OpenAI DevDay 2026 is about moving from a chatbot that answers questions to an ecosystem that carries out work. The September 29 announcements span models, persistent agents, developer infrastructure and collaboration: dots, GPT-6.1 Sol, Codex Cloud, Decisions API, richer plugins and shared work surfaces inside ChatGPT.
The long list can obscure the underlying change. OpenAI is connecting model intelligence to an execution environment, authorized data and places where people can inspect the output. The promise is fewer manual handoffs between asking for something and completing it. The practical question is whether that happens reliably, at an understandable cost and within appropriate permissions.
This article examines the official information available on September 30, 2026. It separates announced availability from previews and future releases, and explains what the changes could mean for users and developers. The practical examples are illustrative scenarios, not independent performance tests. The starting point is OpenAI’s official DevDay recap.
OpenAI DevDay 2026: understanding the announcement map
There are five layers to distinguish. Models provide reasoning and content; agents coordinate multiple steps; environments run code and software; plugins and connections expose tools and information; collaboration surfaces retain and share the work. Mixing these layers creates misleading expectations, such as assuming a subscription automatically authorizes access to every application.
| Announcement | Main change | Announced status |
|---|---|---|
| dots | Persistent agents with their own cloud computer | Eligible plans and markets; administered beta for some workspaces |
| GPT-6.1 Sol | Coding, computer use and professional work | API, Work and Codex on supported plans |
| Ultrafast | Lower-latency inference | Astra available; Sol version forthcoming |
| Codex Cloud and Security Cloud | Remote environments, reviews and repository scans | Subject to plan, connections and permissions |
| Decisions API | Answers from predefined options | Limited preview |
| Agents API and Bedrock | Managed agent infrastructure | Check capabilities and access in each service |
| Plugins, Sites and MCP Events | Integrated interfaces and event-driven automation | Announced support; Events remains a proposed specification |
| Space and Pages | Shared knowledge and documents | Eligible plans; some mobile capabilities later |
| Slides and Meetings | Collaborative presentations and meeting notes | Slides in coming weeks; Meetings in macOS beta |
| Pro 500 and Marketplace | More usage and partner software purchasing | Pro available; Marketplace for eligible enterprises |
Available does not mean visible to every account at the same moment. Geography, platform, plan, administrator settings and gradual rollout all matter. GPT-6 Sol and Luna were introduced on September 22: the DevDay model update is GPT-6.1 Sol, not the original launch of the whole family. Existing capabilities covered in our ChatGPT Images 2.5 explainer should not be relabeled as September 29 launches.
Dots: ongoing responsibility rather than a longer chat
The most distinctive launch is dots. OpenAI presents these as persistent agents with their own cloud computer and browser, powered by GPT-6 Astra. Rather than responding to one message, the agent is meant to keep working toward an ongoing objective: monitoring project developments, preparing materials or investigating recurring problems.
The official dots introduction describes an inspectable computer and connected applications. Connecting the user’s own device is a separate, permission-dependent option. A cloud computer does not automatically grant access to every local folder, personal service or saved credential. The distinction is essential when evaluating what an agent can actually do.
For a small business, a useful scenario would be collecting repeated customer complaints and preparing a proposed fix. The desired outcome is evidence, a reviewable change and test results, not an unexplained production update. Persistent responsibility changes delegation: the owner must define when the work starts, when it stops and what demonstrates completion.
“Take care of this project” is not a sufficient operating specification. A good assignment identifies permitted sources, frequency, budget, prohibited actions, approval requirements and recipients. Otherwise an ambiguous instruction can be repeated and amplified over time. The agent needs durable instructions, and somebody needs to maintain them as circumstances change.
Dots safety: reading, acting and approving are different
A particularly important boundary separates proactive information gathering from execution. OpenAI’s explanation of dots security, safety and privacy describes proactive research restricted to read-only tools. In that path, the agent cannot send messages, modify applications or operate a computer as it could during an authorized execution task.
Controls include activity visibility, custom rules and review of consequential actions. User preferences cannot remove every mandatory safeguard. Some operations require confirmation, while others, including password changes and moving money from a financial account, require a handoff to the user. These restrictions define the authority being delegated rather than merely adding friction.
