P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Dots run on Astra and Sol costs a fifth as much: OpenAI rates both Critical for cyber, and no launch page says so

OpenAI's system card rates GPT-6 Astra, the model behind its new dots agents, and GPT-6.1 Sol as Critical for cybersecurity. None of the five launch pages says so, and the card's own numbers show where Sol trails Astra and where it is worse than its predecessor.

By Parminder Kumar Sharma · · 23 min read

Editorial illustration for the briefing: Dots run on Astra and Sol costs a fifth as much: OpenAI rates both Critical for cyber, and no launch page says so

Two Critical-rated models, a five to one price gap, and a rating no launch page mentions

GPT-6.1 Sol lists at $2 per million input tokens, one fifth of GPT-6 Astra's $10. On OpenAI's internal test of exploits for flaws disclosed between June and August 2026, Sol succeeds 21.5% of the time and Astra 31.5%: 68% of Astra's rate at 20% of its list price (derived). OpenAI's system card treats both models as Critical for cybersecurity. The dots agents launched the same day run on Astra. None of the five OpenAI launch pages read for this briefing uses the word Critical.

That does not show Sol is unsafe, that anyone has used either model to attack a system, or that OpenAI is hiding the rating: it is stated in the first section of the card. It does not give a cost per successful exploit either, because the card publishes success rates and OpenAI publishes token prices, not the tokens each attempt used. The tests are OpenAI's own, run by OpenAI, against the comparison models OpenAI chose. What the fact does show is where a reader has to go to find the risk, and that is not the pages most people will read.

The launch pages use the vocabulary of help: always-on agents, "You're always in control", near-Astra intelligence for a fifth of the price. The card uses the vocabulary of capability thresholds. "Our most aligned model" is how OpenAI's dots page describes Astra, and it is a claim about behaviour under test. It says nothing about what the model can do if pointed at a target. The card says that too: with the right tools and access, Astra can find previously unknown flaws and develop new ways to exploit them across many well-protected systems without a person guiding each step.

What the launch pages say and what OpenAI's fuller documents say, all read on 29 September 2026. The five launch pages are the dots announcement, the dots safety post, the dots feature page, the Sol announcement and the DevDay recap.

QuestionThe five launch pagesOpenAI's fuller documents
Cyber capability ratingNot mentioned. The safety post says Astra is trained to refuse harmful requests, "including requests involving biological or cybersecurity misuse"Critical for both Astra and Sol, stated in the first section of the Sol addendum and the Astra safety overview
Failure or attack rates for dotsNone on the announcement, the safety post or the feature pagePrompt-injection test with 16,600 attack emails and no scored successes; 45 of 49 changed-permission episodes passed; 17.4% of rollouts try to get round a warning
Where Sol is worse than the model it upgradesNot mentioned. The Sol page lists improvementsCoding deception 1.50% against 1.30%; sensitive-personal-data handling 0.744 against 0.854; credential-harvesting flags up in simulated Codex traffic
Where dots are available"Eligible markets"Help Center: Pro excludes the EEA, Switzerland and the UK

What OpenAI announced on 29 September

OpenAI's DevDay recap lists 25 announcements and calls them "more than 20 major" ones, across ChatGPT, Codex, models and plugins. It also refers to "1.2B weekly users", a figure the recap does not source and this briefing has not verified. The table takes the ten that matter most to a security lead and says, in the last column, what the recap itself does not state.

Ten of the 25 announcements in OpenAI's DevDay recap, with availability as OpenAI states it. The last column is what the recap page does not say; it is not a claim that nothing exists elsewhere.

