AI News Feed
Market watch
Products & Applications

OpenAI launches Dots as identity security becomes AI agents' control plane

OpenAI launched Dots, always-on ChatGPT agents with cloud computers, as identity security vendors push to govern AI agents.

The agents are powered by GPT-6 Astra, and each works from a cloud computer that users can open at any time to see what it is doing. More than 4,000 apps are reachable through OpenAI’s plugins, and with permission an agent can also work directly on its owner’s laptop. Users can message or call their agent in ChatGPT on desktop, web or mobile, or reach it in Slack and Teams. Context follows the agent between channels, so a project started in ChatGPT can be passed to a team in Slack without a fresh briefing. Agents send progress updates and questions back to their owners.

OpenAI has been using the agents internally. When a bug is reported in the company’s Slack, the agents start investigating right away, and new designs are turned into working apps while staff concentrate on customer feedback. One early tester outside the company had forgotten to bill a publication; when his agent noticed, it prepared the invoice and waited for his approval before sending it. When no task has been assigned, an agent looks for ways to help through what OpenAI calls proactive research. Its connections to the owner’s apps are read-only during that time, so it cannot send messages or change anything. Actions that could touch a user’s accounts or share information must first pass an auto-review check, and a monitoring system can pause or stop an agent over a safety concern. OpenAI tells users to review consequential work because the agents can still make mistakes.

OpenAI also previewed specialist agents that an employer provisions with their own identity and credentials for a single defined job. Procurement and invoice processing were among the jobs tested inside OpenAI. Customers start with focused pilots, in which OpenAI engineers help define what each agent is responsible for. Microsoft Corp. is working with OpenAI so specialist agents can be managed through governance and security controls in Agent 365. Dots puts OpenAI against Meta Platforms Inc., which released its Muse personal agent in the United States on Sept. 8. Like OpenAI’s agents, Muse runs on a dedicated computer in the cloud; Meta said most of what people use it for is free, with subscriptions sold to heavier users.

Dots began rolling out on Sept. 29 to ChatGPT Pro and Business Premium subscribers, and some accounts may wait several days for access. Pro subscribers in the European Economic Area, Switzerland and the United Kingdom are not included. Enterprise customers, including those on Edu and Healthcare plans, can try a beta once a workspace administrator switches it on. One agent comes with a Pro or Business Premium plan at no extra cost. OpenAI’s help documentation says agent usage will not count against plan allowances for the first month, with terms for each plan coming after that. Additional agents, and more speed or monthly capacity for existing ones, are planned for later at prices OpenAI has not disclosed.

The launch lands as identity security vendors argue that AI agents are becoming a central governance problem. SailPoint Technologies Inc.’s Navigate conference, scheduled for Oct. 5-8 in Austin, Texas, will carry the theme 'AI, secured.' Palo Alto Networks Inc.’s 2026 Identity Security Landscape report found that organizations now manage an average of 109 machine identities for every human identity, and companies expect AI agent identities to grow 85% over the next 12 months. The same research found that more than half of organizations cannot consistently enforce least-privilege access for service accounts across cloud, software-as-a-service and on-premises systems.

SailPoint’s own research found that 97% of AI agents have access to sensitive data, while only 21% of organizations are highly confident they can manage AI agent security risks. On SailPoint’s most recent earnings call, management described a proof-of-concept at a Fortune 500 company that uncovered more than 10,000 previously unknown AI agents and thousands of related risks. Shadow IT took years to spread, while shadow agents are spreading in months, according to the report. A recent ZK Research data point found that almost half of AI use is on mobile devices, most of which information technology cannot see.

Much industry work on agent security has focused on containment: sandboxes, secure runtimes, guardrails and increasingly hardware enforcement. Those controls are essential, but they do not answer basic governance questions, according to the report. A sandbox can prevent an agent from reaching the internet, but it cannot say who created the agent, whose authority it is acting under, or whether it should still exist. Identity systems are needed to tell who an agent is, who owns it, what it is entitled to and when that entitlement should end. Identity matters more for agents than for people because agents operate at machine speed, accumulate access, and undermine accountability. A human with excessive privileges might misuse them occasionally; an agent with excessive privileges can exercise them thousands of times an hour, and the Hugging Face incident this summer showed it can find paths no one anticipated. When a human account fails, there is a person to call. With agents, the owner is often unclear, credentials are shared, and logs point to a service account nobody remembers creating. SailPoint Chief Executive Mark McClain said on the earnings call that enterprises need to know what data each agent can access, which human is accountable for that access, and how to revoke it when necessary. Most companies cannot answer any of those questions today, according to the report.

SailPoint launched Agentic Fabric in May. It discovers AI agents and machine identities, maps each to a human owner and enforces real-time authorization. It became generally available in August as part of a broader SailPoint Identity Security solution that pairs it with Human Fabric, the evolution of its Identity Security Cloud, on the Atlas platform. Capabilities include endpoint and browser sensors that expose hidden agents, Model Context Protocol servers, inline redaction of personal data before it reaches large language models, and a centralized kill switch for rogue agents.