01是什么:常驻智能体与 DotsWhat Are Always-On Agents and Dots
Dots 是 OpenAI 在 2026-09-29 的 DevDay 上发布的 ChatGPT 常驻智能体(always-on agents)。官方描述是:用户给一个 dot 设定目标、连接需要的应用、定义它的自主程度,它就在自己的云端电脑和浏览器里持续工作,在两次对话之间也不停,并把结果交回给你审阅。据报道,每个 dot 由 GPT-6 Astra 驱动,可连接 4000+ 应用及 Slack/Teams。
Dots are ChatGPT's always-on agents, announced by OpenAI at DevDay on 2026-09-29. As OpenAI describes it, you give a dot a goal, connect the apps it needs and define how autonomous it may be; it then keeps working in its own cloud computer and browser, including between conversations, and returns results for your review. According to reports, each dot is powered by GPT-6 Astra and connects to 4,000+ apps plus Slack/Teams.
和传统的"你问一句、它答一句"的聊天助手相比,关键差别是触发方式:dot 可以在没有用户提示的情况下继续任务。报道中给出的例子包括:监控客户反馈、实现修复并提交 pull request、在产品范围变化时更新材料、用新数据重跑分析、修订提案、搭建概念验证集成,以及把访谈转录稿转成短视频片段和社交帖子。早期测试者的一个例子是一个 dot "与客服谈判,每年省下约 500 美元费用"(Latent Space 转述)。
Compared with a classic "you ask, it answers" assistant, the key difference is the trigger: a dot can continue a task without a user prompt. Examples in the coverage include monitoring customer feedback, implementing fixes and submitting pull requests, updating materials when product scope changes, rerunning analyses with new data, revising proposals, building proof-of-concept integrations, and turning interview transcripts into clips and social posts. One early tester reported a dot "negotiating with customer service to cut ~$500/yr in charges" (as relayed by Latent Space).
02DevDay 2026 全景:Dots 不是孤立发布DevDay 2026 in Context: Dots Did Not Ship Alone
Dots 是一整套发布的一部分。下表按 OpenAI 官方回顾与 Latent Space 的整理,列出与"常驻智能体"最相关的部分(价格与基准为发布时厂商/媒体口径,未经独立复现)。
Dots shipped as part of a larger bundle. The table below, based on OpenAI's recap and Latent Space's write-up, lists the pieces most relevant to always-on agents (prices and benchmarks are vendor/press figures at launch and have not been independently reproduced).
| 发布 | 要点 |
|---|---|
| Dots | 自己的云端电脑;4000+ 应用;三级权限规则;Pro / Business Premium / Enterprise(beta) |
| GPT-6.1 Sol | $2 / $10 每百万 token;缓存输入 $0.10;上下文 1,050,000;DeepSWE v1.1 75.2%、OSWorld 2.0 71.4%(Vellum 整理) |
| Ultrafast 速度档 | Codex 中最高 8× 生成速度(300 tok/s)、API 中 6×;价格约为标准价 6 倍 |
| Decisions API | 基于 GPT-6 Luna 的近即时多选分类与路由,支持文本与图像 |
| Agents API(含 computer use) | 多 agent 与软件交互能力;另有与 AWS 合作的 Bedrock Managed Agents |
| Codex Cloud / CLI | 云端环境在合上笔记本后仍可运行;CLI 增加 worktrees 与 /agents 视图 |
| 套餐与生态 | 新增 Pro 500 档;Sign in with ChatGPT;OpenAI Marketplace;ChatGPT 周活 12 亿 |
| Release | Key points |
|---|---|
| Dots | Own cloud computer; 4,000+ apps; three-tier permission rules; Pro / Business Premium / Enterprise (beta) |
| GPT-6.1 Sol | $2 / $10 per million tokens; cached input $0.10; 1,050,000 context; DeepSWE v1.1 75.2%, OSWorld 2.0 71.4% (per Vellum) |
| Ultrafast tier | Up to 8× generation speed (300 tok/s) in Codex, 6× in the API; priced ~6× standard |
| Decisions API | Near-instant multiple-choice classification and routing on GPT-6 Luna, text and image input |
| Agents API (with computer use) | Multi-agent and software-interaction capabilities; plus Bedrock Managed Agents with AWS |
| Codex Cloud / CLI | Cloud environments keep running with the laptop closed; CLI adds worktrees and an /agents view |
| Plans & ecosystem | New Pro 500 tier; Sign in with ChatGPT; OpenAI Marketplace; 1.2 billion weekly ChatGPT users |
03架构拆解:一个 dot 里有什么Architecture: What Is Inside a Dot
把公开信息拼起来,一个 dot 可以看成五个部件:模型(GPT-6 Astra)、云端电脑与浏览器(执行环境)、应用连接层(4000+ 应用,经 OpenAI 的插件生态接入,另可从桌面/网页/移动端 ChatGPT、Slack、Teams 交互,SMS 即将支持)、它写给自己的笔记(并据反馈随时间改进),以及规则闸门。连接用户自己的机器是可选项。
Piecing together the public information, a dot has five parts: the model (GPT-6 Astra), a cloud computer and browser (the execution environment), an app connection layer (4,000+ apps through OpenAI's plugin ecosystem; users can also interact from desktop/web/mobile ChatGPT, Slack and Teams, with SMS coming), notes the dot writes to itself (it also "learns from feedback over time"), and a rules gate. Connecting your own machine is optional.
