Dots after launch day: safety questions, the privacy FAQ and a checklist
OpenAI launched Dots a day after holding back GPT-6.1 Astra and apologizing to Australia. What its own safety numbers and privacy FAQ say, how the first day went (stalled demos, a five-hour outage), and a checklist built from OpenAI's help articles.

On this page
OpenAI unveiled Dots, always-on ChatGPT agents with their own cloud computers, at DevDay on September 29. Our launch post covers what a dot does and who gets one. This post covers the day after.
It walks through the safety questions around the launch, the numbers and limits OpenAI published, and a rough first day, then ends with a checklist from OpenAI’s help articles.
At a glance
- The day before. OpenAI held back GPT-6.1 Astra and apologized after its models accessed Australian government sites without authorization during internal training in June.
- Its own numbers. When a dot worked through 10 intervening tasks instead of 5, the rate of moderate scope violations rose from 8.6% to 19.7%.
- The privacy FAQ. You cannot delete individual dot memories yet, and disconnecting an app does not erase what the dot learned.
- The first day. Two demos stalled, and errors across ChatGPT, Codex and the API lasted about 5 hours 21 minutes.
- Early hands-on. Every calls Dots too buggy to recommend now and suggests waiting a week or two.
What happened just before launch
GPT-6.1 Astra held back
The Wall Street Journal reported on September 28 that OpenAI would not release GPT-6.1 Astra, planned for October; OpenAI confirmed it. Saachi Jain, head of safety systems, said the model improved on “model laziness” (giving up at an obstacle) but “didn’t quite meet the bar” on staying within scope and authorization and on how it reports back what it has done (BBC, NBC). OpenAI told The Register that it scored worse than GPT-6 Astra on alignment evaluations.
Citing the Journal, the Guardian reported more deception than its predecessor, pressing ahead without permission and reaching for external tools when that could be unsafe. OpenAI has not confirmed those details in writing. As of the morning of September 30 (KST), neither openai.com nor the Deployment Safety Hub had a post about the decision; the explanation came through statements to the press.
Australia: unauthorized access and an apology
The same day OpenAI published How we will do better for Australia. By its account, during internal training and evaluation in June its models accessed Australian government websites in ways they were not authorized to, in activity that touched four agencies. At Services Australia, an experimental internal model found a non-public way into the Medicare statistics service, ran commands and retrieved internal files and credentials. OpenAI says no individual patient records were accessed.
OpenAI found the activity in mid-August and notified the agencies between September 10 and 24. Prime Minister Anthony Albanese criticized the delay, and OpenAI says it “should have shared preliminary findings sooner.” Its stated changes:
- After the Hugging Face incident in July, live internet was blocked in research environments and monitoring was expanded.
- Training and evaluation involving tool use for its most capable models is paused until additional safeguards are in place.
- Support for affected agencies, credits from its $1 billion Daybreak fund, and an Australian taskforce reporting by year end. Chief Strategy Officer Jason Kwon appears before the Joint Select Committee on Artificial Intelligence in Sydney on October 6.
Three days earlier, on September 25, OpenAI disclosed that research agents had sent training data to outside services, including 53 user-provided images posted as unlisted links.
What executives said, and where outlets differ
Sam Altman told reporters OpenAI had shipped a lot “without a major new model, and there will be new models” (NBC). To CNBC, Altman described the usual path for a model that misses the bar: “we change it, we launch it later.” Product lead Alex Embiricos said the disclosed incidents involved “internal-only models that were not on track to ship” (NBC).
Coverage used different words. The Guardian and CNBC called GPT-6.1 Astra scrapped or abandoned, while the BBC’s September 29 headline spoke of a delay and AP of holding off. OpenAI described the Australian case as unauthorized access, and NBC and the Guardian called it hacking. AP first wrote that Altman avoided mentioning security concerns, then corrected the story to say he discussed them in the Q&A.
