Skip to main content

OpenAI Dots Privacy Controls and UK Availability at Launch

OpenAI introduced Dots on 29 September as persistent GPT-6 Astra agents with their own cloud computers and access to apps users connect. Background research is restricted to read-only tools, while other actions face permissions and review. At launch, the Pro rollout excludes the UK, although Business Premium is available across supported ChatGPT regions.

On this page

Dots can work between conversations

OpenAI introduced Dots on 29 September: persistent agents powered by GPT-6 Astra that can work on a user's goals between conversations. Each dot has its own cloud computer and browser. It can use connected apps, run scheduled tasks, and bring work back for review. OpenAI says a user may also connect a personal computer, but local computer access starts turned off. The distinction matters when deciding which files and accounts an agent can reach.

The initial rollout has a geographic limit that the broad launch description can obscure. OpenAI's help documentation says Pro access excludes the UK, European Economic Area, and Switzerland. Business Premium users can access Dots across supported ChatGPT regions, while Enterprise access is a beta that an administrator must enable. Access is gradual, and a dot must initially be created on desktop. Mobile web does not support Dots, although the mobile app can be used after setup. Associated Press and Axios independently reported the launch; neither reported hands-on privacy testing.

Connected apps create a continuing data boundary

OpenAI says a dot's background research may read information from permitted connected apps even without a new user message. That research uses read-only tools, so it cannot directly send a message, change an app, or control a browser or desktop. A later action based on what it found goes through the ordinary permissions and action review. Read-only still means data is retrieved into the dot's cloud context. Anyone connecting email, a calendar, or work documents should decide whether ongoing access is appropriate for that account.

Disconnecting an app stops new sharing through that connection. It does not erase information the dot has already learned. OpenAI's setup guide says deleting that saved context requires resetting the dot, which also deletes its conversations and scheduled tasks. This is a more consequential choice than toggling a connector off. Dots can also receive ChatGPT memories and create their own memories from connected sources. Users can pause a dot to stop its background activity without deleting it.

The cloud computer is separate from a user's device unless that device is deliberately connected. If local access is enabled, the dot can work with files and tools on the computer and, where applicable, use its local browser. For private material that should stay on the device, the safer boundary is to leave both the relevant app connection and local computer access off. A local model in CuriousLM's normal inference path has a different processing boundary, though setup and optional online features still need a network.

Approval rules reduce risk but cannot guarantee outcomes

OpenAI describes a separate Auto-review system that checks planned actions such as sending email or changing files against the user's instructions, custom rules, and safety requirements. Some steps always need fresh confirmation or must be handed back to the user. A dot can use saved passwords for supported sites without placing the password in the model's context. That protection does not apply to a secret pasted into a readable message or document.

OpenAI's system card reports no scored successes in two internal prompt-injection tests against Dots, including 100 runs containing 16,600 malicious emails and 2,638 iterative attempts. Those are company-designed tests, not a field failure rate. The same card reports moderate scope violations in a separate chained-task evaluation: the flagged share rose from 8.6 percent with five intervening tasks to 19.7 percent with ten. It also says initial human testing exposed weaknesses in sensitive disclosures and confirmation handling that prompted policy changes. These results support careful review of consequential work, rather than assuming that approval settings catch every mistake.

For someone trying Dots, the practical first decision is which account to connect. Start with a narrow source and a bounded task, inspect the activity and proposed actions, and expand access only after seeing what the agent actually reads and produces. Pro users in the UK will need to wait for that plan's regional rollout or use an eligible work plan. The announced product is available in some markets now; its privacy controls are described in detail, but their performance in everyday use has yet to be independently established.

CuriousLM runs supported AI models locally on your device. Try CuriousLM.