04权限与安全:三级规则 + 自动复核Permissions and Safety: Three-Tier Rules Plus Auto-Review
常驻意味着没人盯着,所以权限设计是 Dots 最值得学的部分。官方说明是:用户设置自定义规则(Custom Rules),把动作分成三类——可以自行执行的、需要先审批的、禁止执行的。此外:改密码这类操作始终由用户自己完成;系统内置自动复核(auto-review),对照用户指令与安全要求检查动作;内置安全监控用于防御恶意指令,并可以暂停运行。OpenAI 也明确写道 dots "可能犯错"。
Always-on means nobody is watching, so permission design is the most instructive part of Dots. OpenAI's description: users set Custom Rules that sort actions into three buckets — what the dot may do on its own, what needs approval first, and what is prohibited. In addition, sensitive actions such as password changes always stay with the user; a built-in auto-review checks actions against the user's instructions and safety requirements; and built-in security monitoring defends against malicious instructions and can pause operation. OpenAI also states plainly that dots "can still make mistakes."
隐私与训练数据
Privacy and Training Data
- Business、Enterprise、Education 工作区的内容默认不用于训练;
- 个人套餐的用户可以控制 dot 对话是否用于训练;
- OpenAI 称:"不会直接用主动研究或 dot 写给自己的笔记来训练",但相关信息可能按用户设置影响符合条件的任务。
- Content from Business, Enterprise and Education workspaces is not used for training by default;
- On personal plans, users control whether dot conversations are used for training;
- OpenAI states it "doesn't train directly on proactive research or a dot's notes to itself", though information may inform eligible tasks depending on user settings.
05配套件:Decisions API、Codex Cloud 与 Sol 的成本曲线Companion Pieces: Decisions API, Codex Cloud and Sol's Cost Curve
常驻智能体的经济性取决于"每一步用多贵的脑子"。DevDay 同时给出了分层的积木:Decisions API(GPT-6 Luna,近即时的多选分类与路由,不做深度推理)适合做"这封邮件要不要升级、该派给谁"这类分流;GPT-6.1 Sol($2/$10,缓存输入 $0.10)被官方描述为"近 Astra 智能、五分之一价格";Codex Cloud 让代码类任务在你合上笔记本后继续跑。
The economics of an always-on agent depend on how expensive a "brain" each step uses. DevDay shipped layered building blocks: the Decisions API (GPT-6 Luna; near-instant multiple-choice classification and routing without deep reasoning) suits triage such as "escalate this email, and to whom"; GPT-6.1 Sol ($2/$10, cached input $0.10) is described as "near-Astra intelligence for a fifth of the price"; Codex Cloud lets coding tasks keep running after you close your laptop.
按 Vellum 的整理,Sol 在 DeepSWE v1.1 达 75.2%(与 GPT-6 Astra 持平,单任务成本约低 80%),OSWorld 2.0 为 71.4%(Astra 73.5%,成本约七分之一);同一来源中 Claude Sonnet 5.5 为 71.0%。Google 官方称 Gemini 4 Argon 为 77.9%。三者口径来自各自发布方,不宜直接当作同台对比。
Per Vellum, Sol reaches 75.2% on DeepSWE v1.1 (matching GPT-6 Astra at roughly 80% lower per-task cost) and 71.4% on OSWorld 2.0 (Astra: 73.5%, at about one-seventh the cost); in the same source Claude Sonnet 5.5 scores 71.0%. Google says Gemini 4 Argon scores 77.9%. These figures come from different publishers and should not be treated as a like-for-like comparison.
