Is OpenAI Dots Safe? What Your Dot Can Access and Do (2026)
Quick answer: OpenAI dots come with real guardrails, but how safe yours is depends on how you set it up. At launch (September 29, 2026), a dot gets its own cloud computer and browser, can connect to 4,000+ apps, can use your laptop with permission and can sign into sites with saved passwords. OpenAI's safeguards include read-only background research, Custom Rules to allow, require approval for or block actions, auto-review of consequential actions, password changes reserved for you, an Activity View with pause and reset, and monitoring that can stop a dot. OpenAI admits dots can still make mistakes, so connect the fewest apps you can and require approval before consequential actions.

Your AI assistant is already in WhatsApp. Get Sonic today.
Reminders that actually fire. Follow-ups Sonic sends for you and reports back. PDFs, contracts and invoices summarized in seconds. Your Google Calendar handled by text, and group chats that run themselves. Voice notes welcome. Nothing to install, nothing to learn: message Sonic like any contact. Try “Remind me to call the accountant every Monday at 9.” Leave your details and you’ll get Sonic’s number right away.
Is OpenAI dots safe to use?
Reasonably safe, if you set it up like you'd onboard a new assistant with keys to your office: give it only the keys it needs, tell it what always needs your sign-off, and check its work. OpenAI shipped dots on September 29, 2026 with a clearly documented set of guardrails, but the defaults you choose matter more than the marketing.
What's new is the risk model. A chatbot can say something wrong; you read it and move on. A dot can do something: it has its own cloud computer and browser, it works toward your goals 24/7, and it keeps going after you close the chat. OpenAI describes dots as "remarkably capable, always-on agents built to handle everything," and that's exactly why permissions deserve five minutes of your attention.
OpenAI is also candid that dots can make mistakes. That's not a reason to avoid them. It's a reason to set approval rules before you connect your inbox, not after.
Who should be most careful? Anyone for whom one wrong email or one wrong payment is expensive: accountants and bookkeepers with client data, agency owners with shared company cards, recruiters with candidate records, anyone whose inbox is full of other people's information. If that's you, start with approval required on everything and loosen rules one at a time.
What can an OpenAI dot access?
A dot can access whatever you connect, plus its own cloud computer and browser. With your permission it can also use your laptop, and it can sign into supported websites with your saved passwords. The table below lists each type of access and the control that comes with it.
The key idea: the access you grant is the access it has. OpenAI's help center makes a point worth underlining. Naming one document in your prompt doesn't reduce the access a connection grants. If you connect a whole file drive and ask about one contract, the dot can still reach the rest of the drive. Scope is set when you connect, not when you ask.
Two other things are easy to miss. First, a dot learns your preferences, standards and working habits from your feedback, and remembers context regardless of which channel you message it from: ChatGPT on desktop, web or mobile, Slack or Microsoft Teams. Second, OpenAI's saved-password sign-in stores passwords without the model seeing them, but the dot can still act inside those accounts once it's signed in.
At work, the picture widens. In ChatGPT Space, the collaborative workspace OpenAI announced the same day, dots can be tagged in to help on shared Pages that several people edit at once. In enterprise pilots, specialist dots go further, with their own organizational identity, credentials and access to company systems, plus Microsoft Agent 365 integration. If you're an admin, treat each dot like a new hire's account: scoped access, reviewed permissions, and someone who owns it.
| Access | What it means | Your control |
|---|---|---|
| Its own cloud computer and browser | Browses and works on tasks 24/7, even with ChatGPT closed | Watch it live in Activity View; pause or reset |
| 4,000+ apps via plugins | Email, calendar, files, work tools: whatever you connect | Only what you connect; naming one file doesn't narrow it |
| Your own computer | Can use your laptop | Only with your permission |
| Saved-password sign-ins | Signs into supported websites as you | Passwords saved without the model seeing them |
| Memory | Learns preferences and habits; remembers context across channels | Reset deletes conversations, memories and schedules |
| Proactive research | Scans connected apps in the background | Read-only: can't send, modify or control your computer or browser |
What guardrails does OpenAI put on dots?
OpenAI built seven layers of protection into dots at launch. Here they are in plain English.
1. Read-only proactive research. When a dot scans your connected apps in the background, it has read-only access. During that research it can't send messages, modify content, or control your computer or browser.
2. Custom Rules. You can allow specific actions, require approval, or block them entirely. "Ask before taking action" covers consequential actions. OpenAI's own example: an early tester's dot noticed he'd forgotten to invoice a publication, pulled the details from the email thread, drafted the invoice and sent it only after his approval.
3. Auto-review. A separate system checks consequential actions before they happen. 4. Human-only sensitive tasks. OpenAI says sensitive tasks such as changing passwords always stay with you.
5. Activity View. You can see your dot's cloud computer and background work any time, sorted into In progress, Scheduled and Completed. You can step in, pause, or reset. 6. Reset. Resetting deletes the dot's conversations, memories and schedules. 7. Safety monitoring. A monitoring system can pause or stop a dot if it raises safety concerns.
