A split image contrasts cloud-based digital services on a laptop with a technician monitoring secure servers at a workstation.
OpenAI's Dots arrived on September 29, 2026, as a hosted always-on agent. Joe Rice-Jones of XDA Developers says it replaced his self-hosted OpenClaw assistant. His setup took less than five minutes, against hours for the Proxmox, Tailscale and Gateway build he'd run before. That timing is one reviewer's experience, not a benchmark. The comparison still shows two different ways of running an agent. One moves the work and the risk onto your own hardware. The other moves them onto a vendor's servers.

A split image contrasts cloud-based digital services on a laptop with a technician monitoring secure servers at a workstation. What Dots actually is​

Dots are always-on agents in ChatGPT, launched on 29 September 2026. They run on GPT-6 Astra with their own cloud computer and browser. They can connect to over 4,000 apps through plugins, keep working between conversations, and bring results back for review.

Availability is narrower than the headline suggests, going by OpenAI's Help Center and the XDA review:

  • Pro: Pro users get dots in markets excluding the EEA, Switzerland and the UK.
  • Business Premium: access covers all supported ChatGPT regions.
  • Enterprise, Edu and Healthcare: these users get a beta once a workspace admin enables it, and it is off by default.
  • Cost: the first dot is included in Pro or Business Premium at no extra cost.
  • Rollout: access is gradual and can take several days to reach an account.
  • Where to create one: you create a dot in the ChatGPT desktop app, which includes the Windows version, or on desktop web. You can't create one on mobile, but you can talk to it in the mobile app afterward.
  • Messaging channels: these, such as Slack, also have to be set up from desktop.

Why setup is so different​

The XDA author's self-hosted stack needed several separate pieces. He lists a non-daily-driver machine, a Gateway daemon, a model provider key or local endpoint, a bot per chat app, and a safe way to reach it remotely. Each piece takes minutes, he says, and together they take hours.

With Dots, his setup was creating the dot and connecting Gmail and Google Calendar through ChatGPT's existing plugin permissions. There was no container, API key or credential file to secure.

His reported tests included:

  • Email draft: it resolved an ambiguous editor reference from his mailbox and saved a Gmail draft instead of sending.
  • Release monitoring: it set up daily checks on Lemonade Server, Windows Insider and Proxmox releases.
  • Lemonade version check: it flagged Lemonade v2026.41.1, then explained that the project now uses year-and-ISO-week version numbers.
  • Morning brief: it was limited to his latest 40 emails by Gmail's read limit, and said so.

These are his observations, and I haven't reproduced them.

The guardrails​

OpenAI documents several layers of control:

  • Custom Rules: you choose whether a dot acts without asking, acts only if pre-approved, asks first, or hands the action to you. OpenAI's help page defines "pre-approved" as an action you explicitly requested in your prompt.
  • Where to find them: OpenAI's controls documentation puts them under Settings, then Personalization, then Custom rules. The XDA author found that menu path hard to locate.
  • Auto-review: before an action that could affect your accounts or share information, an automatic check compares it against your instructions, permissions, rules and built-in safety requirements. Changing a password always stays with you.
  • Limits of the rules: OpenAI's documentation says rules don't grant app access or override built-in safety requirements. Plugin permissions control app access separately. Dots can still make mistakes, including when following your rules.
  • Draft versus send: asking a dot to draft replies doesn't give it permission to send them.
  • Local computer access: your own PC is separate from the dot's cloud computer. Local access is optional and starts off. If you grant it, the dot can reach files and work on that machine, which is a larger trust decision. You can revoke it later.

The privacy tradeoff​

The article's central point is that neither option is a privacy win. They fail in different ways.

Dots (hosted): OpenAI patches and operates the infrastructure, but your connected-account data lives with the provider.

