
A persistent AI agent continues working across connected tools after the user steps away, while permission controls define what it is allowed to access and do. AI-generated image via ChatGPT (OpenAI)
OpenAI DevDay 2026: AI Agents Become Persistent Workers — What Should They Be Allowed to Do?
At DevDay 2026, OpenAI announced more than 20 products and features spanning persistent agents, new models, computer use, collaboration and automation — together pointing beyond chat toward AI systems designed to keep working after users step away.
The bigger story is how the announcements work together. They provide many of the pieces needed to move AI from request-and-response interaction toward ongoing delegated work. For businesses, developers and increasingly individual users, that changes the decision from simply which AI model or tool should we use? toward a more consequential question: Which responsibilities should we delegate to AI systems that may continue working after we step away?
Axios described DevDay as pushing AI further beyond the chatbot and toward software that can work independently on users’ behalf, highlighting Dots, GPT-6.1 Sol, ChatGPT Space, the Decisions API and cloud-based Codex among the event’s biggest announcements. Dots, for example, are designed to keep working on projects in the background, while Space gives teams, ChatGPT and agents a persistent place to share information and work together.
DevDay suggests OpenAI is assembling an environment for that kind of persistent AI work. Models provide the intelligence. Agents provide continuity. APIs, computer use and Codex provide ways to execute work. Plugins and connected applications supply tools and data. Events and schedules can initiate work without a new prompt. Shared spaces give people and agents common context. And permissions, privacy protections and approval systems establish boundaries around what those increasingly capable agents are allowed to do.
To understand what that shift could mean, it first helps to look at what OpenAI actually announced — and how the pieces begin to fit together.
Key Takeaways: What OpenAI DevDay 2026 Means for AI Agents and Businesses
OpenAI DevDay 2026 shows AI moving from interaction toward delegation, with models, agents, tools, triggers, shared context and permission systems increasingly working together so AI can continue assigned work after users step away.
GPT-6.1 Sol lowers the cost of capable agentic AI, making continuous and multi-step AI workflows more practical to run at scale. OpenAI says Sol approaches GPT-6 Astra on several agentic workloads while costing substantially less.
Dots add persistence by allowing AI agents to keep working toward a goal between conversations. They can maintain context, respond to new information, use connected applications and continue making progress without requiring a new prompt for every step.
OpenAI is expanding how agents can act through computer use, the Agents API, the Decisions API and cloud-based Codex. Together, these tools let agents operate software, make bounded choices, execute workflows and continue work remotely after a user steps away.
ChatGPT Space, Pages, plugins, MCP Events and Team Tasks provide the context, tools and triggers persistent agents need to keep work moving. AI can increasingly begin assigned work when an authorized event occurs instead of waiting for a person to initiate every interaction.
As AI agents gain more autonomy, businesses must decide what those systems are allowed to access and do. OpenAI is adding permissions, approvals, Custom Rules, Auto-review and privacy protections, while NVIDIA is developing software- and hardware-level enforcement for autonomous agents.
The central business question is shifting from what AI can do to what AI should be authorized to do. Persistent agents make capability, access, data protection, human approval and governance increasingly important parts of AI adoption.
OpenAI DevDay 2026: New AI Agents, Models, Computer Use and Automation
Seen individually, the DevDay releases look like a collection of models, agents, developer tools and workplace features. Put together, they begin to show the different pieces OpenAI is building for AI systems that can take on work, continue it over time and act across applications.
On the intelligence side, OpenAI introduced GPT-6.1 Sol, a lower-cost model that the company says approaches GPT-6 Astra on agentic coding, computer use and professional work, along with an Ultrafast inference tier for workloads where speed matters most. For persistent work, OpenAI introduced Dots — always-on agents designed to take on ongoing responsibilities — and previewed Specialist Dots for more defined roles inside organizations.
OpenAI also expanded the ways AI can act. The Agents API gained computer use and multi-agent capabilities, while the new Decisions API can make choices from a predefined set of answers. Codex can now continue development work in the cloud, and Codex Security Cloud can run security scans on demand or on a schedule, investigate findings and prepare fixes even when the user’s computer is closed.
