- OpenAI's DevDay recap describes agents that run on schedules and events, such as a new email, even while users are away.
- WebPulse argues this moves a key AI risk question from what a model says to what access it holds.
- Leaders should list which admins enable agents, which plugins hold access, and what can trigger them.
Most people have used AI chatbots by typing a prompt and reading the answer. A person stays in the loop at every step. OpenAI's DevDay recap describes a different arrangement for some products. The software uses connected tools, and so effectively keeps access, and acts when something happens. The lesson here is that the AI risk question is moving from what a model says to what access it keeps.
What OpenAI announced
OpenAI published its DevDay 2026 recap on September 29. It lists more than 20 announcements across ChatGPT, Codex and its models. The company says it is opening ChatGPT to developers who can launch native experiences to its "collective 1.2B weekly users."
Many items share one theme. OpenAI introduced "dots," agents it describes as always-on. It also says teams can give ChatGPT repeating jobs, such as a weekly status report. A job can run at set times, or start when a message lands in email or Slack. It uses the tools the team has connected. Mentioning @ChatGPT in a channel can also draw on tools an admin has connected.
How event-driven agents work
OpenAI is adding support for MCP Events, a specification that is still a proposal. MCP is a standard way for AI tools to connect to other apps. With Events, a change inside a connected app can set an automation running.
OpenAI's example is a project board. Ask ChatGPT to watch for new tasks. When one arrives, it reads the linked documents and drafts a plan, "even while you're away." The trigger is no longer a person typing. It is an event in another system.
Other pieces fit the same pattern. The Agents API now supports computer use, meaning agents can operate software to finish tasks. OpenAI says it runs the underlying infrastructure. Bedrock Managed Agents, built with Amazon, let teams run OpenAI agents entirely inside AWS.
The Decisions API takes a narrower route. Developers supply text or images and a fixed set of questions with finite, predefined answers. The model returns a choice that can classify content, route a request or pick an agent's next action. It is in limited preview.
Security work moves to the cloud too
Codex Security Cloud shows the same shift on the defender's side. It can examine an entire GitHub repository once or on a recurring timetable, and it keeps reviewing commits as they arrive. OpenAI says the service looks into what it finds, drops repeat alerts and drafts fixes. It keeps working even if the user's laptop is shut.
For a security lead, that is relief from triage. It is also another system with ongoing access to source code. Both facts belong in the same decision.
Why the permission model is the story
A chat window ends when the person closes it. An ongoing delegation does not. A visitor pass lapses at the end of the day. A key handed to a contractor stays valid until someone asks for it back.
OpenAI describes some controls. Dots are off by default for Enterprise, Edu and Healthcare workspaces until an admin enables them. Plugins ask for access, and the user decides which to use and what to grant. Skills sharing is limited to the workspace. OpenAI also describes Private Intelligence options, including Zero Data Retention, for protecting business data.
The recap is OpenAI's own summary, and it is short on detail. It does not say how content that arrives in a trigger, such as an email, is screened before an agent acts on it. It does not describe audit logs or how permissions are reviewed over time. That is not a finding of weakness. It is a list of things a buyer should ask.
One feature touches access directly. OpenAI is offering ChatGPT accounts as a single login for outside tools. The company says this speeds up plugin setup and cuts the number of passwords people hold. For a company, one account then links to many tools, so it merits the same rules as any shared login.
That allowance feature concerns usage limits, not data access. OpenAI says users can control how much each partner tool can use. It is a spending control. It tells us nothing about what those tools can read.
What leaders should ask their teams
First, who can enable agents in your workspace, and is that decision recorded? Second, which plugins hold access to mail, chat, code or files, and who approved each one? Third, which events can start an automation, and can anyone outside the company create one?
Fourth, when an agent acts while no one is watching, what record shows what it read and did? Fifth, does a fixed-choice tool like the Decisions API fit routine routing better than open-ended agents? A narrow set of answers is easier to test and review.
As agents take on ongoing work, the useful review question shifts from what the model said to what access it was given. Who granted it, and what can set it in motion?
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: OpenAI.