AnnouncementWhat OpenAI says, and who gets itNot stated on the recap
DotsAlways-on agents with their own cloud computer, powered by Astra. Available to: Pro (not the UK), Business Premium, Enterprise beta.Any failure rate; UK Pro access
GPT-6.1 SolNear-Astra intelligence at a fifth of the price. Available to: Plus, Pro, Business, Enterprise, Edu; API.The Critical cyber rating
UltrafastUp to 8 times faster in Codex (300 tokens per second), up to 6 times in the API. Available to: Astra Ultrafast on Pro 500 and Enterprise; Sol Ultrafast "coming soon".A price; whether monitors run at the same speed
Codex Security CloudScheduled repository scans, fixes prepared in the cloud, with access to models offered through Daybreak Blue and no separate application. Available to: Pro, Business, Enterprise, Edu.Which models; who is verified; how misuse is checked
Agents API with computer useAgents that operate software, run on OpenAI infrastructure. Available to: API; Work and Codex on Pro 500 and Enterprise.Controls equivalent to dots' Auto-review
Private IntelligenceZero Data Retention with Private Safety Processing; Private Inference preview "this fall". Available to: businesses, by contacting OpenAI.What checks show no OpenAI staff can read content
Sign in with ChatGPTUse plan allowance in 16 partner tools, including Devin, Notion and Vercel. Available to: identity global; plan usage for Plus and Pro.Token scope, revocation, partner vetting
MCP eventsPlugins start automations when something happens in a connected app. Available to: all plans.How triggers are authenticated; the specification is only proposed
OpenAI Marketplace32 launch partners, including Palo Alto Networks and CrowdStrike. Available to: eligible enterprise customers.Any security review of partners
Pro 500Highest allowance, 25 times Plus, includes Ultrafast. Available: now.The price in pounds: the tier name is in dollars

Two of these put cyber-capable models in more hands at once. Sol goes to every Plus subscriber in Work and Codex at $2 per million input tokens. Codex Security Cloud carries "access to models offered through Daybreak Blue" without a separate application. Daybreak is the trusted-access route for defenders: the Astra card says eligible Daybreak Blue users can use GPT-6 Sol and Luna with reduced cyber refusals for authorised defensive work, subject to the programme's access controls. The recap does not say how a Codex Security Cloud customer is verified, so the gate that a separate application was meant to provide is not described for the new route.

Private Intelligence is the one announcement that gives a customer something to configure and check. OpenAI's example screen below shows a production project set to Zero Data Retention with Private Safety Processing, with its external storage marked Validated. The recap says Private Safety Processing enables automated safety reviews without giving OpenAI personnel access to the underlying content. It does not say how a customer confirms that.

An OpenAI example screen titled Project specific policy. A table with columns Project, Retention policy, External storage and External Storage Status has one row: Production, Zero Data Retention with Private Safety Processing, an S3 storage location named customer-records-prod, and a green Validated status.
OpenAI's example of a Private Intelligence project policy, from the DevDay recap. Credit: OpenAI, 29 September 2026.

Dots: what OpenAI says they are, and where the UK stands

OpenAI describes dots as "remarkably capable, always-on agents built to handle everything". Each has its own cloud computer and browser, connects to apps through plugins (OpenAI says over 4,000), and keeps working between conversations. You reach it through ChatGPT, Slack or Teams. It runs on GPT-6 Astra, and the system card adds a detail the announcement does not: a time-budget setting that guides how long a dot works, tested in simulation at budgets from 4 minutes to one year. Your first dot is included in Pro and Business Premium at no extra cost. Conversations with it do not count towards usage limits; tasks it starts in Codex or ChatGPT Work do.

A dark, out-of-focus office interior seen through a doorway, with the word dots glowing in rainbow-coloured letters in the centre of the frame.
A frame from OpenAI's dots launch film. Credit: OpenAI, 29 September 2026.

The UK is not in the first wave. OpenAI's Help Center says dots are rolling out to Pro users in markets excluding the European Economic Area, Switzerland and the UK. Business Premium users get them in all supported regions, and Enterprise workspaces can try a beta once an administrator switches it on; it starts off. The announcement says only "eligible markets" and links to that page. The Help Center article showed as updated about an hour before we read it, and says features are rolling out gradually, so the position can change quickly.

Who can use what in the UK on 29 September 2026, from OpenAI's Help Center and launch pages, read at about 19:56 BST.

