
OpenAI's agents now keep working after you close the tab. Third-party products now get a permanent place beside the conversation, not a single turn inside it. Both shipped at DevDay 2026. On the eve of the event, OpenAI shelved GPT-6.1 Astra after the model stepped outside the scope it was authorised for and didn't always report accurately what it had done.
The announcements answer a capability question. They leave a design question wide open: when an agent acts on your behalf, inside an interface you don't own, who decides what it may do—and how does anyone check?
What OpenAI shipped at DevDay 2026
OpenAI called it its biggest DevDay yet, with more than 20 announcements across ChatGPT, Codex, its models and new ways of working with AI. Four of them matter most for product teams.
Dots are always-on agents that take on ongoing responsibilities and keep working between conversations. Plugin extensions go further than the apps OpenAI brought into ChatGPT a year ago. Those apps are rendered inside the conversation. Now OpenAI is opening the platform it uses to build ChatGPT's own features: a plugin gets a home in the sidebar, interactive panels beside the conversation, and viewers for its own file types. Pages and ChatGPT Space give teammates, ChatGPT and their dots a shared place to write, research and build on common knowledge. The Agents API now supports computer use, so developers can build agents that operate other software to finish a task.

Read separately, these are features. Read together, they're a sequence. Last year, ChatGPT became a place where apps run. This year, it became a place where work continues without you.
OpenAI describes ChatGPT as a shared surface where developers can launch native experiences to its 1.2 billion weekly users. That's the offer. The price: your product renders inside someone else's frame.
OpenAI describes ChatGPT as a shared surface where developers can launch native experiences to its 1.2 billion weekly users. That's the offer. The price: your product renders inside someone else's frame.
Agents that work while you're away
Product design has always assumed a session. The user arrives, does something, leaves. Dots break that assumption.
The trigger is no longer the user. With support for the proposed MCP Events specification, plugins can start automations when something happens in a connected app—ChatGPT can watch a project board, read the documents linked to a new task and draft a plan while the user is away. Team tasks follow the same logic, acting on a schedule or in response to a new email or Slack message.
In From UX to AX, we described the agentic loop as intent, result, feedback, better result. Always-on agents cut off the first step. The loop starts with an event, not with intent. The user comes back to a result they didn't ask for at that moment, produced from context they may have forgotten they shared.
That changes the core design moment. The question is no longer what the user sees when they arrive. It's what they see when they return.
Your product in someone else's interface
In June, Olena Zanichkovska argued that the agent becomes the primary surface and apps recede into services it orchestrates. DevDay turns that argument into a product roadmap.
Plugin extensions give your product a place in ChatGPT's sidebar. OpenAI also improved plugin ranking and recommendations, so plugins surface in the directory and inside conversations.
Distribution got easier. Control got harder. You own the panel, the data your plugin exposes and the actions it offers. You don't own when the user meets you, which recommendation brings them to you, or what a dot has already done before your panel opens.
When you don't own the frame, navigation stops being a differentiator. What's left is what your product knows about the user and what it can reliably do on their behalf. Brand moves from layout into behaviour.
This pattern isn't new. OpenAI's Operator and Google's Project Mariner launched as standalone agents and were absorbed back into the core assistants. Dots continue that trend: the agent lives inside the assistant, not next to it.
This pattern isn't new. OpenAI's Operator and Google's Project Mariner launched as standalone agents and were absorbed back into the core assistants. Dots continue that trend: the agent lives inside the assistant, not next to it.
Controls shipped, trust didn't
In the weeks before DevDay, OpenAI disclosed that its agents had escaped testing environments and broken into third-party systems, including Hugging Face and Australia's Medicare public health insurance system. Then it shelved GPT-6.1 Astra. The reason is worth reading twice. OpenAI's head of safety systems said the model didn't meet the bar on staying within scope and authorisation, or on how it reported its work back to the user.
Scope and reporting. That's not a model problem product teams can leave to OpenAI. It's the design problem this article is about.
OpenAI did ship controls. Dots start with built-in rules for when to act alone and when to ask, and users can follow their background work in an Activity View. Custom Rules let people permit an action, require approval for it or prohibit it outright.
Controls aren't trust. They're the raw material for it. Someone still has to decide which of a hundred actions needs approval, write rules a user will still understand in six months, and make an activity log readable at a glance. OpenAI's own guidance is that dots can make mistakes and consequential work needs review. That review lands on the user—and on every product the dot touches.

OpenAI knows this. For enterprise customers, it's piloting specialist dots, with its own engineers sitting beside the customer to define each agent's responsibilities, permitted tools and approval points. In Enterprise workspaces, dots access is off by default until an admin turns it on. That's design work and deliberate configuration. It doesn't come in the box.
We made the same point about MCP: the protocol answers whether an agent can do something, not whether the user understands what it's doing. DevDay closes part of that gap inside ChatGPT. It leaves it open for every plugin a dot touches.
Dots run on GPT-6 Astra. Its planned successor was shelved for going beyond what it was authorised to do and misreporting what it had done. Those are the two failures your product has to design against.
Dots run on GPT-6 Astra. Its planned successor was shelved for going beyond what it was authorised to do and misreporting what it had done. Those are the two failures your product has to design against.
Designing trust into delegation
In Where AI Agents Fail, we argued that control isn't friction. It's the user's ability to understand and influence what the system does. Always-on agents make that argument urgent. Four patterns carry most of the weight.
- 𐩒Bounded scope. Define what the agent cannot do before defining what it can. As we wrote in Designing for AI Agents, the team sets the red lines and the agent finds the route.
- 𐩒Checkpoints by consequence. ChatGPT already lets users choose when connected apps ask for permission: always, before changes, or only before important changes. But only your product knows which of its actions are important. Map them. OpenAI does this for dots by data sensitivity: sharing health data requires a named recipient, while an email address only needs a type of recipient. Money, other people and anything irreversible need a checkpoint. An agent that confirms every step is a form with extra latency.
- 𐩒A readable record. When users return, they need a log they can scan in seconds: what happened, which data the agent used, what it left out. That's auditability, and in enterprise it's the difference between adoption and a stalled pilot.
- 𐩒Reversibility. Every action shows how to undo it, or states plainly that it can't be undone.

Autonomy should grow over time. Early on, the agent proposes and the user approves. As it proves reliable, the user hands over more—the way developers turn on auto-accept once a coding assistant keeps making the right call.
For teams building plugins, the panel is where all of this lives: the place your product's actions become visible, explainable and correctable.
In fintech and healthcare, a readable record isn't a nice-to-have. When agents share credentials and nobody can trace an action to a specific user, that's a direct compliance failure under HIPAA, SOC 2 and GDPR.
In fintech and healthcare, a readable record isn't a nice-to-have. When agents share credentials and nobody can trace an action to a specific user, that's a direct compliance failure under HIPAA, SOC 2 and GDPR.
What product teams should decide now
DevDay leaves three decisions on every product team's table.
Where does your product live? Some of it will sit in ChatGPT's sidebar. Decide which part, and what stays in the product you control.
What can an agent do with your product without a human? Write that list down before a dot finds out for itself.
What does the user see when they come back? That screen—the record of what happened while they were away—may become the most important one in your product.
OpenAI shipped agents that can act. Whoever designs how those actions are seen, questioned and reversed will own the relationship with the user.
What can an agent do with your product?
Discuss with your AI.

A Product Strategist with over 13 years of experience in marketing, product strategy, and branding. His love for analytics, funnels, and a structured approach ensures that the digital products we craft aren't just functional—they impress.


