234: OpenAI's Dots Are Cute. What They Do With Your Data Is Not.

Slobodan "Sani" Manic
Website Optimisation Consultant, No Hacks Founder & Keynote Speaker
CXL-certified conversion specialist and WordPress Core Contributor helping companies optimise websites for both humans and AI agents.
OpenAI's new AI agents, dots, are fuzzy balls with eyes that you name and dress. Each one has a computer in the cloud and a browser, can sign into supported websites with the passwords you saved, and reads the email and calendar you connect. I went through OpenAI's pages to see what the cute face is covering. What a dot does, and the data from the apps you connect, can be used to train OpenAI's models unless you turn off a setting called Improve the model for everyone. In OpenAI's tests, the model behind dots kept looking for another way after an access-denied error about one time in six. And OpenAI tells websites nothing: dots are not on its page for website owners, and its instructions tell users to try their own computer when a website blocks one. I think the face is how it gets sold. Would I give a dot my logins and my card? No, not until OpenAI says how it handles my data.
KEY TAKEAWAYS
- In ChatGPT, go to Settings, then Data controls, and check whether Improve the model for everyone is on. For dots, it covers what your dot does and what it reads from the apps you connect.
- Before you connect your email or calendar to any AI agent, find out what the company does with what the agent reads.
- Before you let an agent use a saved card, check whether purchases can be approved in advance. OpenAI's help page says a dot's purchases can be.
- If you run a website, look at OpenAI's page for website owners. Dots are not listed, so there is no user agent to block in robots.txt.
- If you run a store, read Shopify's rule for agents: an agent should sign what it sends so the store can check who it is.
SHOW NOTES
OpenAI's Dots Are Cute AI Agents That Sign Into Websites With Your Passwords
OpenAI launched dots on 29 September 2026. A dot is an agent, an AI that does not answer you and stop but goes off and does things for you. Each one has a computer in the cloud and a browser, can sign into supported websites with the passwords you saved, can buy with a card you saved on a store once you approve, and reads your email and calendar if you connect them. The launch post shows five of them, fuzzy balls with eyes called Jojo, Iggy, Felipe, Todd and Alfred, and OpenAI's instructions tell you how to name yours and pick its shape, colour, eyes, glasses and accessories. Dots are part of ChatGPT. At launch they came with the ChatGPT Pro and Business Premium plans, with Pro users in the European Economic Area, Switzerland and the UK left out, and an Enterprise beta turned off by default.
The face is not new. Microsoft's Clippy had eyes in 1997 and was switched off by default by 2001. OpenAI gave its business agents named characters with eyes in April 2026. Meta made the character the product when it launched Muse on 8 September 2026, and three weeks later OpenAI did the same. I think the face is how it gets sold. For most people, what a dot does is closer to "this could be fun to try" than "I waited my entire life for this", and the cute covers the privacy and security questions.
OpenAI Can Train On What Your Dot Reads Unless You Turn It Off
OpenAI's privacy FAQ says a setting called Improve the model for everyone controls whether what your dot does, and data from the apps you connect, can be used to train its models. The next line says you can turn it off, and OpenAI's help page on data controls is written as instructions for turning it off. The setting is in ChatGPT under Settings, then Data controls. Meta's Muse has the same default. OpenAI also says it does not train directly on a dot's background research, but if a dot brings that information into a conversation, it may be used for training.
The FAQ says business workspaces are not used for training by default. OpenAI pitches dots as an extension of you, so that line says little about the personal accounts most people would use. Passwords are handled separately: OpenAI says dots use saved passwords without exposing them to the model.
OpenAI's Tests Show GPT-6 Astra, The Model Behind Dots, Kept Trying After An Access Denied Error
Dots run on a model called GPT-6 Astra. In one test in OpenAI's system card, the model hits an access-denied error. The previous model kept trying another way 64% of the time, Astra 19%, and in the version of the test run for dots, 17.4%, about one time in six. The same report says flags for the model searching for credentials were more frequent, and gives an example: "GPT-6 Astra bypassed the application's access controls without user approval."
Prompt injection is when hidden text in a web page or an email tells an agent to do something the user never asked for. OpenAI's prompt injection tests on dots used emails, 16,600 attack emails among 50,000 delivered, and no dots-specific test of malicious web pages is reported, although a dot browses websites all day.
Websites Are Told Nothing About OpenAI's Dots
OpenAI's page for website owners lists four crawlers as of 30 September 2026, each with a user agent, the name it sends with every request so a server can tell what it is. Dots are not on it, so a website has no user agent to recognise, nothing to set in robots.txt and no way to opt out. OpenAI's instructions to users say some websites block the dot's cloud browser, and that if one does, they should try their connected computer, the browser on their laptop. OpenAI's page on computer use says websites may treat what it does there as coming from the user's account.