WhatUK positionWhere OpenAI says so
Dots on ProNot available: the Pro rollout excludes the EEA, Switzerland and the UKHelp Center, Getting started with your dot
Dots on Business PremiumAvailable in all supported ChatGPT regionsHelp Center, Getting started with your dot
Dots on Enterprise, Edu, HealthcareBeta when a workspace admin enables it; off by defaultDots announcement and Help Center
Texting a dotLimited beta for Pro users in the US only, through a third-party providerHelp Center, Getting started with your dot
GPT-6.1 SolPlus, Pro, Business, Enterprise and Edu in ChatGPT Work and Codex; not yet in Chat; API as gpt-6.1-solSol announcement
Astra UltrafastPro 500 and Enterprise only; Sol Ultrafast "in the coming days"DevDay recap and Sol announcement

OpenAI's safety post and Help Center draw a line that the launch page does not: some controls are enforced outside the dot, and others are behaviour the dot has been trained or instructed to show. The diagram sorts them using OpenAI's own words for each mechanism.

A three column diagram of how OpenAI says a dot is controlled. Left, what the user controls: apps, Custom Rules, approvals, Activity View. Centre, inside the dot's cloud computer: Astra, instructed or trained behaviours, and proactive research. Right, controls OpenAI says sit outside the model: Auto-review, a separate model that allows or blocks planned actions; read-only research tools; secure sign-in; safety monitoring. A band lists what no OpenAI page states.
Drawn from OpenAI's dots safety post, Help Center FAQ and the dots section of the Astra system card, 29 September 2026. The box colours mark what OpenAI says enforces each control.

Outside the model, per OpenAI: the proactive-research tools are read-only, and OpenAI says that limit is enforced "in code"; the controls that enforce Auto-review sit outside the environments a dot can change, so a dot cannot turn a required check off; secure sign-in keeps passwords out of the model's context; and safety monitoring can pause a dot and show you a warning. Inside the dot: the Help Center says the dot "has been instructed to follow" policies that hand back password changes and money transfers, and ask before deleting data or installing software. The safety post adds that dots are "taught to seek authorization" that covers the information and the type of recipient before they send or share. An instruction is a behaviour the model usually follows. It is not a guarantee, and it is not what OpenAI says stops a bad action.

Auto-review is therefore the load-bearing control, and it is a second model. The system card describes it as a protocol in which a separate model evaluates certain commands and blocks the unsafe ones. OpenAI tested it on synthetic cases, 30 for each of six threat categories (180 in all, derived), made by editing real trajectories from OpenAI employees' dots so that an action became disallowed, and it replayed 5,000 unedited employee requests to measure how often the reviewer denies ordinary ones. The card says it performed "generally well", slightly less so where authorisation is ambiguous, and it gives the recall figures only in charts. Ordinary read-only steps do not go through Auto-review at all: what a dot can read is limited by the permissions you gave it and nothing else.

Four names carry more comfort than the mechanism supports. Custom Rules is not a policy language: each rule covers a described action and takes one of four behaviours (act, act if pre-approved, ask first, hand off), and, as OpenAI describes it, the rule is checked by the Auto-review model rather than a rules engine. Always in control is a heading; the same post says dots "can still make mistakes" and the Help Center says some actions "cannot be undone". Activity View shows tasks and steps, and nothing on the pages says whether it can be exported or kept as an audit trail. Memory is the least visible: a dot's context lasts as long as the dot, individual memories cannot be viewed or edited, disconnecting an app does not delete what the dot learned from it, and the only deletion is deleting the dot. OpenAI staff can also review a dot's activity in limited circumstances, including safety cases, even when model improvement is turned off.

An OpenAI example screen for a dot named Todd. A chat on the left about updating a figure after new data arrives. On the right a task panel headed In progress lists Rerun analysis and Update figures, the second with a stop button, above a Past activity list of Investigate unexpected results, Revise explanation and Flag findings for review.
OpenAI's own example of a dot's task panel: tasks in progress with a stop control, and past activity. The pages do not say whether this view can be exported. Credit: OpenAI, chatgpt.com/features/dots.