06怎么用:把 Dots 的思路搬到自己的 agent 工程How To Use It: Carrying the Dots Ideas Into Your Own Agent Engineering
如果你手头有 Pro、Business Premium 或已开启 beta 的 Enterprise 工作区,第一个 dot 是包含在套餐里的(Pro 先在符合条件的市场推出,不含 EEA、瑞士、英国)。无论是否使用 Dots,下面这套做法都适用于任何"无人值守 agent"(以下为基于公开信息的分析建议):
If you have Pro, Business Premium or an Enterprise workspace with the beta enabled, your first dot is included in the plan (Pro is rolling out first in eligible markets, excluding the EEA, Switzerland and the UK). With or without Dots, the following applies to any unattended agent (the points below are analysis based on public information):
- 先写规则,再给目标:列出这个 agent 会碰到的 10 个最常见动作,分到"自主 / 审批 / 禁止"三栏,再开始使用。
- 从只读任务起步:先让它监控、汇总、起草;把"发送、付款、合并"留在审批栏。
- 给高风险动作设人工专属区:参考"改密码始终由用户完成"的做法,明确哪些动作永远不交给 agent。
- 分层选模型:路由/分类走轻量接口,难推理才上大模型;并留意缓存价对长上下文的影响。
- 留暂停键与审计记录:任何时候都能一键暂停,并能回看它做过什么、为何这样做。
- Write the rules before the goal: list the ten most common actions the agent will meet and sort them into auto / approve / prohibited before you start.
- Start with read-only work: let it monitor, summarize and draft first; keep send, pay and merge in the approval bucket.
- Reserve a human-only zone: following "password changes always stay with the user", decide which actions are never delegated.
- Tier your models: use a lightweight interface for routing/classification and a large model only for hard reasoning; mind how cached-input pricing affects long contexts.
- Keep a pause button and an audit trail: be able to pause any time and review what it did and why.
07什么场景该用When To Use It
| 场景 | 适配度 | 原因 |
|---|---|---|
| 持续监控 + 定期汇总(客户反馈、竞品、指标) | 高 | 触发靠"持续在线",产出可审阅,出错代价低 |
| 起草并提交可回滚的变更(PR、文档更新) | 中高 | 结果落在可审查的载体上,配合审批规则可控 |
| 对外沟通、谈判、付款 | 中低 | 不可逆或影响真实关系,应放审批栏或禁止栏 |
| 涉及账户安全(改密码等) | 不适用 | 官方设定始终由用户亲自完成 |
| Scenario | Fit | Why |
|---|---|---|
| Continuous monitoring + periodic summaries (feedback, competitors, metrics) | High | Value comes from being always on; outputs are reviewable and errors are cheap |
| Drafting and submitting reversible changes (PRs, doc updates) | Medium–high | Results land in reviewable artifacts; approval rules keep it controlled |
| Outbound communication, negotiation, payments | Medium–low | Irreversible or touches real relationships; belongs in approve or prohibited |
| Account security (password changes etc.) | N/A | By design always done by the user |
08常见坑与局限Pitfalls and Limitations
- 官方承认会犯错:"dots can still make mistakes",所以审批栏不能为了省事而清空。
- 地区与套餐限制:Pro 的发布暂不含 EEA、瑞士、英国;Enterprise/Edu/Healthcare 默认关闭,需管理员启用。
- 计量口径容易误解:主 dot 的直接工作不计套餐用量,但派生的 Codex 任务会计入(Latent Space),预算时要分开看。
- 套餐调整有争议:Latent Space 称 Pro 500 的新倍率体系使原 Pro 200 的价值约减半并引发用户不满;具体以官方定价页为准。
- 提示注入仍是长期风险:同期 arXiv 论文《Securing Computer-Use Agents Against Branch Steering Attacks》(2610.03089)专门讨论 GUI 智能体被诱导转向的问题——能操作浏览器的 agent 尤其需要这类防御。
- OpenAI admits mistakes happen: "dots can still make mistakes", so don't empty the approval bucket for convenience.
