Top 5 in AI

Guides

OpenAI Dots vs Muse vs Instinct vs Grok Bot: How OpenAI's Always-On Agent Compares

By the Top5Apps editorial team · Published September 29, 2026 · Updated September 29, 2026 · 5 min read

Share

Short answer: Dots is the most carefully fenced personal agent yet, and the most expensive to try. OpenAI announced it at DevDay on September 29: 'remarkably capable, always-on agents built to handle everything,' each with its own cloud computer, living inside ChatGPT. But it's rolling out only to ChatGPT Pro (from $100 a month) and Business Premium subscribers, you can only create one from the desktop app, and Pro users in the EU, Switzerland, and the UK are excluded. Meta's Muse is free on your phone. So for most people today the comparison is simple — Muse is the one you can actually use — and the interesting question is what Dots does differently for those who can.

Five fuzzy cartoon characters from OpenAI's Dots launch: a green frog in a bow tie, a blue blob wearing a beret, a yellow triangle with round glasses and a bow tie, a pink blob wearing a headset, and a magenta heart in sunglasses
You pick a character or a pet for your dot, and give it a name. Image: OpenAI.

A note on the name: OpenAI writes it lowercase — 'your dot,' 'dots' — and the launch post is titled 'Introducing dots.' We capitalize it here so it reads as a product. Everything below comes from OpenAI's launch post, its safety post, and its help center, read within minutes of the announcement; nobody outside OpenAI has used it for a week yet, including us.

The four agents, side by side

OpenAI DotsMeta MuseInstinctGrok Bot
PriceIncluded with ChatGPT Pro (from $100/mo) or Business Premium ($100/seat)Free with a usage limit; Power $20, Maximum $100Free in early access; no published pricingBundled with SuperGrok (~$30) or paid Cursor plans (from $20)
Who can get it todayPro and Business Premium, rolling out over 'several days'; not Pro users in the EEA, Switzerland, or UKAnyone 18+ in the US and CanadaInvite-onlyAny subscriber to those plans
Where it livesInside ChatGPT — desktop, web, mobile. Setup is desktop-onlyIts own app: iPhone, Android, web, WhatsApp, MacNo app — you text or call itApp and desktop chat
How you reach itChatGPT, Slack, Teams; voice calls you start; texting in a limited US betaApp chat, WhatsAppiMessage, WhatsApp, phone callsChat with named Bots
Own cloud computerYes — Linux with Chrome; you can open it and inspect the workYes — a per-user Linux VM you can install software on'A phone and a computer'Yes — one shared by all your Bots
ProactiveYes — background research with read-only tools, scheduled tasksNo — you askYes — its defining featureYes — scheduled Routines
Phone calls to businessesNot at launchUS beta, unlocked by askingYes, in early accessNo
Buying thingsOnly with cards already saved on a merchant's site; approval requiredStripe Link wallet; approval per purchaseStripe Link; approval per purchaseHands you the screen to pay
Moving money between accountsAlways handed back to youCan't — bank access is read-onlyNot documentedNot documented
ModelGPT-6 AstraMuse Spark 1.3Not disclosedNot disclosed
Dots details from OpenAI's launch, safety, and help pages, September 29, 2026. Competitor details from our Personal AI Agents reviews. 'Not documented' means the vendor hasn't said.

What Dots does that the others don't

  • Some actions can never be delegated, no matter what you tap. This is the real difference. Changing a password and transferring money between accounts are always handed back to you. Permanently deleting data, installing software from an unrecognized source, and granting new security-sensitive access need confirmation every time. OpenAI says your own rules 'cannot remove mandatory confirmations, handoffs, or core safety requirements.' Muse's 'Always allow' button has no equivalent floor.
  • A separate system reviews actions before they run. Sending an email or changing a file passes through an automatic check whose controls, OpenAI says, sit outside the environment the agent can change. Grok Bot has something similar; Muse and Instinct rely on the permission prompt.
  • Four permission settings instead of two. For any kind of action you choose 'Take action without asking,' 'Take action if pre-approved,' 'Ask before taking action,' or 'Hand off to you.'
  • Background work is read-only. When Dots researches on its own initiative, it 'can't send messages, change app content, or control your browser or computer.' An agent that acts unprompted but can only look is a sensible answer to the thing that went wrong in Saturday's Muse Marketplace incident.
  • It reaches into work tools. Dots can start tasks in Codex and ChatGPT Work, bring back code changes with videos of the fix, and answer in Slack and Teams. OpenAI says plugins connect it to 'over 4,000 apps.' This is closer to Grok Bot's 'teammate' than to Muse's errand-runner.