Malicious instructions inside documents, websites or messages remain a concern. External content may try to persuade the model to abandon the original task or expose information. Defenses therefore need to exist in tool permissions as well as model behavior. An agent allowed to read a repository should not have the ability to delete it, regardless of what a document says.
Disconnecting an application prevents further sharing, but should not be treated as automatic removal of everything already learned in the agent’s context. Before connecting sensitive archives, understand the plan’s data settings and context controls. In crypto workflows, seed phrases and private keys should never be placed in documents the agent can read.
Specialist dots and dedicated enterprise identities
OpenAI also previewed specialist dots for organizations, with dedicated identities and deeper integrations into business systems. These are targeted enterprise experiments, not a universal capability that should already be assumed available. The Microsoft Agent 365 integration is described as work in progress rather than completed compatibility across every deployment.
Dedicated identity is the key architectural idea. An agent account can have narrower and clearer permissions than an automation borrowing an employee’s login. For example, it could prepare support tickets without permission to change administrator roles. This makes activity attribution, access revocation and incident containment easier to design.
A human process owner remains necessary. Someone must approve the scope, investigate exceptions and determine whether the work is useful. Operational identity does not erase accountability. Offboarding matters too: when a project ends, unused connections and credentials should not remain active merely because nobody remembered to remove them.
GPT-6.1 Sol: approaching Astra on selected workloads
GPT-6.1 Sol updates GPT-6 Sol with a focus on agentic software engineering, computer use and professional tasks. OpenAI says it approaches Astra on several evaluations while charging one-fifth of Astra’s standard input and output token prices. Near-Astra on tested tasks is not equivalent to Astra in every circumstance.
In the company’s DeepSWE 1.1 results, the new model matches Astra. On professional PDF understanding, it approaches Astra at lower cost. These are useful signals, not substitutes for testing your own repository and documents. An evaluation set may underrepresent the exceptions that are most expensive or dangerous for a particular organization.
The GPT-6.1 Sol announcement describes availability through the API and in Work and Codex on supported plans. It does not imply selection in ordinary Chat. The API identifier is gpt-6.1-sol. Our GPT-6 Astra versus GPT-5.6 Sol comparison provides context for the earlier positioning.
A sensible approach is to choose the least expensive model that passes an explicit evaluation, keeping stronger models for tasks where they provide measurable value. Ticket classification, document analysis and code changes do not share the same risk profile. They can be evaluated and migrated separately without turning a model announcement into a company-wide emergency upgrade.
Sol pricing: token rates versus cost per accepted result
For inputs within 272,000 tokens, published standard prices are $2 per million input tokens, $0.10 per million cached input tokens and $10 per million output tokens. The changelog separately lists cache writes at $2.50 per million. A discounted cache-read rate should not be applied to every repeated prompt without checking whether the relevant cache conditions actually apply.
Consider an illustrative calculation: 100 requests, each with 20,000 uncached input tokens and 2,000 output tokens. That produces two million input tokens and 200,000 output tokens. At those standard rates, the model component is $4 plus $2, or $6. This excludes tools, other services, additional billable tokens where applicable, premium tiers, different context rules and taxes.
Agent workflows can produce multiple calls, retries and checks from a single user request. A cheap model that repeats an operation ten times may cost more than a stronger one that completes it correctly once. The useful business metric is cost per accepted result, including the human time spent checking and repairing mistakes.
Before changing an integration, inspect supported endpoints, tools and settings in the API changelog. Our GPT-6 Astra API migration guide remains relevant as a method: test compatibility and outcomes instead of simply replacing a model string. Keeping a rollback path also makes comparison less risky.
Ultrafast: less waiting does not mean better reasoning
Ultrafast is a premium speed tier. Astra Ultrafast is announced for the API and for Work/Codex on Pro 500 and Enterprise; GPT-6.1 Sol Ultrafast is forthcoming. Maximum speed claims differ across official surfaces and conditions. They should not be read as a guaranteed reduction in the end-to-end duration of any project.
The Ultrafast technical guide recommends persistent connections to reduce network overhead. A workflow may still wait for an external website, a database or a test suite. Faster token generation does not remove those bottlenecks, fix an invalid tool call or improve the correctness of a patch.