Other announcements built out the environment around those agents. ChatGPT Space gives teams, ChatGPT and Dots shared context; Pages creates documents where people and agents can work together; MCP Events can start automations when something changes in a connected application; and Team Tasks can run recurring work or respond to events such as a new email or Slack message. OpenAI also announced expanded plugins, Slack and Microsoft Teams integration, the Meetings plugin, Private Intelligence, Sign in with ChatGPT, the OpenAI Marketplace, Pro 500 and additional developer and collaboration features. For a full list of the announcements, readers can see OpenAI’s DevDay 2026 recap.
The announcements become easier to understand when they are grouped by what persistent AI work requires rather than simply listed by product name. An AI worker needs intelligence, but it also needs continuity, ways to take action, access to tools and information, context about the work, triggers that tell it when something has changed and boundaries around what it is allowed to do.
That starts with the intelligence itself — and with making capable agentic AI economical enough to use across more kinds of work.
GPT-6.1 Sol Makes Capable AI Agents Cheaper to Run
OpenAI introduced GPT-6.1 Sol as a lower-cost model that nearly matches GPT-6 Astra on several kinds of agentic work. The company specifically points to coding, computer use, professional tasks and multi-step business workflows — the kinds of work that become increasingly important when AI is expected to do more than answer a single request.
The cost difference is significant. OpenAI says GPT-6.1 Sol delivers near-Astra intelligence at one-fifth of Astra’s standard input and output token prices. Astra costs $10 per million input tokens and $50 per million output tokens, compared with $2 and $10 for Sol. Cached input is $1 per million tokens for Astra and $0.10 for Sol.
The difference also shows up in computer-use tasks. On OpenAI’s reported OSWorld 2.0 evaluation, which tests agents on long-running computer-use tasks, Sol came within 2.1 percentage points of Astra at maximum reasoning effort while costing roughly one-seventh as much per task.
Those are OpenAI’s own benchmark results, not independent proof that Sol will perform the same way in every real-world workflow. But the economics still matter. An AI system that works continuously may need to analyze information, make repeated tool calls, operate software and revisit a task many times. The more each step costs, the harder it becomes to use capable models across large numbers of ongoing tasks.
GPT-6.1 Sol is available to Plus, Pro, Business, Enterprise and Edu users in ChatGPT Work and Codex, although it is not yet available in regular Chat. Developers can also access it through the OpenAI API.
Lowering the cost of capable agentic work makes it easier to use AI across more workflows. But a capable model still needs to be given something to do. For AI to keep working toward a goal after the user steps away, it needs something that can maintain context and continue acting over time.
That is where Dots come in.
OpenAI Dots Turn AI Agents Into Always-On Workers
GPT-6.1 Sol makes capable agentic AI less expensive to run. Dots add something different: persistence. OpenAI describes Dots as always-on agents powered by GPT-6 Astra that can keep working toward a goal between conversations. Each Dot has its own cloud computer and browser and can connect through OpenAI’s plugin ecosystem to more than 4,000 apps.
A Dot can take on a project and continue working without the user directing every step. It can handle several projects at once, use connected applications and its cloud computer, and carry context across ChatGPT, Slack and Microsoft Teams. It can also report back with progress, questions or decisions that need the user’s input.
What makes that different from simply leaving a task running in the background is that a Dot can respond to new information and decide what work needs to happen next without waiting for another prompt. OpenAI gives examples of a Dot monitoring customer feedback and preparing fixes, updating an analysis when new evidence appears, revising a proposal as customer requirements change and turning a newly arrived interview transcript into clips, show notes and social posts.
In the interview example, a new transcript could become available through one of the Dot's connected apps — for example, an email account. Once the transcript appears, the user does not have to notice it, tell the Dot that it arrived or separately ask for each next step. The Dot can see that the transcript came in, identify moments for clips, prepare show notes and draft social posts for the user to review — all without a human having to initiate each step.
In other words, persistence is not just about keeping a process running longer. The agent keeps the goal and context of the work, responds when the situation changes, works out what to do next within the task it has been given and continues making progress without requiring a new prompt for every step.
OpenAI is also extending the idea from a personal agent to an organizational role. Specialist Dots are being tested with enterprises and can have their own identity, credentials and access to company systems. Organizations define the responsibilities each Specialist Dot takes on, the tools it can use and how people review and approve its work.
That does not mean teams of autonomous AI workers have arrived. OpenAI says teams of Dots working together are something it envisions over time, while Specialist Dots are currently limited to focused enterprise pilots.
