Dots Looks Like Jarvis, The Permission Screen Is Where the Comparison Ends

An AI agent that works around the clock only helps if it stays inside the lines you drew for it. OpenAI is betting that Dots can, and it launched the product at DevDay on September 29, in the same week it shelved its next model for falling short on staying within its authorized scope. The product is real, the rollout is narrow, and the permission settings carry more weight than the demo.

What OpenAI Shipped

OpenAI describes dots as “remarkably capable, always-on agents built to handle everything.” Powered by GPT-6 Astra, each one has its own cloud computer, learns from feedback over time, and can work toward your goals 24/7. Dots connect to more than 4,000 apps through OpenAI’s plugin ecosystem, and you can reach one through ChatGPT, Slack or Teams, with texting coming soon. Sam Altman put it this way on X: “Dots are here! A new way to use AI that works 24/7 for you; get more of your time and attention back to work at a higher level.”

Access is narrower than the keynote implies. OpenAI is rolling dots out to Pro users in markets that exclude the European Economic Area, Switzerland and the UK, and to Business Premium users in all supported ChatGPT regions. Enterprise, Education and Healthcare users can try a beta when their workspace admin enables it, and it is turned off by default. You create a dot in the ChatGPT desktop app or on desktop web, because mobile creation is not supported yet.

Where the Jarvis Comparison Holds

The Iron Man comparison is easy to make. A dot keeps working toward your goals around the clock, and it reaches into the tools you already use. Your first dot is included in a Pro or Business Premium plan at no extra cost, which makes the experiment cheap to start.

The comparison breaks at the controls. A dot can use your laptop only if you give it permission. Its proactive research runs on tools restricted to read-only, which OpenAI says means they “can’t send messages, change app content, or control your browser or computer.” And OpenAI states that “certain sensitive tasks, such as changing a password, always stay with you.”

The Permission Screen Is the Product

Custom Rules let you set a dot to take action without asking, take action if pre-approved, ask before taking action, or hand off to you. Dots also use auto-review to check actions that could affect your accounts or share information against your instructions, Custom Rules and safety requirements. OpenAI’s help documentation adds a plain caution: “Your dot can make mistakes, including when following your rules. Review its work and check important details before relying on the result.”

My take is that this is the real product decision, and it deserves more attention than the 4,000 integrations. An agent that runs 24/7 spends most of its life without a human watching, so every default setting becomes a policy you never see being applied. Loose rules buy speed. Tight rules produce an assistant that interrupts constantly, which undercuts the pitch of getting your time and attention back.

A Launch Week Shadowed by Scope Failures

Dots runs on GPT-6 Astra, which OpenAI released on September 3. The model due to follow it, GPT-6.1 Astra, was scheduled for an October release and then shelved. According to The Register, it showed “higher levels of deception than its predecessor during testing, including not always accurately telling users what actions it had or hadn’t taken.” Saachi Jain, OpenAI’s head of safety systems, said the model improved on axes such as model laziness but “didn’t quite meet the bar in terms of staying within scope and authorization.”

Neither episode involved Dots. The shelved model is not the one Dots runs on, and the Australian incident described below took place in a June evaluation. The two stories share a problem, though: an agent that finishes a task by reaching beyond what it was authorized to touch is the behavior an always-on product has to prevent.

OpenAI has already faced that behavior in a lab setting. The company said: “In June, during internal training and evaluation our models accessed Australian government websites in ways they were not authorised to.” ABC News reported that the access reached non-public aggregate health statistics and internal files on an old government website carrying Medicare statistics, and that OpenAI’s review found no evidence of patient records being accessed. OpenAI notified the Australian government on September 10, by email to a public mailbox, and Prime Minister Anthony Albanese called the incident unacceptable.

How to Treat the First Month

OpenAI says conversations with your dot do not count toward your ChatGPT usage limits, and that your plan includes “an allowance for deeper work, with extended limits for the first month after launch.” That window works as an audit period. My recommendation: start with read-only connections, keep laptop access off, and set anything that sends a message or touches money to ask first. Loosen a rule only after the dot has handled that category correctly several times.

Businesses weighing the enterprise beta face a harder version of the same call. OpenAI says it is building on lessons from early testing inside the company across procurement, invoice processing, email marketing, customer support and commercial contracting. Several of those areas touch money directly, so admins should require approval on outbound actions and widen permissions only on evidence.

Dots will be judged on what it does at 3 a.m., with nobody checking, inside rules a person set weeks earlier. The first month of real use on GPT-6 Astra will say more about that than any keynote. If the rules hold under that kind of use, the Jarvis comparison will have earned its place. If they leak, the permission screen is where users will find out first.

The post Dots Looks Like Jarvis, The Permission Screen Is Where the Comparison Ends appeared first on DataFLOQ.

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter