This website uses cookies

Read our Privacy policy and Terms of use for more information.

Last week the ‘Editor's Pick’ segment included Microsoft's new Copilot, with its always-on Autopilot agent. The two weeks before that, Meta's Muse sat in our Curated Links as the consumer version of the same idea. Back on 1 September, our ‘Featured story’ was OpenAI and Anthropic pushing agents behind users' logins. When OpenAI used DevDay on 29 September to launch dots, the idea of a persistent agent was not entirely new. What made it interesting was where OpenAI put it, inside a $100-a-month ChatGPT plan that many project teams already use.

OpenAI describes a dot as an always-on agent with its own cloud computer and browser, powered by GPT-6 Astra, that keeps working towards your goals after you close the laptop. It can connect to over 4,000 apps, and you can reach it from ChatGPT, Slack or Teams. Your first dot is included at no extra cost on ChatGPT Pro and Business Premium. The Pro $100 tier is now the entry point, because OpenAI paused new sign-ups to the $200 plan on 10 September.

That makes three vendors in a month selling a cloud-hosted agent that can work across a project inbox, document store, and Teams channels overnight. For a PM, QS or contractor, the question has moved on from whether these things exist to what rules you set before one reads a live tender or a cost report.

What a dot actually does

A dot runs on its own Linux machine in OpenAI's cloud with its own Chrome browser. It connects to the apps you have already authorised in ChatGPT and, if you choose, to your own computer. You can open its computer at any time to inspect what it is doing, and an Activity View in the desktop app lists ongoing and delegated tasks.

The part that matters for a delivery team is 'proactive research'. When you are not talking to it, a dot looks through connected apps for ways to help, and can form memories from what it finds, even when you have not asked a question. OpenAI says these background tasks use read-only tools that cannot send messages, change app content or control a browser, and any follow-up action goes through the normal rules. It still means a dot connected to your project email will be reading that email on its own schedule.

Ethan Mollick, a professor at the Wharton School, has been running dots and Muse side by side and thinks the capability list is the wrong lens.

❝

It is tempting to judge these agents by the list of things they can do, like booking travel or cancelling subscriptions. I think the more important thing is what you no longer have to tell them.

Ethan Mollick, a professor at the Wharton School

An agent that infers what you want will sometimes infer wrongly, and that is the governance problem.

The UK and EEA gap

UK readers should check this before upgrading a personal plan. OpenAI's help centre says dots are rolling out to Pro users "in markets excluding the European Economic Area, Switzerland, and the UK", with no date for those regions. Business Premium is different: dots are available there "across all supported ChatGPT regions", subject to workspace access. Enterprise workspaces get a beta that admins must switch on.

So for a UK or Irish consultancy, the route is the business workspace, and that is probably the better outcome anyway. A workspace admin can switch off Custom Rules for the whole tenant, and OpenAI does not train on Business, Enterprise or Edu content by default. On a personal plan, training is controlled by the individual's settings.

Three agents, three permission models

Microsoft's Autopilot, in the words of Jared Spataro, chief marketing officer for AI at Work, lives in your Microsoft 365 tenant "with its own identity, memory, computer and workspace" and shows up in Teams, Outlook and documents "with permissions, audit and governance behind it". It is also the least available of the three, with Microsoft saying it is expanding to private preview at the end of September.

Meta's Muse runs on what Meta calls a Secure VM, with a separate Sentinel agent that must approve anything leaving the machine, and it is rolling out in the US. The Marketplace incident in this week's One More Thing, where Muse gave a seller's pickup address to a buyer who then turned up at his flat, shows that 'Allow Always' means exactly that.

John Gruber, who writes Daring Fireball, put his own position bluntly: "This is why I don't run any AI agents, from any source, on my production/work Macs where all my personal information and communication apps are." A production Mac is a fair stand-in for a live project folder.

OpenAI's model is ‘Custom Rules’ plus a separate ‘Auto-review’ check. For any action you can describe, you pick one of four behaviours: take action without asking, take action when you say so, ask before taking action, or hand off to you. Before a dot sends an email or changes a file, Auto-review checks the step against your instructions, your rules and OpenAI's own requirements and can block it.

Permanently deleting data or granting new access always needs confirmation; changing a password or moving money is always handed back to you. OpenAI's documentation adds that rules "are instructions your dot tries to follow, and it can make mistakes".

❝

And if I eventually do, I'll pay surgical attention to the permissions I grant them.

John Gruber, Author, Daring Fireball

The rules we would write first

The defaults are tuned for an individual knowledge worker, not a team handling other people's commercial information. Here is where we would start for a delivery firm.

  • Anything external needs approval: every email, Teams message or file share to a client, contractor, consultant or bidder is set to "Ask before taking action".

  • Cost figures are hand-off only: a dot can read a cost plan, valuation or change register and draft commentary, but changing a number in the live file is "Hand off to you".

  • Tender material stays in the tenant: uploading, forwarding or summarising tender documents to any destination outside the workspace is blocked, and the tender folder is not a connected source during a live procurement.

  • Read access is scoped per project: connect one document library and one mailbox folder, and check the plugin permission screen, because a prompt that names one file does not narrow what the connection can see.

  • Someone owns the log: name who reviews Activity View each week, and note that disconnecting an app does not delete what the dot has already learned, so a leaver's dot is reset, not merely disconnected.

The caution comes from the vendors' own publications. The same week dots launched, the UK AI Security Institute reported simulations in which GPT-6 Astra, the model behind dots, carried out unsanctioned supply-chain attacks more often than earlier OpenAI models. OpenAI's cyber classifiers were switched off during the test.

OpenAI also published a misalignment report on a research agent that tunnelled a question to an external chatbot over DNS. As we cover elsewhere this week, OpenAI has also shelved the next Astra. None of that stops a dot from drafting a progress report. It does mean the safety teams do not consider the problem closed.

Takeaway

If your firm holds ChatGPT Business Premium, a dot is available to UK and EEA staff today. If staff hold personal Pro accounts, UK users cannot get one yet. Either way, the useful work this quarter is deciding your permission model before the agent arrives, so the first dot on a project is configured by the firm rather than by whoever got access first.

  • Check which ChatGPT plan your firm and your staff actually hold, and whether workspace admins have left dots and ‘Custom Rules’ enabled.

  • Write the five rules above into a one-page standard, then test them on an archived project with no live commercial exposure.

  • Agree who reviews the ‘Activity log’ and how often, before any project mailbox is connected.

  • Treat Autopilot and Muse as the same decision: one rulebook for always-on agents, whichever vendor ships first in your region.

We will keep track of which of these agents is actually usable on a UK or Irish project and what the first firms running them learn. The weekly Project Flux newsletter is where we report it: sign up here.

All content reflects our personal views and is not intended as professional advice or to represent any organisation.