Dots are beginning to roll out to Pro and Business Premium users in eligible markets. Enterprise users, including Edu and Healthcare, can try the beta when a workspace administrator enables it. The first Dot is included with Pro or Business Premium at no extra charge, along with an allowance for deeper work. OpenAI says users will eventually be able to add more Dots and increase how much work each one can handle.
The important change is that the user no longer has to remain involved in every step of the work. A project can continue between interactions, with the Dot returning when it has progress to report, a question to ask or something that requires approval.
But continuing the work is only part of what an agent needs. To carry out that work, it also needs ways to use software, make decisions and take action.
That is the next piece OpenAI is building.
OpenAI Gives AI Agents Computer Use, Bounded Decisions and Cloud Execution
Dots can keep working over time, but persistence alone does not let an agent complete a job. It also needs ways to use software, make decisions and carry out actions.
OpenAI’s Agents API, now in public beta, is designed for developers building AI systems that need to keep working across multiple steps or longer periods of time. It does not replace OpenAI’s existing Responses API. Developers can still use the Responses API to call models directly and control more of the agent workflow themselves. With the Agents API, OpenAI manages more of the infrastructure behind the agent, including its session, context, orchestration and recovery.
For businesses, that can reduce how much infrastructure developers have to build themselves to keep an agent running reliably over time. Developers can focus more on what the agent is supposed to do, which tools it can use and where it is allowed to work. The Agents API is available to all developers in public beta. OpenAI does not charge a separate fee for the API itself; customers pay for the model tokens, tools and hosted computing resources their agents use.
Computer use gives those agents another way to act. It is now available to all developers through the Agents API public beta, and OpenAI is also making it available in Codex and ChatGPT Work for Pro 500 and Enterprise users. With computer use, an agent can use its own browser session to open websites and interact with software, instead of relying only on services that offer a purpose-built API. Before the agent’s browser opens a new website, the developer’s application can ask the user to approve or deny access to the website. If the site requires an account, the application also handles the sign-in process rather than allowing the agent to log in automatically. OpenAI does not currently list a separate charge specifically for computer use; developers still pay the normal API costs associated with the model and any other paid tools or hosted resources used in the workflow.
OpenAI also introduced the Decisions API, a more specialized tool for making a defined choice inside a larger workflow. An agent using the Agents API might work through an entire customer-service case — gathering information, using tools, checking systems, keeping track of what has happened and continuing across multiple steps. The Decisions API could handle one narrower question inside that process, such as: Is this request about billing, technical support or fraud?
The business defines the allowed choices ahead of time, and the AI chooses among them. That distinction is important for businesses that want AI judgment without giving a system unlimited freedom to decide anything it wants. In other words, the company is essentially saying: Here are the decisions you are allowed to make; choose from these options.
The Decisions API is powered by GPT-6 Luna, OpenAI’s least expensive GPT-6 model. Luna is designed for focused, high-volume work, which makes it a natural fit for decisions such as sorting or routing large numbers of requests. It is also much cheaper to run at scale: Luna costs $0.10 per million input tokens and $0.50 per million output tokens, compared with $2 and $10 for Sol and $10 and $50 for Astra.
The Decisions API is currently in limited preview. OpenAI has not yet published which customers are eligible for the preview or announced separate pricing for the service.
Codex Cloud brings ongoing work to software development. Instead of running a coding task on the developer's own computer, Codex can run it on a remote virtual computer managed by OpenAI. The developer does not buy or maintain that computer; it exists in OpenAI's cloud. Because the work is running there, a task can continue even after the developer closes a laptop and can later be checked from another supported device.
Codex Cloud is available to eligible Plus, Pro, Business, Enterprise, Healthcare and Education users. Standard Codex Cloud environments currently have no separate virtual-machine charge. Usage counts against the user's normal Codex allowance, with additional credits or usage-based billing available depending on the plan.
Codex Security applies the same cloud-based approach to a specific job: finding and helping fix software vulnerabilities. Rather than being another general coding environment, it is designed around a security workflow. It connects to GitHub repositories, builds a threat model for the codebase, investigates potential vulnerabilities, tries to validate them in an isolated environment and proposes patches for human review.
The work runs remotely, and for managed workspaces Codex Security actually requires Codex Cloud access to be enabled. The difference is the job the system has been designed to perform: Codex Cloud handles general coding work, while Codex Security adds a specialized process for finding, validating and helping remediate security problems.
