OpenAI Dots security: permissions, prompt injection and evidence
An agent can have permission to read a message without having permission to obey it. Dots makes that distinction an operational question for every team connecting business accounts.
What OpenAI announced on 29 September 2026
OpenAI published its Dots launch announcement and safety explanation on 29 September 2026. Dots are ongoing agents powered by GPT-6 Astra, with their own cloud computer and connections to apps. The initial rollout covers Pro and Business Premium in eligible markets; Enterprise, Edu and Healthcare require an administrator to enable the beta.
Specialist dots with separate enterprise identities are a preview for focused pilots. Microsoft Agent 365 integration is being developed. Neither is evidence that every enterprise can deploy the complete announced setup today. This is a source-based analysis, not an independent security test or a report of a confirmed Dots breach.
What the safeguards actually cover
OpenAI describes sandboxing, protected sign-in flows and separate action review. Proactive research is restricted in code to read-only connected tools; later actions follow the usual authorization rules. Custom Rules cannot remove mandatory safeguards.
These controls address different boundaries. A sandbox contains execution; app permissions define accessible information; action review checks a proposed step. None by itself proves that an incoming invoice, image or instruction is genuine. Secure sign-in keeps credentials out of model context in supported flows, but secrets in readable documents can still be visible.
Prompt injection is not the same as impersonation
OpenAI explicitly identifies malicious instructions in webpages, emails and documents as a prompt-injection risk. Our practical recommendation is to treat those materials as evidence to inspect, rather than a source of new authority.
A forged supplier message can request a bank-detail change without containing any technical injection. Conversely, an ordinary-looking document can carry instructions intended to redirect an agent. Review both the requested business action and the content an agent is asked to process. A familiar logo, natural language or convincing image does not settle either question.
A supplier invoice example
Consider a hypothetical workflow: an agent finds an urgent supplier email, an invoice and a photo supposedly showing delivered goods. The sender asks for payment to a replacement account. This example is not a reported Dots incident.
The useful output is a review packet: original message and attachments, receipt time, existing supplier record, exact changed fields, cited evidence and unresolved conflicts. A fluent summary that says the delivery looks credible can hide the most important issue: whether the account change was independently authorized.
Keep drafting a reply separate from approving a supplier update or payment. Use a supplier contact recorded before the suspicious message. Do not use the phone number or verification link in that message as the independent check.
A checklist before connecting business accounts
Define one narrow workflow first, its owner and the data it needs. Test with synthetic records and a destination you control before allowing consequential work. These are implementation recommendations, not claims that Dots provides every control below.
- Record which accounts and folders are accessible, including shared material.
- Write down permitted outputs, named recipients and actions requiring human approval.
- Test misleading attachments, conflicting figures and instructions embedded in source material.
- Require citations to the original evidence, not just another AI summary.
- Keep an action record showing input, proposed change, reviewer and outcome.
- Assign a person who can stop the workflow and revoke access; test that process.
Privacy: disconnecting is not erasing learned context
OpenAI says disconnecting an app stops new sharing through that connection, while information already learned remains in the dot’s context. Business, Enterprise and Edu content is not used for training by default; personal-plan settings differ.
Before a pilot, document what data may enter the workflow, who may receive outputs and how context and records will be handled when the workflow ends. Do not equate a disconnected connector with completed deletion or assume a product announcement establishes your retention obligations.
Where media analysis and Cross-check fit
Media generation, document consistency and authorization are separate questions. Preserve a suspicious attachment unchanged and analyze a copy. An AI image detector provides probabilistic media signals; it does not authenticate a supplier, identify the account owner or approve a payment.
Cross-check can help compare supplied evidence and inspect supported claims and conflicts. It is not a Dots security audit, prompt-injection firewall or bank verification service. Keep its findings alongside the source packet and a human decision. DeepfakePolicy has not established detection accuracy for files produced by this release.
The right conclusion may be: the document totals agree, the image result is inconclusive and the bank change remains unverified. That is more useful than forcing the case into a single ‘real’ or ‘fake’ verdict.
Frequently asked questions
Is OpenAI Dots secure for enterprise use?
OpenAI describes layered safeguards, but the launch does not establish safety for every workflow. Review your actual permissions, data, recipients and consequential actions, and test a bounded pilot.
Can proactive research send emails?
OpenAI says proactive research uses tools restricted in code to read-only operation. Follow-up actions are separate and subject to normal authorization and safety checks.
Can an AI detector verify an agent’s authority?
No. Media signals do not prove identity, account ownership or permission to act. Verify authority through an independent trusted process.
Continue with independent verification.
Examine an image attachmentPrimary reading
We use original standards, regulators, public institutions and research papers wherever possible. Sources were last checked on 29 September 2026.