Key facts

  • OpenAI states dots can still make mistakes and that you should review consequential work.
  • OpenAI says its prompt-injection protections reduce risk but do not eliminate it.
  • Some actions always require confirmation and some are always handed back to you, and your approval cannot override core safety requirements.
  • Disconnecting an app stops new sharing but does not remove information a dot already holds.

Most dots coverage leads with capability. This page leads with the parts OpenAI writes in its own documentation about where the product can go wrong — because a persistent agent with access to your email, files, and code is a different risk object from a chatbot.

1. It can still be wrong, and OpenAI says so plainly

OpenAI's own wording: dots "can still make mistakes", and you should check work that could have material consequences. The safety write-up goes further, noting that agent errors can extend beyond a conversation — a misunderstood request can mean the wrong file gets changed, or information you wanted kept private gets shared.

Treat the first month as supervised, not autonomous. That is what the credit allowance effectively buys you: time to find out where your dot's judgement and yours diverge.

2. Prompt injection is mitigated, not solved

Dots read from sources you cannot fully control: web pages, emails, documents. OpenAI names the risk directly — such content can contain instructions designed to redirect the agent or make it disclose private information — and describes the defence as model mitigations plus tool restrictions, pre-action checks, and monitoring.

The honest summary is in OpenAI's own line: these protections "help reduce the risk of malicious instructions causing an unwanted action, but they do not eliminate it."

Practical consequence: a dot with read access to untrusted input and write access to anything valuable is the configuration to be most careful about. Those two permissions are what turn an injection into an action.

3. Some things you cannot approve away

Approval is powerful but bounded, and the boundaries are the most useful thing on this page:

Always requires your confirmation

  • permanently deleting data
  • installing or running software from unknown sources
  • granting new security-sensitive access
  • card purchases on merchant sites where you have saved a payment method

Always handed back to you — a dot cannot do these for you

  • changing passwords
  • transferring money between financial accounts

Cannot be overridden at all

  • core safety requirements. Your approval does not override them, and a dot cannot disable or modify the Auto-review checks or the proactive-research restrictions.

4. Auto-review is a gate, not a guarantee

Before actions such as sending email or changing files, an independent system checks the step against your instructions, rules, and safety requirements. For email it checks recipient and content.

If it blocks a step, the dot may ask you or request approval, try a permitted alternative, hand the step back, or stop. Two implications:

  • A blocked action is not necessarily a bug — it is the gate working.
  • A permitted action is not an endorsement. Review passed means "no rule objected", not "this was a good idea".

5. The credential caveat

Secure login is genuinely stronger than typing passwords into a chat: for supported flows the model pauses while you fill the credential form, credentials go straight to the browser environment, and saved-password logins use an encrypted credential service so the password never enters the model's context.

OpenAI adds the caveat that makes this real: if sensitive information is written into a readable message or document, the model can still see it. Copying a password into a chat message "so the dot can use it" defeats the entire mechanism.

6. Revocation is partial

Disconnecting a connected app stops new information from being shared through that connection. It does not remove what the dot already has in its context. Every dot has its own context, which you can reset — and resetting deletes the dot, including its conversations, memories, and scheduled tasks.

For an organisation, the operational version of this is: plan for what leaves with the dot when someone offboards, and prefer reset over "just disconnect it" when sensitive material was in play.

7. Data handling differs by plan, and the difference is meaningful

  • Business, Enterprise, Edu: OpenAI states it does not use your data to train models by default.
  • Personal plans: the "Improve the model for everyone" setting governs whether your dot's conversations and work may be used for model improvement. That can include actions the dot takes, work it delegates to other agents, automations you set up, and data from connected apps used to inform conversations.
  • Proactive research: OpenAI states it does not train directly on background research or its notes. But if that information is later pulled into an eligible conversation or task, it may be used according to your settings.

If the data matters, read the settings — not the marketing.

8. Surface limits that trip people up

  • You cannot create a dot on mobile, and mobile web is not supported.
  • Texting is a limited beta for Pro users in the US, unavailable in Business and Enterprise workspaces, and runs through a third-party provider. OpenAI warns about sharing sensitive information over text.
  • Not available to users under 18.
  • Pro is not available in the EEA, Switzerland, or the UK at launch, even though Business Premium is available across supported regions.

9. Availability risk is a real operational risk

The help center currently carries a notice that OpenAI is gradually rolling out DevDay features and that some may not yet be available to your account. If your workflow depends on a dot, that dependency inherits OpenAI's rollout schedule. Build the fallback first.

We keep a public list of what remains unconfirmed in our source index. If you find documentation that contradicts anything above, send it to us — corrections are published with a dated note.

Sources

Found an error or a fact that has changed since our last update? Tell us — corrections are published, not quietly edited.