OpenAI has unveiled a new class of always-on AI agents called Dots, designed to carry out tasks across common workplace tools including Slack and Microsoft Teams. The company says the agents operate under custom permissions, a detail aimed squarely at businesses that need to control what an automated system can see and do.
The launch is part of a broader push to win enterprise customers, the corporate buyers who pay for software at scale and tend to be far more lucrative than individual subscribers. At the same time, OpenAI's safety controls are facing fresh questions, a tension that hangs over any product designed to act on its own inside a company's systems.
From answering questions to doing the work
The shift Dots represent is a meaningful one. Most people's experience of AI so far has been conversational: you type a prompt, the model replies, and you decide what to do with the answer. An always-on agent flips that. It runs in the background, often on cloud computers, pulls context from the apps a team already uses, and then takes action — drafting a document, updating a project tracker, or preparing a demo for a person to review.
That move from "answering" to "doing" is the direction much of the software industry is heading. Microsoft has been folding similar always-on assistant features into its Copilot products, and other vendors are racing to build agents that can complete multi-step tasks rather than just describe them. The pitch to businesses is straightforward: if software can handle routine coordination work, employees get time back for higher-value tasks.
The catch is that autonomy and trust pull in opposite directions. An agent that can only chat is low-risk. An agent that can read messages, edit files and trigger workflows inside a company's systems is a different proposition entirely.
Why permissions and safety are the real battleground
OpenAI says Dots operate with custom permissions, which is the mechanism that determines which tools an agent can touch and what data it can reach. For businesses, especially in regulated industries like healthcare and finance, those controls are not a nice-to-have. They are the difference between a tool that can be deployed and one that legal and compliance teams will block.
Companies evaluating autonomous agents typically want clear answers to a few questions: Who is the agent acting on behalf of? What systems and records can it access? Where is sensitive information stored, and how long is it retained? Without convincing answers, the productivity gains on offer are unlikely to outweigh the risk of a data leak or an unauthorized action.
Those concerns are not hypothetical. Regulators and researchers have been pressing AI developers on how they test and constrain models that can take real-world actions. Internal critics at major AI labs have warned that a speed-first culture can leave safety work lagging behind product launches, a theme that has followed OpenAI and its peers as they ship more capable tools.
There is also competitive pressure from below. Cheaper and open-weight AI models have been pulling some enterprise spending away from the biggest labs, as businesses look for lower-cost ways to build their own assistants. That makes the enterprise market a contest not just of raw capability but of price, integration and trust.
What it means for investors
For everyday investors, the Dots launch matters less as a standalone product and more as a signal about where the money in AI is heading. The first phase of the AI boom was dominated by infrastructure — chips, data centers and cloud capacity. The next phase is about applications that businesses will actually pay recurring fees to use. Agents that plug into Slack and Teams sit right in that second wave.
That has implications across several parts of a portfolio. Software companies that own workplace platforms, like Microsoft, have an obvious stake in how this market develops, since agents need somewhere to live and something to integrate with. Cloud providers benefit if agents run continuously in the background, because always-on workloads consume compute around the clock. And the model developers themselves, including OpenAI, are betting that enterprise contracts become a durable revenue base rather than a one-off experiment.
It is worth being clear about what this news does not tell us. OpenAI has not disclosed pricing, adoption numbers or specific customer commitments for Dots, so there is no way to judge commercial traction yet. Investors should treat the announcement as a strategic marker, not a financial result.
The things to watch next are practical. Whether large regulated companies actually deploy these agents, how OpenAI and rivals handle permissioning and data retention, and whether safety incidents or regulatory pushback slow adoption. If enterprises embrace always-on agents, the winners will likely be the platforms that host them and the infrastructure that powers them. If trust proves too hard to win, the shift from answering to doing could take considerably longer than the hype suggests.