What the guardrails don't do is make your choices for you. Rules only cover what you configure, connections stay as broad as you made them, and OpenAI hasn't published how auto-review decides what counts as consequential. Treat the guardrails as a seatbelt, not a chauffeur.
- +Background research is read-only
- +Custom Rules: allow, require approval or block
- +Auto-review of consequential actions
- +Password changes always stay with you
- +Activity View with pause, intervene and reset
- +Monitoring can pause or stop a dot
- −OpenAI admits dots can make mistakes
- −Rules only protect what you set up
- −Naming one file doesn't narrow a connection's access
- −OpenAI hasn't detailed how auto-review judges 'consequential'
- −Consumer data defaults: check your own settings
Can OpenAI dots spend money or send messages without asking?
Not if you set Custom Rules to require approval or block those actions, and consequential actions also go through auto-review. But OpenAI hasn't published every detail, so the safe move is to decide these rules yourself on day one.
Spending money. OpenAI's launch materials don't describe a built-in payment feature the way Meta Muse requires a card on file, and OpenAI hasn't said how dots handle purchases. What we do know: a dot has a browser, can sign into supported sites with your saved passwords, and can use the apps you connect. If any of those accounts has a stored card, treat purchases as possible and write a rule that blocks them or requires approval.
Sending messages. During proactive research, a dot can't send anything. Outside research, sending an email or posting in Slack is exactly the kind of consequential action to put behind "Ask before taking action." The invoice example above is the model: the dot did the drafting, the human pressed send.
Here's the full risk picture in one table.
| Risk | What dots does | What you should do |
|---|---|---|
| Sends an email or message you didn't want | Custom Rules plus auto-review; research is read-only | Set "Ask before taking action" for anything that sends |
| Buys something | OpenAI hasn't detailed purchase handling | Block or require approval for payments; skip shopping logins |
| Sees more data than you meant | Access follows what you connect | Connect the minimum; one file named doesn't narrow access |
| Changes your account security | Password changes always stay with the human | Keep it that way; review which saved sign-ins it uses |
| Keeps doing something wrong in the background | Activity View, pause, reset; monitoring can stop a dot | Check In progress and Scheduled tabs regularly |
| Simply gets it wrong | OpenAI admits dots can make mistakes | Review drafts before approving; don't auto-allow high-stakes actions |
| Work content used for training | Business, Enterprise, Edu: not by default | On consumer Pro, check your data controls yourself |

Your AI assistant is already in WhatsApp. Get Sonic today.
Reminders that actually fire. Follow-ups Sonic sends for you and reports back. PDFs, contracts and invoices summarized in seconds. Your Google Calendar handled by text, and group chats that run themselves. Voice notes welcome. Nothing to install, nothing to learn: message Sonic like any contact. Try “Remind me to call the accountant every Monday at 9.” Leave your details and you’ll get Sonic’s number right away.
How do you set up an OpenAI dot safely?
Set your rules before you connect anything, then connect as little as possible. This checklist is quick, and it covers the mistakes that are easiest to make in week one.
1. Turn on "Ask before taking action" first. Make consequential actions require your approval before the dot touches any real account. Loosen specific rules later, once you trust a pattern.
2. Connect the minimum apps. Add one app at a time, for a task you actually have. Remember the help-center point: naming one document in a prompt doesn't limit what the connection can reach.
3. Say no to your laptop by default. A dot can use your own computer only with your permission. Don't grant it unless a specific task needs it.
4. Be deliberate with saved-password sign-ins. Only let the dot sign into sites it needs for the job. Leave banking, shopping and anything with a stored card off the list unless you've written a block or approval rule.
5. Write block rules for never-events. Payments, deleting files, messaging certain people: block them outright instead of relying on judgment calls.
6. Read the Activity View. Check In progress, Scheduled and Completed daily in your first week, then weekly. Scheduled is where surprises hide.
7. Know your exits. Find pause before you need it. Reset is the nuclear option: it deletes conversations, memories and schedules.
8. Business users: check the data policy with your admin. For Business, Enterprise and Edu, workspace content isn't used to train models by default. In Enterprise, Edu and Healthcare, dots are in beta and off until an admin enables them. On a consumer Pro plan, review your ChatGPT data controls yourself.
How do dots' guardrails compare with Meta Muse?
Both are always-on agents with their own computer and browser that ask before sensitive actions. Dots give you more granular controls; Muse is more explicit about money, because it's built to buy.
Meta Muse, launched September 8, 2026 in the US, runs its own virtual machine and browser in the background and asks your approval for sensitive actions like purchases and emails. Even its free plan requires a payment card on file for that reason. Amazon has blocked Muse from shopping on Amazon. Our full Meta Muse safety guide covers its permissions in detail.
Dots reach further (4,000+ apps, optionally your laptop, saved-password sign-ins) and pair that reach with more visible controls: allow, approve or block rules, read-only background research and an Activity View you can pause. More reach plus more controls isn't automatically safer or riskier. It means your setup choices carry more weight.
| OpenAI dots | Meta Muse | |
|---|---|---|
| Runs its own computer | Cloud computer and browser | Virtual machine and browser |
| Approvals | Custom Rules (allow / approve / block) plus auto-review | Asks approval for sensitive actions like purchases and emails |
| Payments | Not detailed by OpenAI | Card on file required, even on Free |
| Where available | Pro: not EEA, Switzerland or UK | US and Canada (Canada since Sept 18) |
Do you really need to give an AI agent this much access?