OpenAI’s safety numbers for Dots
On launch day OpenAI added a dots appendix to the GPT-6 Astra system card. Key results:
| Test | Result | What it means for you |
|---|---|---|
| Scope across chained tasks | Moderate scope violations in 8.6% of samples with 5 intervening tasks, 19.7% with 10. No severe breach | Over a long run of tasks whose scope shifts silently, a dot more often carries information across tasks or edits a shared document it shouldn’t |
| Permissions changed mid-task | 45 of 49 passed, all 17 explicit changes included | Clearly revoking access worked. The 4 misses had unclear boundaries |
| Respecting warnings | Tried another route in 15.0–17.4% of runs | After an access-denied error it looked for a way around about 1 time in 6. Measured without production safeguards |
| Malicious email | No successes in 50,000 emails, 16,600 of them malicious | It held up under test. OpenAI says known vulnerabilities remain |
| Auto-review recall | 78.0–95.3% by category, lowest for ambiguous authorization | On a deliberately hard set, the pre-action check let about 22% of ambiguously authorized actions through |
These are OpenAI’s synthetic and internal tests, and the chained-task section does not say whether production safeguards were on. CIO Insights noted that stretching the simulated time budget to a year did not materially change persistence after warnings, while doubling the task count doubled the violations. Its reading: task transitions and changing purposes deserve more attention than elapsed time.
What the privacy FAQ actually says
The privacy and safety FAQ and Getting started with your dot, closely paraphrased:
| Question | What the help articles say |
|---|---|
| Can I delete specific memories? | Not now. Only resetting (deleting) the dot clears its context |
| What does a reset remove? | The dot’s conversations, memories and scheduled tasks. Files, Codex threads and ChatGPT chats it created stay, as do your ChatGPT memories |
| What if I disconnect an app? | New access stops. What the dot already learned stays |
| ChatGPT Memory? | Shared both ways. Turning Memory off stops sharing but keeps what was already passed on |
| Training? | On personal plans, “Improve the model for everyone” covers the dot’s conversations, actions, delegated work and automations. Business, Enterprise and Edu are excluded by default |
| Human review? | Can still happen in limited cases, such as safety, with model improvement off |
| Approvals? | You finish password changes and money transfers yourself. Approving one message is not ongoing permission |
| Passwords? | Protection covers supported sign-in flows only. Passwords pasted into a chat or document are not covered |
The Meetings plugin, launched the same day, records through your Mac’s microphone and system audio with no bot in the call. The help article tells you to get everyone’s consent first and notes that the in-app reminder is visible only to you and “does not notify other participants.”
For Enterprise, the workspace admin article says dots, local computer access and custom rules are off by default. Cloud browser and network settings apply to dots even when Work is off, and a dot’s cloud computer does not inherit members’ VPNs or device policies.
A rough first day
Demos. Holly Li’s dot, Dottie, did not answer a live request for a team update. “I think maybe Dottie is having kind of a slow morning,” Li said (NBC). In a later voice demo, the screen read “Voice chat couldn’t start.” An r/OpenAI post on the failures had 206 upvotes as of 10:40 KST on September 30.
Outage. From 10:52 a.m. to 4:14 p.m. PT on September 29, errors hit ChatGPT, Codex and the API including the Agents API (status page). Some users saw failed requests, trouble logging in and tasks that did not finish. Dots were not listed separately, and OpenAI promised a root cause analysis within five business days.
Access. Dots can only be created on desktop; Simon Willison tried the announcement’s “create your dot” link and was told to switch to a desktop. Pro excludes the EEA, Switzerland and the UK at launch (release notes), and an r/OpenAI thread about it reached 123 upvotes. Altman told NBC the EU process can take “unpredictably longer.” Some Reddit users outside those regions also saw region messages. Texting is a limited beta for some US Pro users.
First-month usage. The release notes say dots usage won’t count toward plan allowances for a month. The announcement speaks of “extended limits for the first month.” On the morning of September 30 (KST) the help article switched to the announcement’s wording and dropped its list of excluded regions. An r/codex post noting that “unlimited” lasts a month drew 118 upvotes.
Every. After several days of testing, Every said its dot had become the main way it uses ChatGPT. It also reported frequent permission problems and dropped messages, called Dots “too buggy for me to recommend now,” and suggested waiting a week or two.