Codex Security is available as a research preview for Pro, Business, Enterprise and Edu users. OpenAI says Codex Security Cloud uses token-based billing, with customers required to opt in before paid usage begins. It has not published a simple fixed price for the service.
Altogether, these tools move AI beyond generating an answer. An agent can operate software, make choices within defined limits, execute workflows and continue working in the cloud after the user steps away.
But acting is only part of the job. An agent also needs access to the right context, tools and information — and something that tells it when new work needs to begin.
That is where OpenAI’s shared workspaces, plugins and event-driven automation come in.
OpenAI Is Building the Environment AI Agents Need to Keep Working
An agent that can act still needs to know where the work lives, what information it can use and when something has changed. Several of OpenAI’s DevDay announcements fill in those pieces by giving agents shared context, access to outside tools and data, and triggers that can start work without waiting for another human prompt.
ChatGPT Space provides the shared context. A team can create a Space where coworkers, ChatGPT and Dots work from the same project knowledge instead of each conversation starting from scratch. ChatGPT can also keep the Space organized according to instructions from the team. For businesses, that gives people and agents a common place to keep the information surrounding ongoing work. Space is available on Pro, Business and Enterprise plans on desktop and web, with some features also available on mobile. OpenAI lists access by plan rather than charging separately for Space.
Pages gives that collaboration somewhere more specific to happen. Pages are shared documents built for people and agents to work on together. A team can write, research, create charts or images and continue refining the same document with ChatGPT or an agent. Pages are also available on Pro, Business and Enterprise plans, with no separate price announced for the feature.
Plugins themselves are not new, but OpenAI expanded what they can do at DevDay. New plugin extensions can give a plugin its own place in the sidebar, add interactive panels beside a conversation and display supported files. OpenAI also updated plugin creation and discovery, including recommendations that can surface relevant plugins during a conversation. Plugins continue to give ChatGPT and agents access to outside services, information and actions that users have authorized, while Dots can connect through OpenAI’s plugin ecosystem to more than 4,000 apps. Plugin extensions and OpenAI’s updated plugin creation and discovery tools are available across all ChatGPT plans.
MCP Events change something even more fundamental: the human does not always have to start the interaction. A connected application can tell ChatGPT that something has happened and trigger an automation. OpenAI gives the example of asking ChatGPT to watch for new tasks on a project board. If a new task is added and includes links to the relevant project documents, for example, ChatGPT can detect that the task was added, open the linked material and draft a plan for completing it — even while the user is away. MCP Events are available across all plans, and OpenAI has not announced a separate price for the feature.
That changes who starts the interaction. Instead of waiting for a person to prompt it, AI can begin assigned work when an authorized event occurs. A new task, message or other change in a connected system can become the starting point.
Team Tasks extends the same idea to work shared across an organization. A team can create work that runs on a schedule or in response to a supported event, using company tools the workspace has approved. For example, ChatGPT could prepare a weekly project update and post it to an approved Slack channel, while authorized teammates can review the results and change the instructions together. Team Tasks are available in Business and Enterprise workspaces, and OpenAI has not announced a separate price for the feature.
OpenAI is also bringing ChatGPT directly into Slack and Microsoft Teams. If an organization enables ChatGPT in Slack or Microsoft Teams, employees can mention @ChatGPT in a channel or message it directly to ask questions, summarize a discussion or draft work. ChatGPT can also use company tools that the organization has connected and approved, subject to those tools’ permissions.
That lets people work with ChatGPT inside communication tools they already use, while Space and Pages give teams shared places to build on the same work. These features reduce the need to constantly move information into a separate AI conversation before the AI can help.
OpenAI is also adding ways for agents to divide work among other agents. GPT-6.1 Sol supports multi-agent delegation in beta through the Responses API. A main Sol agent can create subagents to handle separate parts of a task in parallel, then bring their work back together into a final result. For example, different subagents could research separate sources or investigate different possible causes of a software problem at the same time.
The Agents API also supports multi-agent delegation, but inside the managed agent environment described earlier. A primary agent can assign work to separate subagents while OpenAI keeps the larger session, tools, context and execution environment running. In simple terms, Sol can divide a particular task among subagents, while the Agents API provides the infrastructure for multiple agents to work within a longer-running agent workflow.
