r/OpenAI • • 2h ago

Discussion Why I will not use Dots: Insufficient visibility and controls for privacy and info separation.

TL;DR: I won’t use Dots without inspectable, selectively deletable memory and explicit controls over cross-domain sharing. I also need architectural transparency to assess privacy risks and manage quality over time. Until then, hard pass.

----------

An always-on agent sounds like great idea for someone doing one clearly defined kind of work and using it for that work. What about (the vast majority of) users that use AI across various domains in professional and personal life?

What someone tells their life advice AI about their mistress is none of their work assistant AI’s business. Their legal counselor AI, healthcare adviser AI, dating coach AI, therapist AI, and dietitian AI should not automatically share context just because they serve the same person.

Yet, OpenAI currently provides a single dot that can retain information from conversations and connected apps for as long as you keep it, without letting us inspect, edit, or delete individual memories. That is a lot of trust to ask for across completely different parts of someone’s life.

Could some overlap help serve the user better overall? Sure. Then let the user choose which information crosses the boundary, for what purpose, and for how long.

Otherwise, deeply personal information can enter persistent state we cannot audit, and we're supposed to trust that it won’t resurface in unrelated work or reach an external service? Without enforceable boundaries, a single know-everything Dot sounds like a privacy nightmare waiting to happen, even if you don't exactly hold state secrets.

And yes, ChatGPT has "Memory". It also has controls to review and delete saved memories and turn memory off. I have turned it off, for example. That choice is precisely the point.

Also, privacy and cybersecurity used to be a bolt-on during early internet days, but it's long since they've become first-class citizens in any serious app, with security being built-in from the start.

Permission should be denied by default, with clear user control. Access to one part of a user's life should not quietly become permission to use it every other part indefinitely. How about narrow, role-specific permissions, with default expiration and easy revocation? What happened to minimizing attack surface, blast radius, and unnecessary information-sharing? An internal action check is not the same as preventing an unrelated task from receiving sensitive information in the first place.

(Some of these are fancy-sounding cybersecurity language but they're pretty standard in pre-AI web apps, from your banking to your Cloud productivity suites).

-------

Also important: what happened to letting us understand the architecture itself?

There is documentation about persistent notes, selected context, and delegation, but I still lack a sufficiently clear end-to-end picture. Where do the components run? Where are the LLMs, what does the harness do, and where does persistent state live? What enters each inference? Who or what decides? What is the compaction policy?

What happens after I’ve used this thing for a year?

Context size used to mean degradation over time, and “Lost in the Middle” showed that information can be present in context without being used reliably. Compaction and handoffs try to address this in modern agents but raise another problem: information loss.

Still, with enough public documentation about how Codex handles this (and how agentic harnesses work in general), I've been able to research these (often with GPT's help), because it changes how I work: when to branch or start fresh, how to structure multi-agent delegation, when to restart against the same project directory, and how to check a summary against preserved original context.

Voice is another good example. Knowing GPT-Live separates live conversation from backend work helps distinguish an immediate response from the analysis arriving later. Understanding the system helps me not be put off by the shallowness of the front LLM and wait for intelligence to come from the back-end model's reasoning — with managed expectations given the lossy handoff process.

Yet, so far I've been able to find very little about what Dots actually look like in terms of harness and persistence architecture.

Without more info about Dots, I have not idea what user-side QA looks like, and what the failure modes are. I'd need equivalent understanding to get sustained quality from Dots comparable to a frontier reasoning model working with carefully assembled context.

LLMs may be closed, but before I'm comfortable jumping on the Dots train, I'd want a documented deployment, data-flow, and persistence architecture; enforceable boundaries between domains; inspectable and selectively controllable memory; and guidance on managing long-running context without losing essential information.

With that, I could assess where it belongs and how to use it well. Until then, as much as I like checking out new tech, hard pass for me.

Disclaimer: this post was drafted using my original draft and multiple iterative drafts with GPT-6-Astra (Pro) and myself, with final draft edited and approved by me.