  • Proactive reading: a dot can review connected-app information and form memories from it without a specific prompt. OpenAI says the tools it uses for that research are read-only and can't send messages or change app content.
  • Memory limits: per OpenAI's help documentation, you can't currently inspect, edit or delete individual dot memories.
  • Disconnecting an app: this doesn't delete what the dot already learned from it.
  • Deleting memories: the help page says deleting the dot's own saved memories means deleting the dot.
  • Reset scope: OpenAI's privacy FAQ adds that files, Codex threads and ChatGPT conversations the dot created are stored separately. Other ChatGPT memories stay and are managed through ChatGPT's own Memory controls. So a reset clears the dot's context, not everything it touched.
  • ChatGPT Memory sharing: turning off ChatGPT Memory stops further sharing with the dot. It doesn't erase what the dot already received.
  • Training: on personal plans, the "Improve the model for everyone" setting governs whether dot conversations and work are used for training. Business, Enterprise and Edu workspace content isn't used by default.
  • Background research and notes: OpenAI says it doesn't train directly on proactive research or a dot's notes to itself. Information from them can be used if it informs an eligible conversation or task, depending on your settings.
  • Prompt injection: the XDA author notes OpenAI admits its defenses reduce the risk without eliminating it.

OpenClaw (self-hosted): you get more control, but you own the host.

  • Cloud model exposure: unless you run a local model, prompts still go to whichever cloud provider you configured.
  • Local secrets: memory and API keys sit in files on a machine you have to keep locked down.
  • Marketplace risk: Palo Alto Networks' Unit 42 describes skills as markdown-driven packages with broad local system access. It says Koi Security's ClawHavoc disclosure documented 341 malicious skills. Unit 42 reports that ClawHub added VirusTotal and ClawScan screening after the early findings. Its own February–May 2026 analysis still found five unblocked malicious skills, which it reported and which were removed.
  • Fair reading: that supports saying marketplace scanning reduced the risk but didn't eliminate it. It doesn't mean every skill or installation is malicious.
  • An unverified detail: the XDA piece cites CVE-2026-25253 as a Gateway remote-code-execution flaw. I couldn't confirm it against a primary advisory, so check the official record before acting on it.

Why Windows and IT readers should care​

The Windows desktop app is a supported place to create a dot, so this lands directly on Windows machines. The enterprise side matters more. OpenAI says it is working with Microsoft to bring specialist dots under Agent 365's governance and security controls. Microsoft describes Agent 365 as a control plane for managing and securing AI agents. It uses Entra for identities and access, Defender for security and Purview for data governance.

Specialist dots are not generally available. They're starting as pilots in which OpenAI engineers work with customers to set duties, tools and review processes. No timeline was given for the Agent 365 integration. Administrators shouldn't treat that integration as something they can deploy today.

Practical guidance​

The sources support a short checklist:

  1. Connect narrowly. Link only the accounts you need, and review each plugin's permissions before connecting.
  2. Skip shared workspaces. The XDA author skipped Slack because connecting it would expose other people's messages.
  3. Set confirmation rules. Use "ask before taking action" for consequential steps like sending email, and verify the output.
  4. Leave local access off unless you really need the dot on your own PC.
  5. Check your training setting on personal plans, and confirm that a Business or Enterprise workspace is actually covered.
  6. Know what reset does. It deletes the dot's conversations, memories and scheduled tasks. It doesn't touch separately stored files, Codex threads or ChatGPT conversations.
  7. If you self-host, treat the agent like any other server. Patch it, isolate it, and review every skill as untrusted code, as Unit 42 recommends. Its guidance includes checking publisher provenance, auditing package source and watching outbound traffic for undocumented endpoints.

Verdict​

Dots lowers the operational burden for most people. In exchange, you hand your account data and memory to a provider whose current controls don't let you inspect or selectively delete what the agent has learned. OpenClaw keeps that data under your control, especially with a local model, but it leaves patching, integrations and skill vetting to you. The XDA author's pick is Dots for most people, with OpenClaw still the more private option for anyone willing to run it like a server. Which one suits you depends on whether you'd rather trust a vendor or maintain a box.

 

References

  1. I ditched OpenClaw for OpenAI's Dots, and setup took minutes instead of hours XDA 2026-10-08T18:00:18+00:00
  2. ስለ dots ግላዊነት፣ የመረጃ ጥበቃ እና ደህንነት ተደጋጋሚ ጥያቄዎች | OpenAI Help Center help.openai.com
  3. Getting started with your dot | OpenAI Help Center help.openai.com