Measure the time from a request to a verified result before paying for speed. For interactive work, reduced waiting may be valuable. For overnight processing, reliability and cost may matter more. Check account limits and data-residency requirements for the selected tier rather than assuming they are identical to the standard service. Latency is one part of the purchasing decision, not the whole decision.
Codex Cloud and reusable development environments
Codex Cloud focuses on reusable environments containing repositories, dependencies, tools and approved permissions. Work can be followed from different devices while execution happens remotely. This does not automatically upload every local folder or make all credentials on the user’s laptop available in the cloud.
The Codex Cloud guide includes preparing and checking the project setup. A shared environment needs reproducible instructions and a credible test procedure. If the agent uses dependencies different from production, it can produce a change that appears correct only inside its own environment. Cloud execution is useful only when the environment represents the intended workload.
A sound workflow asks the agent to investigate a bug and prepare a pull request, then examines the diff, tests and reasoning. A phone can be useful for steering or tracking progress, but should not turn a sensitive approval into a rushed tap. Software handling money or keys still needs deliberate review. A remote task being finished is not the same as its output being accepted.
The refreshed Codex CLI: voice, delegation and continuity
The terminal remains central. The refreshed CLI adds voice interaction, an /agents view for delegated tasks, and improvements to prompts, resumed sessions and worktrees. In a long-running job, knowing which agent is working on which task is an operational requirement rather than a cosmetic feature.
The CLI documentation continues to emphasize models, permissions and local context. Voice changes the input channel, not the authority behind the command. An ambiguous spoken instruction needs the same checks as an ambiguous written one. Sensitive commands should still have their parameters inspected before execution.
Worktrees can separate parallel changes without mixing working files, but shared dependencies and cross-cutting contracts still need coordination. Delegating several tasks does not guarantee proportional acceleration. It also creates integration work and the possibility of contradictory assumptions. A visible agent overview helps manage that complexity; it does not make the complexity disappear.
Code Review and Security Cloud are not interchangeable
Code Review provides summaries, diffs and potential issues in the desktop application, with GitHub and GitLab integrations. The review documentation identifies GitHub as generally available and GitLab support as preview. Automated review can flag a missing check, but a clean review is not a certificate that the software is secure or correct.
Codex Security Cloud scans GitHub repositories and monitors new commits. It investigates findings, reduces duplicates and prepares possible fixes remotely. OpenAI includes access to Daybreak Blue models without a separate application for that program. This should not be generalized to every cybersecurity capability or to other model-access levels.
The Security Cloud setup guide separates connected repositories, environments and findings review. Detecting a suspicion, establishing its significance and applying a patch are different steps. A false positive consumes time; an unverified fix may create a regression. Evidence attached to a finding is therefore more useful than a dramatic severity label alone.
For a small team, first define the threat model, prioritize confirmed issues and require tests for fixes. Scanning does not replace updates, secret management, least privilege or backups. It strengthens one stage of maintenance, and must be integrated into a process that can assign ownership and verify closure.
Decisions API: constrained judgments for application logic
Decisions API uses Luna to answer bounded questions with a finite set of predefined answers, using text or image context. At launch it is in limited preview, with broader release planned for the following days. This differs from generating a long response and attempting to extract a decision from prose afterward.
A simple illustrative use is classifying a request as “billing,” “technical issue” or “other.” The program knows which outcomes to expect. However, a structured answer can still be wrong. Schema validity and semantic correctness are separate properties, and an application should not confuse the two merely because parsing is easier.
Design for uncertainty, ambiguous examples and fallback behavior. Calculations, access control and destructive decisions should remain deterministic. AI can suggest routing; it should not invent permission to issue a refund. Narrow options make error rates easier to measure but do not eliminate errors. A new API changes how the judgment is obtained, not the application’s responsibility for what happens next.
Agents API computer use and the AWS route
Agents API expands computer use alongside tools, tool search, multi-agent capabilities and context compaction. Instead of only describing a procedure, an agent can interact with software in a managed environment. The computer-use documentation is the reference for hosted-browser behavior and access management. API eligibility should not be conflated with access through particular ChatGPT plans.
Compaction makes long sessions more manageable; it is not a promise that every earlier detail will be preserved perfectly. Applications should separately store permissions, amounts, identifiers and completion criteria. The sole copy of an important authorization should not live inside a summarized conversation. Durable state belongs in systems designed to validate and retrieve it.