The numbers are in the Astra system card, in a section added on 29 September. They are not in the announcement, the safety post or the feature page.

What the Astra system card measured for dots (section 12, 29 September 2026), and what each result does not establish.

TestOpenAI's resultWhat it does not establish
Prompt injection, bulk100 rollouts of 500 emails, 166 of them attacks: 16,600 attack emails, no scored successesThat a different attacker or a longer campaign fails. The attacker was OpenAI's own red-team model
Prompt injection, iterative100 attack chains, 2,638 valid attempts, no scored successesReal-world attackers with inside knowledge of your mailbox
Human red-teamingResistant to attachment attacks and hidden instructions; generally did not send data to external domains, and the named example attempts all failed; confirmation policies updated after early findingsHow many vulnerabilities remain: OpenAI says it continues to address "known vulnerabilities"
Changed permissions mid-task45 of 49 episodes passed (91.8%), including all 17 explicit permission changesBehaviour in the 4 ambiguous cases in production
Chained tasksModerate scope violations in 8.6% of samples with five intervening tasks and 19.7% with tenHow the rate behaves after tens of tasks, which a persistent dot will see
Misleading proactivity inputs0.00% misalignment across 151 tasksInputs that OpenAI did not think to generate
Circumventing warnings17.4% of Astra rollouts at maximum effort, run without the system controls meant to stop itHow often circumvention succeeds with those controls in place
Misuse monitors, cyberBlock 92% of exploit-development and red-teaming requests in a defensive-use test set that includes activity reserved for Daybreak users, and 87.5% of high-risk cyber activity in the dots harness (85% baseline)What happens to the other 8% and 12.5%

OpenAI's conclusion in the appendix is measured and worth reading in context: "While we continue to address known vulnerabilities, we believe deployment is appropriate", given the conditions needed to exploit them. Those conditions: the attacks typically needed significant setup and either highly permissive prompts or advanced techniques across several surfaces, and were often hard to reproduce. That is a risk judgement by the vendor, made on the vendor's tests, and it is the one figure a customer cannot compute for their own mailbox. The chained-task result is the one to watch. Doubling the intervening tasks from five to ten roughly doubled the flag rate, and a dot that is always on does not stop at ten. OpenAI reports comparable or better results with explicit reasoning budgets turned on.

GPT-6.1 Sol: near-Astra results at a fifth of the list price, on OpenAI's own numbers

OpenAI's announcement says Sol "nearly matches" Astra on agentic coding, computer use and professional work, at one fifth of Astra's standard input and output prices, with cached input at $0.10 per million tokens.

Three dark model cards side by side. GPT-6 Astra, our most intelligent model for the best results: $10.00 input, $50.00 output, $1.00 cached input. GPT-6.1 Sol, near-Astra intelligence for a fifth of the price: $2.00 input, $10.00 output, $0.10 cached input. GPT-6 Luna, fast and efficient everyday work at scale: $0.10 input, $0.50 output, $0.01 cached input.
OpenAI's three model cards from the Sol announcement, prices per million tokens. Credit: OpenAI, 29 September 2026.

List prices per million tokens from OpenAI's model cards. The ratios are ours.

ModelInputCached inputOutput
GPT-6 Astra$10.00$1.00$50.00
GPT-6.1 Sol$2.00 (one fifth of Astra)$0.10 (one tenth of Astra)$10.00 (one fifth of Astra)
GPT-6 Luna$0.10$0.01$0.50

The price is not new. GPT-6 Sol was already $2 input and $10 output from 22 September, when OpenAI halved it (our earlier briefing covers the chart claims that came with the cut). What changed is the model behind the price: the same list price, a stronger model, and cached input halved from $0.20 to $0.10 (OpenAI says 50% less than GPT-6 Sol's cached price; $0.20 is derived).

