Safety

Are OpenAI Dots Safe? Security and Privacy Explained

Dots are built to do real work on your behalf. This page walks through what OpenAI has published about isolation, approvals, and data controls — and where responsibility stays with you.

Last verified: September 30, 2026 · Reviewed by AstraDot editorial desk

The moment an assistant can act instead of just answer, the safety question changes. A Dot does not only draft text — it signs into tools, runs a browser, and works while you are away. That is useful, and it is exactly why "are OpenAI Dots safe?" deserves a careful, source-checked answer rather than a marketing one.

This page collects what OpenAI has published about how Dots are isolated, what they are allowed to do on their own, and how your data is handled. Where OpenAI has not published a detail, we say so and link the official safety overview. And the one caution that applies to every page like this: Dots can still make mistakes, so review consequential work before you rely on it.

A Dot works on its own computer, not yours

Each Dot has its own cloud computer and browser. That environment is separate from your own devices unless you deliberately connect something to it. In practice this means a Dot does not run on your laptop, does not take over your browser session, and does not need to be logged into your machine. It works in its own space and reports back to you. If you want to see the work, you can open its computer and inspect it — the same way you would check on a colleague's file rather than take it on trust. For the product basics, see what OpenAI Dots are.

Passwords are used, not exposed

When a Dot signs in to an app you have connected, OpenAI says saved passwords are used without exposing them to the model. The model can act as the logged-in account without being handed the password in plain text. This narrows the blast radius of a leak, but it is not a reason to connect everything. The safest setup is the smallest: connect only the accounts a Dot genuinely needs to finish the work, and review what you have connected on a regular schedule.

Background research is read-only

A large part of a Dot's value is the work it does unprompted. OpenAI calls this proactive research: the Dot reads, gathers, and prepares while you are busy elsewhere. Crucially, OpenAI says proactive research uses read-only tools. A Dot in this mode cannot send messages, cannot change the content of your apps, and cannot control your browser or your computer. It can look and summarise; changes wait for a person.

Read-only is a meaningful guardrail, but it is still worth remembering that reading the wrong thing or summarising it badly can mislead you. Treat research output as a draft to check, not a verdict to act on.

Auto-review, approvals, and Custom Rules

When a Dot wants to do something that affects your accounts, it does not simply proceed. OpenAI runs auto-review, which checks an intended action against your instructions, your Custom Rules, and its safety requirements. You decide how strict the gate is. Custom Rules let you place actions into one of three buckets:

Rule settingWhat happensBest for
Allow The Dot can take this kind of action without asking each time. Low-stakes, repetitive steps you are happy to delegate.
Require approval The Dot prepares the action and waits for you to confirm it. Anything visible outside your team, or hard to undo.
Block The Dot is not permitted to take this action at all. Spending, deletions, or systems you never want touched.

The practical approach is to start almost everything on require approval, watch what a Dot actually tries to do, and only loosen rules once the pattern is boring and predictable.

Some tasks always stay with you

OpenAI draws a line around certain sensitive tasks and keeps them with the person. Its example is changing a password: that step is not handed to the Dot. The broader principle is worth internalising — the more a task resembles account recovery, identity, money movement, or irreversible deletion, the more you should expect to handle the final step yourself and use the Dot only for preparation.

Watch progress in the activity view

Dots are not black boxes. OpenAI provides an activity view that shows what a Dot is doing, including background work, so you can follow along as a project moves. You can pause or stop monitoring when you want, and OpenAI says it can also pause or stop a Dot if its own monitoring finds a concern. Think of the activity view as the audit trail you check before you sign off — not something to ignore once setup is done.

Data controls

Data use is one of the clearest areas where the answer depends on your plan. By default, OpenAI does not use content from ChatGPT Business, Enterprise, or Edu workspaces to improve models. On personal plans, whether your conversations and work are used to improve models is something you control through opt-in. OpenAI also says it does not train directly on proactive-research content or on a Dot's own notes. For the exact controls on your plan, check OpenAI's help center.

Enterprise governance and specialist Dots

For organizations, the governance story extends to specialist Dots — organizational agents with their own identity, credentials, and access to the systems of record they need. That is a larger surface than a personal Dot, so oversight matters more, not less. OpenAI is working with Microsoft to integrate specialist Dots with enterprise governance and security controls in Agent 365, which is where many larger organizations will expect to manage policy. See Dots vs Microsoft Agent 365 for how the two fit together.

Before you connect an app: a checklist

Most safety problems are set up in the first ten minutes, when you are excited and connecting things quickly. Slow down once and use this list:

  • Name the job. Connect an app only because a specific task needs it, not because it is available.
  • Prefer read-only access where the app offers it, and upgrade only if a task truly needs to write.
  • Set Custom Rules first. Put money, deletions, and outbound messages behind require approval or block.
  • Check the account, not just the app. A Dot inherits whatever the connected account can reach, including shared folders.
  • Review the activity view after the first few runs and confirm the Dot behaved as you expected.
  • Use least privilege for people, too. The narrower the connected account, the smaller the consequence of a mistake.
  • Know your data controls. Confirm whether your workspace content is used to improve models before you rely on default behaviour.

No safeguard removes the need for human judgement. OpenAI itself notes that Dots can make mistakes — verify consequential output before it reaches customers, money, or the public.

Source: OpenAI, how we build safety, security and privacy into Dots, checked 2026-09-30. Values OpenAI has not published are marked "not published" rather than estimated.

Frequently asked questions about Dot safety

Are OpenAI Dots safe to use?
OpenAI says each Dot runs on its own isolated cloud computer, background "proactive research" uses read-only tools, actions that affect your accounts pass through auto-review, and you can set Custom Rules and inspect an activity view. OpenAI also states that Dots can make mistakes, so you should review consequential work before it goes out.
Can a Dot see my saved passwords?
OpenAI says saved passwords are used without exposing them to the model. In other words, a Dot can sign in to a connected app without the password being shown to the model in plain text. This limits exposure, but you should still connect only the accounts a Dot genuinely needs.
What can "proactive research" actually do?
Proactive research is the background work a Dot does while you are away. OpenAI says it uses read-only tools, so it cannot send messages, change app content, or control your browser or computer. It can gather, read, and prepare, while changes wait for a person to approve.
What are Custom Rules?
Custom Rules are the instructions you give a Dot about how it may act. They let you allow an action, require your approval first, or block it. Auto-review checks a Dot's intended actions against your instructions, your Custom Rules, and OpenAI's safety requirements.
Which tasks always stay with a human?
OpenAI says some sensitive tasks always stay with you — changing a password is the example it gives. More broadly, the guidance is that consequential work should be reviewed by a person rather than accepted at face value.
Does OpenAI train on what my Dot does?
By default OpenAI does not use content from ChatGPT Business, Enterprise, or Edu workspaces to improve models. On personal plans you control whether that content is used. OpenAI says it does not train directly on proactive-research content or a Dot's own notes.