Cinematic Short AI Security 60 sec Failure mode + fix

The Rule Was Only a Wish

Your agent fixed the deck overnight. Nobody asked it to.

Remember

Code and permissions hold. Rules are requests.

Context

Dots launched at OpenAI DevDay on 29 September 2026: persistent personal agents in ChatGPT, each a named mascot with its own cloud computer. This Short is the 2:30 companion to the landscape deep dive ai-visual-deep-dive/specs/chatgpt-dots-deep-dive.md (8:34). Owner's decision: no villain — the Short explains the mechanism; the deep dive keeps the two failure stories.

Architecture

ComponentRoleNotes
TriggersWake the dot without a promptMorning timer, new email, Slack mention
Proactive researchReads connected apps while you're awayRead-only, enforced in code; output is a suggestion or question
Action tierDoes the work once you say yesOwn cloud computer (browser, files persist); apps via plugins
Private notesWhat the dot learnedCan't be viewed or edited one by one; deleting the dot is the only reset
Custom RulesYour preference per actionFour levels; words the dot reads and tries to follow
Auto-reviewSecond model, outside the dot's controlChecks every consequential action
App permissionsPer-app levelAlways ask · Read-only actions · Allow low-risk · Allow all
Fixed floorHard limits in codePassword changes, money transfers always to you; deletes/installs approved every time
Activity ViewAuditDesktop app only

Sources

  • OpenAI, Meet dots and Control your dot (learn.chatgpt.com/docs/dots).

  • OpenAI Help, Getting started with your dot; Dots privacy, security, and safety FAQs.

  • Facts and decisions carried over from ai-visual-deep-dive/plans/chatgpt-dots-deep-dive.md (re-checked 2026-10-09).

Found this useful?

Subscribe for the next episode, or share it with the person who owns this part of your stack.

Keep going