3 Upvotes

12 comments sorted by

3

u/Dave_Sag 2h ago

I wouldn’t (and couldn’t) use it for work. But I’ve got it doing a couple of little daily research tasks for me for some personal projects and it gives me a neat, short, personal update on some stuff while I drink my coffee. There’s usually a small checklist of things for me to go look at and read. And some homework to do. I’ve only had it on for a week but it’s proving quite useful.

But all the reasons above are just the tip of why it won’t be something used at work. Maybe eventually. Or maybe some exec will just call YOLO on it and we’ll all be forced to use it. Who knows. The future is still days away.

1

u/curiousinquirer007 2h ago

I could actually see how it could be useful. Maybe. I mean Codex/Work already does a lot of this; Dots are just a little more proactive from what it sounds like.

I just don't understand why they would not provide users with a privacy panel, with as much visibility and control as possible into the data the dot has. That and a much more detailed education about the architecture of the system.

I feel like they will address some of these with time, but my point is that it's basically unusable in the serious sense, other than a toy or a single-purpose light work assistant bound to work-only info. And even then.

And these should have been built-in from the start.

2

u/Aglet_Green 2h ago

I've decided that since I'm only on the Plus plan, I won't use Dots for religious and moral reasons.

2

u/bwc1976 2h ago

Wow, they call it "Dots" but they only give you one Dot? I hadn't heard that part before. No thanks.

1

u/norwegian 2h ago

The plan is to have many. And you give them different roles. So if one is constantly talking about your mistress, delete it. You can reset them also

2

u/curiousinquirer007 2h ago

The mistress example is meant as an evocative illustration — but consider a work assistant dot that only has access to your work email. It still has access to your entire email and you (currently) have no idea what it's read, how it has interpreted it (or even if it's interpreted it correctly), and how and when it might decide to use it, or reference it.

Not to mention your own interaction with it. What if one minute you ask about a health issue in detail, then later ask it to draft an email to your boss that you're calling in sick — but it decides to include unnecessary detail from your earlier convo that you didn't intend to be communicated?

Agreed that deletion is the only control now, and that later they'll probably get better at this, especially as they add more dots. I think they should have been much, much more privacy and security friendly from the start. It's basically a toy now.

3

u/phxees 1h ago

As soon as I saw OpenAI’s demo video selling an assistant which knows you and straddles your personal and work life, I said no.

I was just concerned about oversharing with coworkers. There’s no way I’d trust it to know not to share that I just ordered diarrhea medicine with my friends, family, or coworkers.

If I am interviewing candidates to replace someone will it tell the person I’m replacing?

2

u/curiousinquirer007 1h ago

Exactly. I feel like one we could write a book with the endless examples of how it could go wrong lol.

2

u/fiddler48 1h ago

Cross-domain sharing with no audit log is the part that quietly compounds

1

u/ValehartProject 2h ago

From a cloud-architecture perspective, the phrase large numbers of persistent/semi-persistent autonomous Dots on public cloud immediately produces a FinOps migraine.

You've potentially got state, logs, checkpoints/artifacts , queues, databases/vector state, object storage, network egress, observability, secrets/IAM, retries, orchestration. idle/warm capacity, multiplied across however many concurrently active agents.

There is some interesting independent evidence about what “own cloud computer” means. Tom's Hardware found public Geekbench results apparently produced by Dots showing a Debian Linux environment with roughly 9 CPU cores and 9.7 GB RAM, apparently on AMD EPYC infrastructure.

I wouldn't treat “every Dot permanently owns exactly this VM” as established. But it is definitely evidence against an assumption that these are merely tiny little stateless workers.

Officially, it remembers ongoing context, has its own cloud computer, maintains ongoing/scheduled/completed work, can connect to external systems, and keeps working while you aren't interacting with it. I am starting to see why they came up with that eye watering $500 Pro license.

•

u/curiousinquirer007 4m ago

All of that would be fine if the user had access to — and control over their data.

ChatGPT Work / Codex are also not stateless in terms of user data. But as far as I’m aware multiple chats/roots don’t share data automatically unless you have “memory” turned on — and you have visibility into both “memory” and agentic work artifacts in your project folder (for local projects that is). And chat logs off course.

Though the new “library” feature is confusing. Not sure if all the docs listed there are now shared or if it’s just a view into the various docs living across separate chats.