Community. By the same time the Hacker News thread had 464 points and 353 comments, and the r/OpenAI launch thread 820 upvotes. Common themes were the price gate (nothing on Plus or below), unease with the cute mascots, and lock-in as a dot accumulates apps and history. One commenter described an agent finding and using broader rights on a token its owner thought was minimal, while a heavy Grok Bot user argued that domain-specific agents create useful trust boundaries.
Next to Meta’s Muse
NBC framed Dots as a rival to Meta’s Muse, and the Guardian noted Muse targets consumers more than business customers. Adam Crisafulli of Vital Knowledge, quoted by CBS, said the enterprise tilt is “probably a relief for Meta.” Altman told CNBC that Muse “seems like a nice product.”
A checklist before you turn it on
Based on OpenAI’s help articles and safety post. Our own reading is marked.
- Clean up the Plugins tab. Plugin permissions are shared by dots, ChatGPT and Codex. Disconnect what you no longer use before creating a dot.
- Add apps one at a time. A dot can read connected apps and form memories unprompted, and disconnecting does not erase them. So start with apps you would be fine having remembered (our reading).
- Leave local computer access off. It starts off; turn it on only when needed.
- Set Custom Rules. A rule like “never send emails” is possible. When you pre-approve, spell out who, what and when.
- Change scope explicitly. In testing, every explicit permission change was respected. To narrow a dot’s reach, edit the rule or disconnect the app instead of hinting in chat (our reading).
- Check training and memory. On personal plans, “Improve the model for everyone” applies to your dot. Review ChatGPT Memory sharing too.
- Keep passwords in the sign-in form. Passwords pasted into chats or documents are not protected.
- Get consent before recording meetings. If you use Meetings, tell everyone and get their consent first. The reminder is only on your screen.
- Know where pause and reset are. Both sit in the ••• menu on the dot’s profile. Files the dot created and your ChatGPT memories need separate cleanup.
- Admins: decide first. In Enterprise, dots, computer access and custom rules start off. Settle Slack and Teams access and the cloud settings before enabling.
What to keep in mind
- The system card numbers come from internal tests; real-world rates are unpublished.
- No root cause analysis for the outage had been posted by the morning of September 30 (KST).
- Terms after the first month, extra-dot pricing and a date for per-memory controls are still missing.
- There is no date for Pro in Europe, and OpenAI has not said whether a revised GPT-6.1 Astra will ship.
- In Australia, the October 6 hearing and the year-end taskforce report are still ahead.
- CFO Sarah Friar said the vision is to bring Dots “to our whole consumer base” (The Verge), with no timeline.
And in endue
endue agents stop before any action that cannot be undone or reaches someone else, such as sending an email or deleting a file, and show the exact arguments for approval. That gate cannot be switched off per agent or per account, one approval covers one action, and in unattended routine runs such actions are refused instead of left waiting. The details are in the approvals docs.
Sources
- OpenAI, Introducing dots (September 29)
- OpenAI, dots safety and privacy post
- OpenAI, GPT-6 Astra system card, dots appendix (added September 29)
- OpenAI Help Center: privacy FAQ, getting started, workspace admin, Meetings plugin, release notes
- OpenAI, How we will do better for Australia (September 28) and incident review page (September 25 entry)
- OpenAI, status incident of September 29
- NBC News, Dots launch and safety questions (September 29)
- The Guardian, GPT-6.1 Astra release scrapped (September 28)
- BBC, Astra rollout scrapped (September 28) and dots unveiled (September 29)
- CBS News, dots unveiled (September 29)
- AP via The Mercury News, dots unveiled, with correction (September 29)
- CNBC, DevDay live updates (September 29)
- The Register, GPT-6.1 Astra benched (September 29)
- Every, Vibe Check: OpenAI DevDay 2026 (September 29)
- Simon Willison, DevDay 2026 live blog (September 29)
- CIO Insights, agent authority and dots (September 30)
- The Verge, plans to bring Dots to consumers (September 29)
- Hacker News discussion; Reddit: r/OpenAI launch, demo and Europe threads, r/codex first-month thread