OpenAI and Amazon also announced Bedrock Managed Agents powered by OpenAI. Enterprises can evaluate agent capabilities within AWS rather than assuming every workload must follow the same infrastructure route. This is an integration option, not automatic compatibility with every existing architecture.
Compare permissions, observability, regions, billing and dependencies across the OpenAI service and the AWS option. Managed describes responsibility for part of the infrastructure; it does not remove responsibility for data and action configuration. A read-only document task is an easier starting point than an irreversible financial process. Successful deployment begins with a controlled scope, not the widest possible permission set.
Plugin extensions, Plugin Creator and Sites
Plugins gain richer surfaces: sidebar access, panels alongside conversations and viewers for specific file types. The extensions documentation describes applications that provide a working interface instead of returning only text. Users can inspect an object directly rather than asking the model to narrate every interaction.
Plugin Creator, revised submission feedback and improved discovery complement that shift. They may reduce the distance from prototype to use, but developers still need authentication, error handling and clear permissions. A polished interface cannot compensate for a connection that exposes more data than the task requires. Discovery inside a platform is an opportunity, not guaranteed distribution.
ChatGPT Sites can host supported plugins. Colleagues can use a shared experience with their own connected information and permissions. A shared site should not become a workaround for sharing credentials. Announced access concerns the relevant organizational plans rather than every free account, and the supported-plugin qualification matters.
MCP Events and event-driven automation
MCP Events supports starting automation when something happens in a connected application. It remains a proposed specification, not a finalized standard. The integration guide describes subscriptions and callbacks through a webhook-based path.
The benefit is avoiding repeated checks for new information. A newly created ticket can trigger a summary. The system still needs to handle duplicates, delayed delivery, revoked access and restarts. Receiving the same event twice should not produce two payments or two public messages. Event-driven does not mean failure-free, and it does not inherently guarantee exactly-once action.
Separate receipt, processing and execution. Stable identifiers and recorded outcomes are often more important than the wording of the prompt. The agent interprets content; the application maintains workflow guarantees. Failed events need a visible destination as well: a silent delivery problem can leave an apparently active business process stalled.
ChatGPT Space, Pages and collaborative slides
ChatGPT Space organizes shared knowledge and materials. Pages introduces documents where people and AI can collaborate. Instead of leaving the result dispersed through a message history, it becomes an object that can be read, corrected and shared.
A project can retain decisions, analysis and drafts without reconstructing the context every time. Sources still need to be separated from summaries, verified claims identified and original documents retained where necessary. A collaborative document can amplify an error if everybody trusts it merely because it is organized and visually convincing.
Collaborative slides are announced for the coming weeks, with people and agents working on decks and export to PowerPoint or Google Slides. They should not be described as universally available today. Mobile creation and editing also have a different rollout from reading and sharing. The distinction matters when deciding whether the tool can support an immediate workflow.
For an editorial or research team, the potential benefit is keeping the reasoning close to the artifact. Verification remains independent of presentation: readable charts, dated sources and reproducible numbers matter more than generating a deck quickly. Generated imagery should remain clearly illustrative, not presented as documentary evidence of a real event.
Team Tasks, Slack, Teams and Meetings
Teams can share materials and recurring responsibilities. The teams and Team Tasks guide explains that service accounts and configured connections determine resource access. A task’s authority may differ from an individual member’s personal access. Check this before inviting colleagues or connecting a broader company account.
@ChatGPT in Slack and Microsoft Teams brings interaction into channels and threads. Participants can contribute without necessarily holding individual ChatGPT licenses within the supported organizational integration. This does not make every ChatGPT feature free, nor imply that everyone sees identical underlying data.
Meetings produces notes and follow-up actions. The initial beta concerns the macOS desktop app for Pro and Business; other availability follows separate paths. The Meetings guide requires informing participants and obtaining consent. An on-screen reminder does not notify them or collect consent on the user’s behalf.
Audio is deleted when notes are ready and cannot be replayed. This matters when a quote or commitment needs verification: a summary is not a retained recording. For formal minutes, define how to correct attribution, figures and obligations, and identify which document is the approved record. Automation can make note-taking easier without making the notes authoritative by default.