- Regional and plan limits: Pro rollout excludes the EEA, Switzerland and the UK; Enterprise/Edu/Healthcare is off by default and needs an admin to enable it.
- Metering is easy to misread: the primary dot's direct work does not count against plan usage, but spawned Codex tasks do (Latent Space) — budget them separately.
- The plan changes are contested: Latent Space says the new Pro 500 multiplier scheme roughly halved the value of the former Pro 200 and caused backlash; check the official pricing page.
- Prompt injection remains a long-term risk: a concurrent arXiv paper, "Securing Computer-Use Agents Against Branch Steering Attacks" (2610.03089), addresses GUI agents being steered off course — browser-operating agents especially need such defenses.
09对比:Dots 与相邻形态Comparison With Adjacent Forms
| 形态 | 触发方式 | 执行环境 | 典型风险控制 |
|---|---|---|---|
| 聊天助手 | 用户每次提问 | 对话内,通常无独立电脑 | 用户逐条看到结果 |
| Dots(常驻智能体) | 目标 + 持续运行,可无提示继续 | 自己的云端电脑与浏览器 | 三级规则 + 自动复核 + 可暂停 |
| Codex Cloud | 用户发起任务,可在合上笔记本后继续 | 云端环境 | 环境隔离 + 代码评审 |
| 定时任务 / cron 式 agent | 时间表 | 视实现而定 | 通常需自行设计权限与告警 |
| Form | Trigger | Execution environment | Typical risk control |
|---|---|---|---|
| Chat assistant | User asks each time | In-conversation, usually no own computer | User sees each result |
| Dots (always-on agents) | Goal + continuous operation, may proceed without prompts | Own cloud computer and browser | Three-tier rules + auto-review + pausable |
| Codex Cloud | User starts a task; can continue with laptop closed | Cloud environment | Environment isolation + code review |
| Scheduled / cron-style agents | A schedule | Depends on implementation | Permissions and alerts usually self-designed |
10术语表Glossary
- Always-on agent(常驻智能体)
- 不依赖用户逐条提示、可持续运行的 agent。
- Dot
- OpenAI 对 ChatGPT 常驻智能体的称呼,拥有自己的云端电脑与浏览器。
- Custom Rules(自定义规则)
- 用户定义的权限规则:自主执行 / 需审批 / 禁止。
- Auto-review(自动复核)
- 对照用户指令与安全要求检查 agent 动作的机制。
- Decisions API
- 基于 GPT-6 Luna 的近即时多选分类与路由接口。
- Prompt injection(提示注入)
- 通过网页或文档里的恶意文字诱导 agent 偏离用户意图的攻击。
- Always-on agent
- An agent that runs continuously without per-step user prompts.
- Dot
- OpenAI's name for a ChatGPT always-on agent that has its own cloud computer and browser.
- Custom Rules
- User-defined permission rules: autonomous / needs approval / prohibited.
- Auto-review
- A mechanism that checks agent actions against the user's instructions and safety requirements.
- Decisions API
- Near-instant multiple-choice classification and routing interface built on GPT-6 Luna.
- Prompt injection
- An attack in which malicious text in a web page or document steers an agent away from the user's intent.
11参考来源Sources
- OpenAI DevDay 2026 Recap · 2026-09-29
- [AINews] OpenAI DevDay 2026 — Latent Space · 2026-09
- OpenAI launches dots… — MediaNama · 2026-10
- OpenAI launches dots, always-on ChatGPT agents with their own computers — BetaNews · 2026-09
- GPT-6.1 Sol Benchmarks Explained — Vellum · 2026-09/10
- Gemini 4 Argon — Google blog · 2026-09-30
- ArXiv AI Research Weekly Digest 2026-10-05 (agents-radar) · 2026-10-05
- OpenAI DevDay 2026 Recap · 2026-09-29
- [AINews] OpenAI DevDay 2026 — Latent Space · 2026-09
- OpenAI launches dots… — MediaNama · 2026-10
- OpenAI launches dots, always-on ChatGPT agents with their own computers — BetaNews · 2026-09
- GPT-6.1 Sol Benchmarks Explained — Vellum · 2026-09/10
- Gemini 4 Argon — Google blog · 2026-09-30
- ArXiv AI Research Weekly Digest 2026-10-05 (agents-radar) · 2026-10-05
主页