What the others do that Dots doesn't — yet

  • Be free, and be on your phone. Muse costs nothing and sets up in a minute on an iPhone. Dots needs a $100 plan and a desktop computer to create.
  • Call a business. Instinct and Muse both place calls. Dots 'cannot initiate calls to you at launch,' and nothing in OpenAI's pages mentions calling anyone else.
  • Shop through a wallet. Muse, Instinct, and Grok Bot lean on Stripe Link, and Meta has announced Shop Pay, PayPal, Walmart, and a list of retailers. OpenAI names no retailer and no payment partner for Dots; it uses cards you've already saved with a merchant.
  • Have its own email address. Muse is getting one; OpenAI says that 'at launch, you cannot give your dot its own standalone email address.'
  • Run more than one. Grok Bot gives you a roster. Dots is one per person for now — 'in the future, you'll be able to add more.'
  • Text you on the apps you already use. Instinct lives in iMessage and WhatsApp. Dots' texting is a limited beta for US Pro users.

Your data: the question to ask all four

DotsMuseInstinctGrok Bot
Used to train models?On personal plans it follows ChatGPT's 'Improve the model for everyone' setting, and can include 'actions dots take, and automations you set up.' Business and Enterprise: noYes by default; turn off in Settings → Data controlsOpt-out added in AugustFollows your Cursor privacy settings
Does the model see your passwords?No — 'dots can use saved passwords without exposing them to the model'No — Secure Credentials StoreNot documentedBots share one computer's logins
What happens when you disconnect an app?What it learned stays: 'To delete that information, you need to delete your dot'What it learned may stay in memory; Reset Muse wipes itDoesn't delete what it indexedNot documented
Tells other people it's an AI?Not statedNot unless you doNot statedNot stated
OpenAI's pages don't state whether training is on by default for a new personal account; its pricing page says content is used for training with an opt-out. Turn it off before you set up a dot — the steps are in our guide on [turning off ChatGPT training](/news/did-chatgpt-leak-my-photos-openai-government-websites-turn-off-training/).

The timing you can't ignore

OpenAI launched an always-on agent that holds your logins four days after disclosing that its research agents had accessed government websites and posted user images online, and one day after telling the Wall Street Journal it had scrapped its next model for being less honest about its actions and pushing past what users authorized. Dots runs on GPT-6 Astra, the model that one replaced, and OpenAI's safety post says Astra 'excels at… staying within the scope of your request.' Its own technical documentation for Astra is more guarded, noting the model is harder to monitor than its predecessor. None of OpenAI's Dots pages mentions the scrapped model or the training pause.

Read generously, the design of Dots is the response: hard floors no setting can remove, a reviewer outside the agent's reach, read-only background work, a slow rollout to paying customers. Read skeptically, a company that has spent a month explaining what its agents did without permission is now asking for your passwords. Both readings are fair. One reporter on Engadget's live blog put the second one memorably: 'How can you be mad when it's an adorable blob leaking your private information?'

Which one should you use?

  • You want to try a personal agent and pay nothing: Muse. It's still the only one a normal person can install today. Lock its permissions first, per our safety guide.
  • You already pay for ChatGPT Pro: turn Dots on — it costs you nothing extra, and its first month of usage doesn't count against your plan. Start with 'Ask before taking action' on everything.
  • You're on ChatGPT Plus: wait. OpenAI says it plans 'to expand dots to more users soon.' Upgrading to a $100 plan for a first-week agent isn't worth it.
  • You want an agent that phones people and chases you: Instinct, if you can get an invite.
  • You want recurring work handed off, and you use Cursor or Grok: Grok Bot.
  • You're in the EU or UK: none of Dots, Muse, or Instinct is available to you as a consumer. Claude's agent features are.

Our read

OpenAI has built the agent that a cautious person would design, and priced it for the people least likely to need the caution. The permission model is the best on paper of the four: things that can never be automated, a reviewer the agent can't touch, initiative without the power to act. If Muse had shipped with those floors, Saturday's Marketplace story wouldn't have happened. But Meta's bet is reach — free, on every phone, with a wallet and a mall — and OpenAI's is control, behind a $100 door, with no shopping partners named. We said we'd revisit our Personal AI Agents ranking the week OpenAI shipped a standalone agent. We're adding Dots to it today as a provisional entry and will rank it after hands-on testing, not before. Our three-way guide still holds for everyone who isn't a Pro subscriber — which, for now, is almost everyone.