Shareable profiles and Sign in with ChatGPT
Shareable profiles showcase creations such as Sites and plugins. The updated profiles guide identifies limitations, including non-mobile showcase functions and Enterprise availability still forthcoming. Sharing a profile does not automatically publish personal conversations.
Sign in with ChatGPT adds account-based authentication and, in participating services, use of the plan’s allowance. Partners named by OpenAI include Devin, Notion and Vercel. The cross-application usage guide distinguishes identity from consumption. Signing in does not grant unlimited usage or automatically include every external service.
This could reduce subscription fragmentation, but users need to understand application-specific limits. Check which tool consumes the allowance, how to revoke it and what information it receives. Convenient authentication should not disguise a broad delegation or an external application consuming resources needed elsewhere. Permission and spending reviews remain useful even with a familiar login button.
Pro 500, Marketplace and Private Intelligence
Pro 500 costs $500 per month, according to the official Pro tiers page, and includes Ultrafast. The recap describes an allowance 25 times Plus: that is a usage comparison, not a promise of infinite work. Check local pricing, terms and taxes before buying.
OpenAI Marketplace is for eligible enterprise customers applying part of an existing commitment toward approved partner software. It is not an unrestricted consumer store and is distinct from the plugin directory. Companies should determine whether it simplifies procurement without creating unwanted dependencies. The relevant question is contract fit, not simply the number of partners announced.
Private Intelligence concerns data protection. The Private Safety Processing documentation describes automated safety review without OpenAI retaining prompts and responses in the configured path. Private Inference, combining confidential computing and verifiable controls, is announced as an autumn preview.
Do not generalize those properties to every request across every product. Configuration, endpoints, contracts and customer responsibilities matter. Not used for training and not retained are different claims. Private processing does not authorize uploading any material regardless of rights. Verify the architecture before sending sensitive data, rather than treating privacy terminology as a substitute for the actual policy.
A practical evaluation plan before deployment
Start with repetitive, reversible work and an observable result. For example, gather ten authorized documents, identify changes from the previous week and produce a source-linked summary. Measure coverage, errors, cost and review time. Expand the scope only when that result is reliably useful, and retain examples that reveal where the approach fails.
For coding, include a known bug, an ambiguous case and a problem requiring missing information. A useful agent asks for the missing input instead of inventing it. Tool-based tests should cover stopping, resuming and revoking access, not only the successful path. Failed or incomplete work should be distinguishable from accepted completion.
Keep responsibilities separated: the model proposes, tools expose limited actions, deterministic code validates conditions, and a person approves sensitive operations. Results should identify the model, evidence and authority used. There must be a way to stop automation and return to manual work. A small, auditable deployment provides better evidence than enabling every new capability simultaneously.
Dots availability and choosing the right plan
The rollout concerns Pro and Business Premium in eligible markets. Enterprise, Edu and Healthcare workspaces require an administrator to enable the beta; it is off by default. The first dot is included for eligible users, but deeper work and allowances must be distinguished from that inclusion. Included does not mean unlimited computation. Check country eligibility before changing a subscription specifically to obtain the feature.
Choosing between Sol, Astra and a larger allowance should start with measured work. Our overview of GPT-6 Astra pricing, benchmarks and availability supplies earlier context, while current official terms determine a purchase. More expensive access cannot repair vague instructions or incorrectly configured tools. Better permissions and better evaluation often matter before more capacity.
Questions after OpenAI DevDay 2026
Does dots replace Codex?
No. Dots concerns persistent responsibilities and cross-application work; Codex focuses on software development. They can cooperate without being the same product layer.
Does Sol make Astra unnecessary?
No. Lower pricing makes Sol attractive for many tasks. Astra may remain preferable where additional capability produces measurable value. Verified outcomes matter more than the model’s name.
Does a subscription include every API?
No. Plan allowance, partner usage and API billing are separate paths. Specific service conditions take precedence over a broad reading of an announcement.
What is the structural change?
Connecting models, environments, tools and collaboration into a continuous workflow. That is also where stronger controls become necessary: a mistake once confined to an answer can become an action in a real system.
The takeaway is more substantial than a benchmark contest. OpenAI DevDay 2026 presents AI that follows work, executes tasks and preserves results in shared spaces. Its value should be measured by reliable outcomes with understandable costs, limited permissions and a practical route for correcting errors, not by how many features an account has enabled.