Neither should be confused with OpenAI’s future vision for teams of Dots. Dots are persistent agents with their own ongoing projects and context; OpenAI says teams of those persistent agents working together are still a future goal.
This is where the DevDay announcements begin to form an operating environment for persistent AI work, bringing together the pieces an agent needs to keep a job moving.
Capability → models
Persistence → Dots
Execution → Agents API, computer use and Codex
Decisions → Decisions API
Context → Space and Pages
Tools and data → plugins and connected apps
Triggers → MCP Events and Team Tasks
Collaboration → people, agents and multi-agent delegation
Once those pieces are connected, the next question becomes harder to avoid: Who decides what the agent is allowed to do?
That question becomes more important as the agent gains access to more information, applications and ways to act.
OpenAI Adds Permissions and Privacy Protections as AI Agents Gain Autonomy
The more an AI agent can do on its own, the more important it becomes to define what it is actually allowed to do. OpenAI’s DevDay announcements show the company expanding what agents can do while building controls around their access, actions and use of sensitive information.
Dots provide one of the clearest examples. When a Dot is proactively researching in the background without the user actively participating, its connected-app tools are restricted. It cannot directly send messages to other people, change content through plugins or take control of a browser or computer. In other words, the Dot may be capable of taking some of those actions in other circumstances, but background research does not automatically give it permission to do them.
Users can also set Custom Rules that tell a Dot which supported actions it may take on its own, which require approval and which should be handed back to the user. Those rules cannot override OpenAI’s built-in safety requirements. Some actions remain human-only; for example, a Dot may require the user to take over to change a password.
OpenAI adds another layer through Auto-review, which checks certain planned actions against the user’s instructions, Custom Rules and safety requirements before they happen. OpenAI gives the example of a Dot preparing to send an email: Auto-review can check the recipient and message for problems before allowing the action to continue. Depending on what it finds, the Dot may continue, ask the user for clarification or approval, try another permitted approach or stop.
Specialist Dots extend the same idea into the workplace. These enterprise agents can have their own identities, credentials and access to company systems, but organizations decide what responsibilities they are assigned, which tools they can use and where human review is required. OpenAI also plans to integrate Specialist Dots with Microsoft Agent 365 so organizations can manage them through existing governance and security controls.
The same pattern appears in computer use. As discussed earlier, an agent’s browser can require user approval before opening a new website, while sign-in remains a controlled part of the application rather than something the agent can simply do on its own.
None of these safeguards means autonomous agents are mistake-proof. OpenAI explicitly warns that Dots can make mistakes and tells users to review consequential work. The important point is narrower: as OpenAI increases what agents are capable of doing, it is also creating ways to separate actions they may perform independently from actions that require approval or remain off-limits.
Permissions answer one trust question: What is the agent allowed to do? But OpenAI also introduced new Private Intelligence protections aimed at a different trust question: What happens to sensitive information while the AI is doing the work?
Private Intelligence includes Zero Data Retention with Private Safety Processing. Zero Data Retention means OpenAI does not retain an approved API customer’s prompts or model responses after a request is processed. Private Safety Processing adds automated safety checks across related interactions without giving OpenAI personnel access to the underlying customer content. When information needs to be retained for that safety review, it remains encrypted in storage controlled by the customer, while OpenAI receives only limited safety signals rather than the underlying content. The goal is to let businesses use more advanced AI while keeping tighter control over sensitive information.
Access is currently limited to API organizations approved for Zero Data Retention, and OpenAI directs interested customers to contact its sales team about eligibility. OpenAI has not announced separate public pricing for Private Intelligence. A preview of another capability, Private Inference, is planned for this fall.
That distinction matters for businesses using agents for work involving finance, human resources, customer information, legal documents or other sensitive material. Giving an agent permission to access the systems it needs is only half of the trust question. Organizations also need to know what protections remain around the information the agent accesses and reasons over while completing the work.
OpenAI is not alone in treating agent authority as an infrastructure problem. NVIDIA’s Open Agent Safety Platform takes a different approach, enforcing boundaries around autonomous agents at both the software and hardware levels.
NVIDIA’s new OpenShell provides a secure runtime environment around the agent that tracks its actions and enforces policies about what it may access and do. NVIDIA Sentry adds a separate hardware-based watchdog running on BlueField-4 DPUs. If an agent attempts to move outside its permitted software boundary, NVIDIA says Sentry can quarantine and stop it in milliseconds.
