What OpenAI’s Dots reveal about AI agents at work

OpenAI’s Dots look approachable, but the product feels aimed more at work than casual shopping. In early hands-on use, the agent struggled with security checks and payment flows, while performing better on controlled creative and website tasks.

What OpenAI’s Dots reveal about AI agents at work

OpenAI’s Dots arrive with friendly avatars and customizable names, but the early experience described in the source points to something more practical than playful. This is an AI agent built around doing work through software, even if it can also attempt everyday chores like booking an appointment or ordering food.

The result is a useful snapshot of where AI agents stand right now: capable in controlled environments, less reliable when the open web pushes back with security checks, payment steps, and account barriers.

A friendly face on workplace software

OpenAI announced Dots earlier this week. Like Meta Muse, Dots use blobby, anthropomorphic avatars and names users can customize. OpenAI says people will eventually be able to have multiple Dots, but for now the experience gives users one.

The interface is familiar for anyone who has seen recent consumer AI agents. A user chats with the agent in one window while watching it operate inside a virtual machine in another. That setup makes the work visible: the agent can click, navigate, and attempt tasks while the user follows along.

But Dots are not positioned in the same way as lighter consumer agents. The source frames them as closer to coworkers than personal shoppers. The agent’s virtual machine can access apps including Blender and GIMP from the start, and users can also give it access to their own computer through the desktop ChatGPT app.

There is also a voice layer. Users can call their Dot to talk through work out loud, which matters because some tasks are easier to explain conversationally than to specify in a single prompt.

The rollout reinforces the work-first impression. OpenAI is offering Dots first to users on its highest-tier accounts, including the $100-per-month Pro account. By contrast, Muse and Instinct cost nothing for now, according to the source.

Everyday errands exposed the weak spots

OpenAI says Dots “can do nearly anything” with its cloud computer and app access. The source tested that claim with personal tasks, and the results were uneven.

One attempt involved scheduling an installation appointment for a new internet service provider. Dot made meaningful progress and even found a $100 promotional discount in an email that had been mass deleted. Then it hit a “human check.”

The issue was simple but revealing: the bot could not complete a sustained mouse hold. Dot asked the user to open its browser and hold “Press & Hold” until the check completed, then report back so it could continue.

That is the kind of failure that shows the gap between an agent that can navigate a website and an agent that can finish a real transaction without help. The task moved forward, but only because a human stepped in.

Payment created another obstacle. Dot reached a checkout screen and asked the user to enter bank account details. There was no Stripe-style integration like Muse has for storing credit card information and using a virtual card at checkout. The provider also needed a bank account to unlock a $5 monthly bill discount.

Dot paused so the user could enter the numbers into the virtual browser. The user declined to type in a checking account number there and completed the process on their own computer instead.

Security checks kept getting in the way

Other personal tasks showed the same pattern: the agent could try, but the surrounding web often made completion difficult.

At a coworking space, Dot failed to find the option for a free tour and entry. Instead, it offered to sign the user up for a $35 day pass. Instinct, another agent the source had been testing, found the trial option and set up an appointment within minutes.

When asked later why it missed the option, Dot answered: “I jumped to the wrong conclusion.”

Dot also struggled with account access. It could not retrieve information from an Ikea account about a hanging planter because it got stuck in a looping security check. A neighborhood teriyaki spot would not allow Dot onto its ordering page.

The source notes that Dot seemed to run into security checks more often than Muse or Instinct. Dot offered a link to OpenAI’s page about websites blocking its cloud browser traffic as an explanation. Whatever the exact cause, these blocks meant more manual intervention and browser takeovers.

For users, that distinction matters. An agent that needs frequent handoffs may still save time on parts of a task, but it does not yet feel like full delegation.

Dot worked better on controlled projects

The strongest results came when Dot was given access to something the user controlled: a personal website. The user asked it to create a more streamlined design for an outdated site, then called Dot to describe requested changes section by section over 10 minutes.

After the call, Dot produced another version for review. It was not perfect, but it improved the work. The source describes this as the kind of situation where AI is most helpful: taking a large amount of loose input and turning it into a usable draft.

The user then continued iterating through a browser chat and voice-to-text on the phone app. That workflow points to a practical use case for AI agents: not replacing judgment, but absorbing messy instructions, producing a version, and repeating the cycle.

Dot became more useful again when granted access to the user’s computer. It was given two tasks: combining a handful of desktop video files into one clip sized properly for social media, and deploying website changes that had been worked through in a prototype.

The process required a large number of permissions, but it worked. Dot clicked through the website backend and recreated the prototype block by block. The consolidated video clip was also ready for review through updates in the ChatGPT app on the user’s phone.

The real promise is narrow but clear

Dots are presented with approachable design cues, but the early experience suggests the product is most convincing when the task is structured, permissioned, and under the user’s control. Website edits, creative assembly, and software-based workflows were a better fit than payment pages, account portals, and ordering systems.

That does not make Dots useless for personal chores. It does suggest that the most ambitious version of the product still depends on the web around it. Security checks, blocked cloud browser traffic, and sensitive payment information can interrupt the flow quickly.

For now, OpenAI’s Dots appear less like a universal assistant and more like a work agent with consumer features attached. The cute avatar may make the interface feel approachable, but the strongest case is practical: using software, following instructions, revising drafts, and handling multi-step tasks where the user remains close enough to review and approve the outcome.