Live
Leveraging Container Snapshots for Stateful Durable Object WorkloadsPersistent AI Agents (Dots) Shift DevOps Automation and Security BoundariesAI‑Driven Security Automation for Public‑Sector Cloud WorkloadsDynamic Container Image and Size Selection via Durable Object Scheduling in CloudflareIndia geographic inference for Anthropic Claude models on Bedrock: practical implications for engineersRun Anthropic Claude Opus 5 and Sonnet 5 with Bedrock’s in‑region inference in Seoul and SingaporeVerifiable Execution Records for AI Agents: What Engineers Need to KnowBeta Cloudflare CLI Unifies Zone, DNS, and Workers Management for EngineersLeveraging Container Snapshots for Stateful Durable Object WorkloadsPersistent AI Agents (Dots) Shift DevOps Automation and Security BoundariesAI‑Driven Security Automation for Public‑Sector Cloud WorkloadsDynamic Container Image and Size Selection via Durable Object Scheduling in CloudflareIndia geographic inference for Anthropic Claude models on Bedrock: practical implications for engineersRun Anthropic Claude Opus 5 and Sonnet 5 with Bedrock’s in‑region inference in Seoul and SingaporeVerifiable Execution Records for AI Agents: What Engineers Need to KnowBeta Cloudflare CLI Unifies Zone, DNS, and Workers Management for Engineers
OpenAI

Persistent AI Agents (Dots) Shift DevOps Automation and Security Boundaries

AI SummaryPowered by AI

OpenAI launched Dots, persistent AI agents that run on dedicated cloud compute, have their own browsers, and can access thousands of apps. For engineers, this introduces continuous automation, new security review steps, and resource‑management considerations.

OpenAI’s DevDay introduced Dots, a new class of persistent AI agents built on the GPT‑6 Astra model that run on dedicated cloud compute, have their own browser instance, and can reach more than 4,000 applications through OpenAI’s plugin ecosystem. For engineers who build and operate software, the shift from on‑demand prompting to continuously running agents changes how code, feedback, and operational tasks can be automated.

How Persistent AI Agents Work

Each Dot lives in an isolated cloud computer that users can inspect or optionally connect to a local laptop. The agent maintains state across sessions, allowing it to juggle multiple projects and carry context between ChatGPT, Slack, and Microsoft Teams without a new prompt. When a user is idle, a Dot can perform “proactive research” – a read‑only scan of connected apps for opportunities to help – but it cannot send messages, modify content, or control a browser in that mode.

Implications for Cloud and Platform Engineering

Because Dots provision their own compute and browser, platform teams must consider resource allocation, isolation, and observability. The Activity View provides a log of background work, enabling operators to redirect or pause a Dot if needed. Integration points include the existing OpenAI plugin ecosystem, which now expands to over 4,000 apps, meaning credential management and network egress rules may need to be revisited for each connected service.

Security and Governance Considerations

OpenAI separates discovery from execution. Actions that could affect user accounts or modify data pass through an “auto‑review” step that checks the request against user instructions, OpenAI safety requirements, and any custom rules the user defines. Custom rules can allow, require approval, or block specific actions; sensitive operations such as password changes are always required to stay with the user. A monitoring subsystem can pause or stop a Dot if a safety problem is detected, and all activity is visible in the Activity View.

Data handling policies differ by plan. Business, Enterprise, and Education workspaces are not used to improve OpenAI models by default. Personal‑plan users can opt‑in or out of using Dot conversations and work for model training, and proactive research notes are not directly used for training unless they become part of an eligible conversation.

Specialist Dots and Enterprise Integration

OpenAI previewed “specialist” Dots that are provisioned with an organization’s identity, credentials, and dedicated hardware, giving each Dot a defined workflow rather than a single‑user assistant. Internal tests covered procurement, invoice processing, email marketing, support, and contracting. External pilots will involve OpenAI engineers working with customers to define responsibilities, tool access, and review points. Integration with Microsoft’s Agent 365 is planned, allowing administrators to manage specialist Dots through existing governance tooling.

Related CloudNinjas coverage: AI engineering.

What This Means For Practitioners

Practitioners should start by mapping existing automation pipelines to the Dot model: identify tasks that can benefit from continuous, stateful execution and evaluate the need for custom rule sets to enforce approval boundaries. Verify that resource quotas, observability pipelines, and credential stores can accommodate isolated cloud computers per Dot. Finally, test the auto‑review workflow in a sandbox environment to confirm that safety checks align with organizational policies before enabling Dots in production.

Originally published atThe New Stack