The two companies are approaching the problem from different parts of the system. OpenAI is building permissions, approvals, identities and human review into the agent and the products around it. NVIDIA is adding another enforcement layer outside the agent itself, so the environment in which the agent operates can impose boundaries even if the agent tries to move beyond them.
The timing makes the connection difficult to miss. On September 28, NVIDIA introduced infrastructure designed to control what autonomous agents are permitted to do. On September 29, OpenAI introduced infrastructure that gives agents substantially more ways to keep working, access information, use software and take action.
As agents gain persistence and more ways to act, capability and authority become two different questions. An AI system may be technically capable of performing an action without necessarily having permission to perform it.
OpenAI’s DevDay shows that building persistent AI workers requires more than increasing intelligence. It also requires systems that govern access, actions, information and human oversight.
And that may become just as important as what the AI itself is capable of doing.
What OpenAI DevDay 2026 Means for Businesses Using AI Agents
The main change is that AI adoption is beginning to move from interaction to delegation. Instead of using AI only when someone opens a chat and asks for help, organizations can increasingly assign AI systems goals, tools, triggers and ongoing responsibilities that allow work to continue between human interactions.
Businesses and developers now have a larger set of decisions to make: Which responsibilities can an AI system handle continuously? What information and applications should it be allowed to access? Which actions can it complete on its own? Where should human approval still be required? And how should the information it uses be protected while the work is happening?
The infrastructure for that kind of delegated AI work is becoming easier to see, but it is not finished. Dots are only beginning to roll out. Specialist Dots remain in enterprise pilots. Teams of Dots are still a future goal. The Decisions API is in limited preview, multi-agent capabilities remain in beta, and OpenAI itself warns that Dots can make mistakes.
Even at this early stage, many of the pieces needed for persistent AI work are beginning to work together: intelligence, agents, computer use, decisions, shared context, connected applications, event-driven triggers and permission systems.
If persistent agents become a normal part of work, AI governance will increasingly depend on more than how intelligent the model is. Organizations will also need to decide what agents can access, how the data they use is protected, what actions they may take independently and where human approval remains mandatory.
And that brings the story back to the question underneath many of OpenAI’s DevDay announcements: If AI is becoming something we delegate work to rather than something we simply ask questions of, the defining question may increasingly shift from “What can this AI do?” to “What should this AI be authorized to do?”
Capability does not mean authority.
Q&A: What OpenAI DevDay 2026 Means for AI Agents and Businesses
Q: What was the biggest change announced at OpenAI DevDay 2026?
A: The biggest change was not one individual product, but the way OpenAI’s announcements begin to support persistent, delegated AI work. New models, agents, APIs, computer use, shared workspaces, plugins, event triggers and permission systems increasingly give AI the pieces needed to keep working toward a goal after a user steps away.
Q: What are OpenAI Dots, and how are they different from regular ChatGPT?
A: OpenAI Dots are always-on AI agents that can continue working toward a goal between conversations. Unlike a normal chat that typically waits for another user prompt, a Dot can maintain context, respond when new information appears, use connected applications and continue making progress within the responsibilities it has been given.
Q: What is GPT-6.1 Sol, and why does it matter for AI agents?
A: GPT-6.1 Sol is designed to make capable agentic work less expensive to run. OpenAI says Sol approaches GPT-6 Astra on several agentic workloads while costing substantially less, which could make continuous and multi-step AI workflows more economical to use at scale.
Q: How can OpenAI agents take action instead of just answering questions?
A: OpenAI is giving agents several ways to act through computer use, the Agents API, the Decisions API and cloud-based Codex. These tools can let AI operate software, make choices from predefined options, execute multi-step workflows and continue work remotely even after a user closes their computer.
Q: Can OpenAI agents start working without someone sending another prompt?
A: Yes. MCP Events and Team Tasks can allow authorized events or schedules to initiate AI work without a new human prompt. A change in a connected application, a new task or a recurring schedule can become the trigger that starts an assigned workflow.
Q: Are OpenAI’s new agent features available now?
A: Some are available now, while others are still rolling out, in beta or in limited preview. GPT-6.1 Sol, the Agents API, computer use, Codex Cloud, Space, Pages and several automation features have broader availability, while Dots are still rolling out, Specialist Dots remain in enterprise pilots and the Decisions API is in limited preview.