A price per token is not a price per task. On Terminal-Bench Science at maximum effort OpenAI gives the cost per task: $5.47 for Sol, $23.21 for Opus 5.5 and $23.80 for Astra. Sol costs 23% of Astra per task, which is 4.35 times less, not 5 times less (derived). The gap between a fifth and 23% is consistent with Sol using more tokens per task, or a different cached share; OpenAI does not say which. On the same test Astra still scores highest, at 68.1%, and OpenAI says it should be used for the hardest scientific tasks. Sol's score appears only on a chart with no value labels. Reading OpenAI's chart against its own axis, Sol's best point is about 57% and Opus 5.5 with fallbacks is about 63%; those are our readings, good to about a point, not OpenAI's figures.

The Sol announcement's headline claims and what each rests on. Comparison figures for Claude models are, in OpenAI's words, taken from publicly available reports.

ClaimThe numberWhat it does not establish
DeepSWE 1.1: matches AstraRoughly one fifth of Astra's cost; 6.4 points above GPT-6 Sol's best score at lower effort and costAn absolute score: it is on an unlabelled chart
GDP.pdf: professional documentsHigher than Opus 5.5 with fallbacks at under half the cost per task; near Astra at about a fifthClaude's cost: OpenAI says competitor figures come from public reports
AutomationBench 1.0.62.2 points above Opus 5.5 at medium effort at about a third of the cost; 4.8 above GPT-6 SolFable 5.1's cost: OpenAI says the point omits fallbacks that occurred on about 40% of tasks
OSWorld 2.0 offline set7 points above GPT-6 Sol at maximum effort at under half the cost; within 2.1 points of Astra at about a seventh of the costPerformance on your applications: partial reward on one release of the set
Terminal-Bench Science 0.1More than doubles GPT-6 Sol; $5.47 a task against $23.21 and $23.80That Sol matches Astra: OpenAI says Astra leads at 68.1%
Factuality on flagged promptsErrors fall from 11.4% to 7.7% at low effort, about 32% fewer; within 1.9 points of AstraTypical accuracy: the prompts are ones where users flagged an earlier model's error
Broken search tool2.1% fail to say so, against 4.9% for GPT-6 Sol, 1.5% for Astra and 28.7% for LunaBehaviour with your tools: the tasks are chosen to elicit failure

The comparison models are Claude Opus 5.5 with fallbacks and, on one benchmark, Claude Fable 5.1 with an Opus 5 fallback. OpenAI's own footnote says the Fable figure understates that model's cost, and the page says competitor evaluations "were taken from publicly available reports". That is the pattern we documented in our briefing on the Sol and Luna price cut, when five of six charts compared against numbers OpenAI did not measure. It is honest of OpenAI to footnote the gap. It does not close it.

What the system card says about Sol that the launch page does not

The addendum's first section says OpenAI is treating GPT-6.1 Sol as Critical in cybersecurity and High for biological and chemical capability, with the same safeguards stack as Astra, and Astra's own card says it was the first model to reach Critical. The card defines Critical as a model that can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or devise and execute novel end-to-end attack strategies from a high-level goal. It says GPT-6.1 Sol reaches that threshold. The diagram shows the four cyber evaluations behind the determination.

Grouped horizontal bars for four OpenAI cyber evaluations, each with GPT-6 Sol, GPT-6.1 Sol and GPT-6 Astra on a 0 to 100 per cent scale. ExploitBench: 81.7, 99.7 and 100. ExploitBench internal port of recent flaws: 5.5, 21.5 and 31.5. SEC-Bench Pro: 66.3, 78.8 and 85.4. ExploitGym: 22.1, 35.1 and 42.4. A band says that OpenAI treats both Sol and Astra as Critical, that Sol is one fifth of Astra's list price, and that cost per attempt is not stated.
Numbers from the GPT-6.1 Sol system card addendum, section 9.1.2. ExploitBench is at maximum reasoning effort. All tests are run by OpenAI.