Websites do block agents: Amazon blocked Meta's Muse from its store on 20 September 2026. Shopify's checkout tools for agents, released the day before dots, ask an agent to sign what it sends so the store can check who it is. That is an agent built through the web. A dot arriving from your laptop, signed in as you, is one built over it.
WATCH ON YOUTUBE
QUESTIONS ANSWERED
What are OpenAI dots?
Dots are OpenAI's AI agents, launched on 29 September 2026. Each dot has a computer in the cloud and a browser, can work in the background, can sign into supported websites with saved passwords and can read connected email and calendars. Dots are part of ChatGPT. You name each dot and choose its look, from shape and colour to eyes, glasses and accessories.
Are OpenAI dots available in the EU and UK?
Not for Pro users at launch: on 29 September 2026 OpenAI rolled dots out to ChatGPT Pro users outside the European Economic Area, Switzerland and the UK, and to Business Premium users in all supported ChatGPT regions. Enterprise workspaces got a beta that is turned off by default.
How much do OpenAI dots cost?
There is no separate price. At launch, OpenAI said your first dot is included in a ChatGPT Pro or Business Premium plan at no extra cost, with an allowance for deeper work and extended limits for the first month after launch. Conversations with your dot do not count toward ChatGPT usage limits, but tasks it starts in Codex or ChatGPT Work do.
Does OpenAI train on what dots read?
It can. OpenAI's privacy FAQ says the setting Improve the model for everyone controls whether a dot's conversations and work, including actions it takes and data from connected apps, can be used to train OpenAI's models. The setting can be turned off in ChatGPT under Settings, then Data controls.
How do I stop ChatGPT from training on my data?
In ChatGPT, open Settings, then Data controls, and turn off Improve the model for everyone. For dots, OpenAI's privacy FAQ says this setting covers what your dots do and data from the apps you connect. OpenAI says human review may still happen in limited cases, including safety-related ones.
Are OpenAI dots safe?
OpenAI says saved passwords sit in a separate encrypted service and are not exposed to the model, and purchases need your approval. Its tests found the model behind dots kept trying after an access-denied error 17.4% of the time, and its prompt injection tests on dots used emails, not web pages.
Can websites block OpenAI dots?
Not by name, because OpenAI's page for website owners lists four crawlers and does not list dots, so there is no user agent to block in robots.txt. OpenAI's instructions tell users to try their own computer's browser when a website blocks a dot's cloud browser.
SOURCES
- Introducing dots, OpenAI
- How OpenAI built safety, security and privacy into dots saved passwords and purchase approval
- Dots privacy, security and safety FAQ Improve the model for everyone, business workspaces, advance purchase approval
- Data controls in ChatGPT where Improve the model for everyone is
- Dots, computers and apps when a website blocks the cloud browser
- Computer use, OpenAI actions treated as coming from your account
- OpenAI's crawlers, for website owners
- GPT-6 Astra system card the access-denied test and the dots appendix
- OpenAI DevDay 2026 keynote
- Introducing workspace agents, OpenAI, April 2026
- Introducing Muse, Meta
- Thomas Germain, BBC, on trying Meta's Muse
- The Tech Report, with Ed Zitron
- Better Offline, Ed Zitron's podcast
- Shopify, checkout tools for agents
- FTC on the Joe Camel campaign, 1997
- Amazon Blocked Meta's Muse, And robots.txt Had Nothing To Say
CHAPTERS
RELATED ARTICLES
Eleven Ways Websites Can Get Paid For AI Use, And Who Sets The Price In Each
In 2025 Cloudflare let websites set the price AI crawlers pay. In 2026 it launched a scheme where the AI company sets the price and reports its own usage. Across eleven schemes that pay websites for AI use, the ones where the website names the price have no AI company named as paying, and where AI companies pay, they set the price or count the usage.
Shopify Now Enrols Your Store In Every New AI Shopping Channel
Shopify signs eligible stores up for every new AI shopping channel by default. Leave it on, and read the shopper count in your Shopify admin as clicks from AI apps, not agent purchases.
Amazon Blocked Meta's Muse, And robots.txt Had Nothing To Say
Amazon cut Meta's Muse off from its store on 20 September with a Conditions of Use notice. Its own robots.txt blanket-refuses 99 named agents, and Muse is not one of them, because Meta's crawler documentation lists no user agent string for it.
ENJOYING THIS EPISODE?
Practical strategies for making your website work for AI agents and the humans using AI to find you. Once a week you get the new articles, the latest podcast episode, and a few links worth keeping.