Q: What controls does OpenAI use to keep AI agents from doing whatever they want?
A: OpenAI is adding permissions, approvals, Custom Rules, Auto-review, controlled sign-in and privacy protections to separate what an agent is technically capable of doing from what it is actually authorized to do. Some actions can be performed independently, while others may require human approval or remain off-limits.
Q: Why does AI agent authorization matter for businesses?
A: AI agent authorization determines what systems, data and actions an AI worker is allowed to access or control. As businesses delegate more ongoing work to AI, they will need to decide which responsibilities agents can handle independently, where human approval is required and how sensitive information is protected during the work.
Q: What is the main business takeaway from OpenAI DevDay 2026?
A: The main business takeaway is that AI adoption is beginning to shift from asking AI for help toward delegating ongoing responsibilities to AI systems. As that shift develops, businesses will need to evaluate not only what an AI agent can do, but what it should be authorized to do.
Sources:
OpenAI: GPT-6.1 Sol
https://openai.com/index/introducing-gpt-6-1-sol/OpenAI: Introducing dots
https://openai.com/index/introducing-dots/OpenAI: DevDay 2026 Recap
https://openai.com/index/devday-2026-recap/OpenAI Developer Community: DevDay 2026 announcements and developer resources
https://community.openai.com/t/devday-2026-announcements-and-developer-resources/1402006OpenAI API: Changelog
https://developers.openai.com/api/docs/changelogAxios: The 5 biggest announcements from OpenAI's blockbuster AI conference
https://www.axios.com/2026/09/29/openai-dev-day-2026-dots-space-solOpenAI Help Center: Getting started with your dot
https://help.openai.com/is-is/articles/20001530-getting-started-with-your-dotOpenAI Help Center: Manage dots in ChatGPT workspaces
https://help.openai.com/nb-no/articles/20001554-manage-dots-in-chatgpt-workspacesOpenAI Help Center: Connected apps in ChatGPT
https://help.openai.com/en/articles/11487775-connected-apps-in-chatgptOpenAI API: Agents API
https://developers.openai.com/api/docs/guides/agents-api/overviewOpenAI API: Computer use
https://developers.openai.com/api/docs/guides/agents-api/tools/computer-useOpenAI Help Center: Using Codex Cloud
https://help.openai.com/en/articles/20001545-using-codex-cloudOpenAI Help Center: Using Codex with your ChatGPT plan
https://help-lb.openai.com/en/articles/11369540-using-codex-with-your-chatgpt-planOpenAI Help Center: Codex Security
https://help.openai.com/en/articles/20001107-codex-securityOpenAI: Introducing the Agents API
https://openai.com/index/introducing-the-agents-api/OpenAI API Reference: API Overview
https://developers.openai.com/api/reference/overviewOpenAI API: GPT-6 Luna Model
https://developers.openai.com/api/docs/models/gpt-6-lunaOpenAI API: Pricing
https://developers.openai.com/api/docs/pricingOpenAI Developers: MCP Events
https://developers.openai.com/plugins/build/mcp-eventsOpenAI Help Center: Creating and managing team tasks in ChatGPT
https://help.openai.com/en/articles/20001540-creating-and-managing-team-tasks-in-chatgptOpenAI Help Center: Setting up and managing @ChatGPT in Slack and Microsoft Teams
https://help.openai.com/en/articles/20001538-setting-up-and-managing-chatgpt-in-slack-and-microsoft-teamsOpenAI API: Multi-agent
https://developers.openai.com/api/docs/guides/responses-multi-agentOpenAI API: Multi-agent
https://developers.openai.com/api/docs/guides/agents-api/multi-agentOpenAI Help Center: Dots privacy, security, and safety FAQs
https://help.openai.com/en/articles/20001529-dots-privacy-security-and-safety-faqsNVIDIA Newsroom: NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment
https://nvidianews.nvidia.com/news/open-agent-safety-platform
Editor’s Note: This article was created by Alicia Shapiro, CMO of AiNews.com, with writing support, AEO/GEO/SEO optimization, image concept development, and editorial structuring support from ChatGPT, an AI assistant. All final editorial decisions, perspectives, and publishing choices were made by Alicia Shapiro.