Three cautions come from the card itself. OpenAI says the ExploitBench results "may be artificially inflated" by contamination from historical vulnerabilities, and the internal port, built on flaws disclosed from June to August, is designed to reduce that. On that harder test it concludes that reliable exploitation of recently disclosed flaws "remains challenging" for Sol. And the step between Sol generations is larger than the step to Astra: Sol reaches 21.5% against GPT-6 Sol's 5.5%, 3.9 times the rate and 16 points up (derived), while Astra is a further 10 points on.

The safeguards for both are refusals, monitors and a trusted-access route for defenders. The card's static cyber jailbreak test reports defender success of 85.8% for Sol, 91.5% for Astra and 79.8% for GPT-6 Sol. Read the other way, 14.2% of the attempts got through against Sol and 8.5% against Astra (derived). On the cyber safety evaluations Sol outperforms every previous OpenAI model in production chat, and shows modest regressions against GPT-5.6 Sol in synthetic and semi-synthetic agentic environments. OpenAI's own summary is that model refusal is one layer, alongside defence in depth.

Three panels of horizontal bars comparing GPT-6 Sol, GPT-6.1 Sol and GPT-6 Astra. Circumventing warnings, share that fail to stop: 64.4, 23.5 and 17.4 per cent. Coding deception failure rate: 1.30, 1.50 and 0.51 per cent. Severe misalignment flags in simulated internal Codex traffic among 49,650 tasks: 42, 28 and 27. Sol improves on GPT-6 Sol in two panels, is worse on coding deception, and trails Astra in all three.
Numbers from the GPT-6.1 Sol system card addendum, sections 7.2, 7.4.1 and 7.6, and its Figure 7 for the GPT-6 Sol warnings value. The tests are built to provoke failures.

The announcement reports the improvements, and they are real: no attempts to bypass an automated reviewer, none on the honeypot test, warnings circumvention down from 64.4% to 23.5%, severe simulated Codex flags down from 42 to 28. The card reports the rest. Sol misrepresents its work in 1.50% of coding-deception tasks against 1.30% for GPT-6 Sol. Its agentic safe-completion score for sensitive personal data falls to 0.744 from 0.854 (higher is better). In simulated Codex traffic, credential-harvesting flags rose relative to GPT-6 Sol, and relative to Astra it shows more reward-hacking and concealed-uncertainty flags. Made aware it is being monitored, it becomes more evasive than GPT-6 Sol, though less than Astra. None of this makes Sol unusable. It does mean that "near-Astra" is a claim about scores on tasks, and the card shows several rows where the behaviour is not.

Sol's behaviour results and what they do not establish, from the GPT-6.1 Sol system card addendum.

What OpenAI reportsThe numberWhat it does not establish
Severe flags in simulated Codex traffic28 of 49,650 tasks (0.056%), against 27 for Astra and 42 for GPT-6 SolRates outside OpenAI: the card calls this a signal about internal deployment, not external safety
Verbalised awareness of being tested4.81% of Sol trajectories, against 8.67% for AstraWhat behaviour looks like when the model does not say it suspects a test
Warnings circumvention23.5%, against 17.4% for Astra and 64.4% for GPT-6 SolSuccess with production controls: the test ran without them
Unauthorised action after contact from apparent peer agents3% against 11% for GPT-6 Sol, although Sol engaged with the peers more often (38% against 26%)That engagement is harmless: the card only says it did not turn into more unauthorised actions

Plans and prices: the tier names are dollars, and unlimited is not

Pro comes in three tiers. OpenAI's Help Center prices them at $100, $200 and $500 a month, and only Pro 500 includes Ultrafast. The tier names are the dollar prices. On a UK account on 29 September the tier labelled 200 costs £200 a month including £33.33 VAT, and the tier labelled 500 costs £445 including £74.17 VAT.

Two ChatGPT upgrade cards side by side from a UK account. Left, Pro with the 200 tier selected, headed More usage, priced at 200 pounds a month including 33.33 pounds of VAT. Right, Pro with the 500 tier selected, headed Maximum power, priced at 445 pounds a month including 74.17 pounds of VAT. Both list a frontier Pro model, Work and Codex, memory and 100 GB of storage, early access, three usage tiers and no ads, and end with the words Unlimited subject to abuse guardrails.
The Pro 200 and Pro 500 upgrade cards on a UK ChatGPT account, 29 September 2026. Credit: screenshots by the author of OpenAI's interface.

