-day read, not a verdict on the product.

The personality layer is doing real work

One more thought on the blobs, because I think dismissing them entirely is a mistake. OpenAI describes Dots as getting to know what matters to you. Giving an agent a face and a name sounds like fluff, but it solves a genuine interface problem: when software acts on its own, users need a mental model of what “it” is. A named entity you assigned a project to is easier to reason about than a background process. It also makes it easier to run several at once without losing track of which is doing what.

The risk is the flip side. Cute things get trusted faster than they’ve earned. A blob that feels like a helpful colleague is a blob you’re less likely to audit.

Where I land for now

If you’re on Pro or Business Premium and you have a research or monitoring task you’ve been putting off, this is worth a real trial. Give a Dot something with a clear finish line and low blast radius, then check its work carefully rather than skimming the summary.

If you’re an enterprise buyer, the Agent 365 story is the reason to take the beta seriously, and the reason to test permissions and logging before you test capability. The capability will demo fine. The controls are what determine whether this survives contact with your security team.

I’ll have a hands-on review once I’ve had time to break one properly.

🕒 Published:

🧰
Written by Jake Chen

Software reviewer and AI tool expert. Independently tests and benchmarks AI products. No sponsored reviews — ever.

Learn more →
Browse Topics: AI & Automation | Comparisons | Dev Tools | Infrastructure | Security & Monitoring
Scroll to Top