For most people, no. Security folks call it least privilege: give a tool only the access its job needs. Look at what most of us actually want help with: remember the Monday call, chase the reply, read this contract, keep the team group on schedule. None of that requires handing an agent a computer, your laptop and a door into 4,000 apps.
That's the design idea behind Agent Sonic, a personal AI assistant that lives inside a WhatsApp chat. There's no computer for it to control, and it doesn't make purchases. It works with what you send it. You decide exactly what to forward, one message or file at a time.
[Forwards one PDF] "Does this contract have a non-compete clause?" Sonic reads that file and answers. It doesn't need your whole drive to do it. Our guide on sending documents to an AI on WhatsApp safely goes deeper on this.
"Remind me to renew the car insurance on March 3." No app connection needed at all, just a reminder in the chat you already use.
"Message the landlord and ask when the plumber is coming. Tell me what he says." Sonic's outreach sends the message you asked for and reports the answer back. It isn't composing messages to your contacts on its own initiative.
In a team group: "Every Friday at 4, remind everyone to submit timesheets." Automatic group reminders, visible to everyone in the group, doing exactly what the group can see.
Fair's fair: if you connect Google Calendar, Sheets or Docs to Sonic, the same rule applies as with dots: connect only what you'll use. And Sonic isn't a replacement for everything a dot does. It doesn't connect to 4,000 apps, run hours of autonomous research or coding on a cloud computer, or work in Slack or Teams. If that's your work, dots with careful Custom Rules are the right tool. If your work is reminders, follow-ups, documents and groups, a smaller footprint is the safer default.
There's a quieter benefit, too: everything happens in one chat you already read every day. Your reminders, the replies Sonic collected, the answer about that contract all sit in the WhatsApp thread, where anything odd is easy to spot. If least privilege sounds like the right fit for your week, get access at tryagentsonic.com/contact.
| OpenAI dot | Agent Sonic | |
|---|---|---|
| Computer control | Own cloud computer; your laptop with permission | None |
| App connections | 4,000+ via plugins | Google Calendar, Sheets and Docs |
| Purchases | Not detailed by OpenAI; control with Custom Rules | Doesn't make purchases |
| What it works with | Everything in the apps you connect | What you forward, plus integrations you connect |
| Messages to other people | Via connected apps, subject to Custom Rules | Outreach you asked for, in WhatsApp |
Frequently asked questions
Is OpenAI dots safe?
Dots ship with real guardrails: read-only background research, Custom Rules to allow, require approval for or block actions, auto-review of consequential actions, and password changes reserved for you. OpenAI also admits dots can make mistakes. They're as safe as your setup, so require approval for consequential actions and connect as few apps as possible.
Can OpenAI dots spend my money?
OpenAI hasn't detailed how dots handle purchases at launch. A dot has its own browser and can sign into supported sites with your saved passwords, so if an account has a stored card, write a Custom Rule that blocks payments or requires your approval. Consequential actions also pass through OpenAI's auto-review.
Can a dot change my passwords?
No. OpenAI says sensitive tasks such as changing passwords always stay with the human. Dots can sign into supported websites using saved passwords, which are stored without the model seeing them.
Does an OpenAI dot read my email in the background?
If you connect your email, yes: proactive research scans connected apps in the background. That research is read-only, so during it the dot can't send messages, modify content or control your computer or browser. If you don't want an app scanned, don't connect it.
Does OpenAI train on my dot's data?
For Business, Enterprise and Edu, OpenAI says workspace content isn't used to train models by default. For consumer Pro plans, check your ChatGPT data controls directly; we won't guess at the defaults.
How do I pause or reset an OpenAI dot?
Open the Activity View, where you can see work In progress, Scheduled and Completed, then intervene, pause or reset. A reset deletes the dot's conversations, memories and schedules, so pause first if you only want it to stop. OpenAI's monitoring system can also pause or stop a dot over safety concerns.
Can an OpenAI dot use my laptop?
Only with your permission. By default a dot works on its own cloud computer and browser. Grant laptop access only when a specific task genuinely needs it.
Is there a lower-access alternative to OpenAI dots for everyday admin?
Yes. Agent Sonic works inside a WhatsApp chat, where you choose exactly what to forward. It handles reminders, outreach you ask for, group reminders and document analysis without controlling a computer or making purchases. You can get access at tryagentsonic.com/contact.

Your AI assistant is already in WhatsApp. Get Sonic today.
Reminders that actually fire. Follow-ups Sonic sends for you and reports back. PDFs, contracts and invoices summarized in seconds. Your Google Calendar handled by text, and group chats that run themselves. Voice notes welcome. Nothing to install, nothing to learn: message Sonic like any contact. Try “Remind me to call the accountant every Monday at 9.” Leave your details and you’ll get Sonic’s number right away.