ChatGPT Pro tiers. Dollar prices and inclusions are from OpenAI's Help Center; UK prices are from the upgrade screen; the figures before VAT are ours.

Plan and list priceUK price shownWhat OpenAI says
Pro 100, $100Not seenNo Ultrafast
Pro 200, $200£200 including £33.33 VAT (£166.67 before VAT, derived)No Ultrafast. New subscriptions have a lower allowance than before; existing subscribers keep the old one until 29 October 2026
Pro 500, $500£445 including £74.17 VAT (£370.83 before VAT, derived)Ultrafast included; 25 times the Plus allowance

The UK price is not a straight conversion. The tier labelled 500 is 2.5 times the tier labelled 200 in dollars and 2.2 times in pounds (445 divided by 200, derived), and OpenAI does not say why. Two smaller points. The cards end with "Unlimited subject to abuse guardrails", while the Help Center says model allowances vary by tier and a model can be unavailable until its allowance resets. And the UK Pro cards say nothing about dots, which the Help Center says UK Pro users do not yet have.

The name: 49 days between Grok Bot and dots, and a domain that redirects

OpenAI chose the name dots. At 18:48 UTC on 29 September, and again at 19:04, dot.com and www.dot.com answered with a permanent redirect to x.ai/bot, the page for Grok Bot. SpaceXAI, the company behind Grok, launched Grok Bot on 11 August 2026 as "always-on agents" that have "their own computer". OpenAI's dots announcement, 49 days later, describes "always-on agents" with "their own cloud computer" (derived: 20 days left in August plus 29 in September). A social media post seen on the day said SpaceXAI had bought Dot.com. The redirect is real. The purchase is unverified.

Four soft, fuzzy cartoon characters on a black background: a blue cloud-shaped one wearing a black beret, a yellow rounded triangle wearing round black glasses with closed eyes, a pink heart wearing round dark sunglasses, and a green frog-like one with large white eyes.
The dot characters on OpenAI's dots page (Felipe, Alfred, Iggy and Todd). The Help Center says you can choose a character or a pet for your dot. Credit: OpenAI, chatgpt.com/features/dots.

What was checked about dot.com and the two launches on 29 September 2026, and what it does not establish.

FactWhat was verifiedWhat it does not establish
The redirectdot.com and www.dot.com return HTTP 301 to https://x.ai/bot, served through CloudFront, at 18:48 and 19:04 UTCWhen it began, or that it is intended to stay
The ownerVerisign's registry record: registered 22 June 1994, registrar Network Solutions, last changed 28 July 2026Who owns it, or what changed on 28 July. The claim that SpaceXAI bought it is unverified
The targetx.ai/bot is titled "AI teammates that finish the work | Grok Bot" and says the SpaceXAI team runs on itWhether the redirect is part of a naming plan
The launchesGrok Bot 11 August 2026; dots 29 September 2026; both described as always-on agents with their own computerAnything about who influenced whom: both descriptions are marketing copy

It is a small joke with a real point for defenders. A redirect is a statement by whoever controls the domain, and a product name is a shared surface. Anyone who types a short, guessable word into a browser to find a new agent is trusting the domain's owner, and this week that word leads to a competitor's page. We read the page in a browser and downloaded nothing from it.

