The Short Answer
On a supported sign-in, your password never reaches the model. OpenAI's documentation is specific: "your dot pauses while you enter your credentials in a secure login form. The form sends your credentials directly to the browser environment without exposing them to the model."
The dot's stored context also holds none of it — "your dot's context does not retain credentials, images, or screenshots."
That is a better architecture than most of the launch coverage assumed, including ours. The risks are real, but they are not where people are looking.
Where the Risk Actually Is
The credential protections apply only to supported sign-in flows. OpenAI states that passwords shared directly in chats, in documents, or through plugins do not get them.
That is the sentence to remember. The secure path is secure. The moment you paste a password into a conversation because it was quicker, or store one in a document the dot can read, or hand one to a plugin, you have left the protected path entirely — and nothing in the product stops you doing it.
So the honest answer to "can I give a dot my passwords" is: use the login form, never the chat box. The difference between those two habits is the entire security model.
What a Dot Cannot Do on Its Own
During proactive background research, the dot can read from connected sources and save private notes. Its research tools, per OpenAI, "cannot directly: Send messages to other people. Change content through plugins. Control a browser or computer."
That is a genuine boundary rather than a policy promise. The autonomous mode is observational; acting requires a different mode.
The Approval Model
- User takeover required: password changes and money transfers. The dot cannot do these, you do them.
- Per-action approval may be required: permanent deletion, software installation.
- Auto-review: planned actions are checked against your instructions and safety requirements before they run.
- Advance approval can be granted for recurring tasks — but OpenAI notes that "approving one message does not give your dot ongoing permission to contact people on your behalf."
That last point is the one that will annoy people and should not. Blanket permission is exactly how an agent ends up emailing a client something you never saw, and scoping approval per-recipient rather than per-task is the more conservative default.
Prompt Injection: Read OpenAI's Own Wording Carefully
A dot browses the open web on your behalf. That means it reads content written by people who would like it to do things for them instead of you.
OpenAI says the dot is designed to "distinguish your instructions from content it encountered while working. That content does not grant permission on its own."
Then, immediately: those protections "do not eliminate" the risk of malicious instructions causing unwanted actions.
And in general: "These safeguards help reduce risk, but your dot can still make mistakes."
Take that at face value rather than as legal boilerplate. Prompt injection against an agent with a browser and your logged-in sessions is an unsolved problem across the entire industry, and OpenAI is telling you it is unsolved here too. A company that wanted to oversell this would have phrased it differently.
What Gets Retained
The dot keeps context from your conversations and plugins for as long as the dot exists. Deleting the dot removes that context — but not files or conversations stored elsewhere.
Worth understanding before you delete one expecting a clean slate.
The Regional Exclusion Says Less Than It Appears To
Dots are not available to Pro users in the EEA, Switzerland or the UK. That has been widely read as a sign that always-on agents holding credentials cannot legally operate under EU and UK rules.
That reading does not survive the rest of the availability matrix. Business Premium users in those same regions do have access. Enterprise, Edu and Healthcare have it in beta with administrator activation. Free, Go and Plus are not in the initial rollout anywhere.
If the capability itself were the obstacle, it would be unavailable to everyone in those territories, not just consumers on one plan. What it looks like instead is a decision about which customers to launch to first in markets with more regulatory exposure — business customers arrive with administrators, contracts and someone accountable for configuration; individual consumers do not.
We inferred the stronger version in our launch coverage and are correcting it here. OpenAI has published no reason for the exclusion and no timeline for lifting it, and we are not going to invent one.
What We Would Actually Connect
Judging by what the documentation supports rather than what is technically possible:
- Reasonable: read-only research across sources you already treat as non-sensitive. This is the mode with the hard boundary around it.
- Reasonable with review: drafting that you approve before it sends. The per-recipient approval model is built for this.
- Be careful: anything where a wrong action is expensive rather than embarrassing. Money movement already requires takeover, which tells you how OpenAI rates that risk.
- Do not: paste credentials into a conversation, store them in a document the dot reads, or pass them through a plugin. Those paths are explicitly outside the protections.
And start with accounts where the worst case is annoying. You cannot un-share a credential.
FAQ
Does the model see my password?
Not on a supported sign-in. OpenAI states credentials go from a secure login form directly to the browser environment without being exposed to the model.
Are my passwords stored in the dot's memory?
No. OpenAI states the dot's context does not retain credentials, images or screenshots.
Can a dot send emails without asking?
Not during proactive research, whose tools cannot send messages, change content through plugins, or control a browser. Sending otherwise requires approval, and approving one message does not grant ongoing permission.
Can a dot transfer money?
No. Money transfers and password changes require user takeover.
Is it protected against prompt injection?
Partly. The dot is designed to treat content it encounters as information rather than instruction, but OpenAI states these protections do not eliminate the risk.
Why is it unavailable in the UK and EU?
The exclusion applies only to the Pro plan; Business Premium has access in those regions. OpenAI has given no stated reason or timeline.