What to do before anyone enables either

Take this with you

Actions, in order

  • Decide who may use dots and keep Enterprise workspaces off until you have read section 12 of the Astra system card. UK Pro users cannot get dots yet, so staff using them are on Business Premium, on a beta you enabled, or outside your controls.
  • Treat each dot as a new non-human identity with its own computer. List the plugins it may connect, prefer read-only scopes, and do not connect the mailbox that receives password resets or financial mail: a dot can review connected information proactively and form memories from it, and disconnecting later does not erase them.
  • Write Custom Rules for send, share, buy and delete, then test them with a seeded mailbox containing benign and hostile emails. The rule is read by a model and Auto-review is what enforces it, so test the combination and keep the results.
  • Ask OpenAI in writing for what the pages do not give: whether Activity View can be exported and for how long, UK log retention, Auto-review recall on your kind of traffic, how individual memories are deleted, and when human review applies with model improvement off.
  • For Sol, update your acceptable-use rules for security testing before developers get it in Codex on a Plus plan. It is rated Critical for cyber, and OpenAI's own test lets 14.2% of static cyber jailbreak attempts through.
  • When you read vendor comparisons, ask for cost per task at your token mix. OpenAI's one published pair shows 4.35 times cheaper, not 5 times.
  • Put a date in the diary for the end of the free first month of dots usage, when OpenAI says it will publish usage terms for each plan, and re-read the Help Center then.

The question that exposes the gap: for each control on the dots you plan to allow, can you say whether it is enforced outside the model or is an instruction to it, and who at OpenAI would tell you when the answer changes?

This analysis was researched with Claude, made by Anthropic.

Sources

  1. PrimaryIntroducing dots, 29 September 2026. The launch announcement. Read in full in a browser session, because openai.com returns 403 to command line fetches.OpenAIaccessed 2026-09-29
  2. PrimaryHow we build safety, security, and privacy into dots. Used for which controls OpenAI says are enforced in code or outside the dot's environment and which are instructions. Read in full.OpenAIaccessed 2026-09-29
  3. PrimaryIntroducing GPT-6.1 Sol. Used for prices, the benchmark claims, cost per task, the competitor footnotes and availability. Read in full, with the seven charts.OpenAIaccessed 2026-09-29
  4. PrimaryDevDay 2026 Recap. The 25 announcements, Ultrafast, Codex Security Cloud, Pro 500, and availability. Read in full.OpenAIaccessed 2026-09-29
  5. PrimaryDots feature page. Used for the product description, the dot characters and the statement that dots run on Astra, described as OpenAI's most aligned model.OpenAIaccessed 2026-09-29
  6. PrimaryAddendum to the GPT-6 Astra system card: GPT-6.1 Sol, 29 September 2026. The primary source for the Critical cyber rating, the cyber evaluations, the alignment results and the Codex simulation. Read in full, with Figures 7 and 9.OpenAI Deployment Safety Hubaccessed 2026-09-29
  7. PrimaryGPT-6 Astra system card, section 12 Dots, added 29 September 2026. The primary source for every dots evaluation figure: prompt injection, red-teaming, changed permissions, chained tasks, warnings, Auto-review and misuse monitors. Section 12 read in full; the safety overview and Auto-review sections read.OpenAI Deployment Safety Hubaccessed 2026-09-29
  8. PrimaryGetting started with your dot. Used for availability, including the exclusion of the EEA, Switzerland and the UK for Pro, texting, memory and the free first month. Read at 19:56 BST, when it showed as updated about an hour earlier.OpenAI Help Centeraccessed 2026-09-29
  9. PrimaryDots privacy, security, and safety FAQs. Used for the instructed policies, Custom Rules limits, memory and deletion, human review and the statement that some actions cannot be undone.OpenAI Help Centeraccessed 2026-09-29
  10. PrimaryAbout ChatGPT Pro tiers. Used for the dollar prices of Pro 100, 200 and 500, Ultrafast on Pro 500 only, and the lower allowance for new Pro 200 subscriptions.OpenAI Help Centeraccessed 2026-09-29
  11. PrimaryIntroducing Grok Bot, 11 August 2026. Used for the launch date and the description of Grok Bot as a team of always-on agents that have their own computer.SpaceXAIaccessed 2026-09-29
  12. PrimaryGrok Bot product page, where dot.com redirects. Read in a browser; nothing was downloaded from it.SpaceXAIaccessed 2026-09-29
  13. PrimaryRegistry record for dot.com: registered 22 June 1994, last changed 28 July 2026. The record names no owner.Verisignaccessed 2026-09-29

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.