Analyst(s): Mitch Ashley, Nick Patience, Vikram Rathnam
Publication Date: October 1, 2026
OpenAI did not add features at DevDay 2026. It made one coordinated move across three layers: the work surface where work happens, the runtime where agents execute, and the pricing that meters both. Together, they relocate what the CIO controls today, the record of intent and the authority to buy, toward whoever owns the outcome. That is what puts OpenAI in direct competition with the platforms running its models, Atlassian and the Microsoft and AWS agent control planes.
What Is Covered in This Article:
- How OpenAI used DevDay 2026 to move up the stack, from supplying models to owning the work surface, the agent runtime, and the pricing that meters both.
- Why dots and ChatGPT Space stake a claim on the work surface, and what that puts in contest with Atlassian, Microsoft, AWS, and Google.
- Where the CIO’s durable leverage now sits: governing dots at the connector layer rather than approving plugins one app at a time.
- What cloud Codex and the Agents API mean for runtime lock-in, competing control planes, and OpenAI’s thin record on customer proof and agent governance.
- How new model tiers, Marketplace, and data-retention terms fund the climb and bid for the committed-spend lock-in hyperscalers already hold.
The News: OpenAI made more than 20 announcements at its DevDay conference in San Francisco this week. The headline launch was dots, which are always-on agents inside ChatGPT. Each dot runs on GPT-6 Astra, has its own cloud computer, and works toward goals across a user’s connected apps. Dots are rolling out now to Pro and Business Premium subscribers. Enterprise workspaces get them only once an admin switches them on.
OpenAI also launched ChatGPT Space for team collaboration and GPT-6.1 Sol, which it says comes close to Astra at one-fifth of the price. Other announcements included computer use in the Agents API and Amazon Bedrock Managed Agents, which run OpenAI agents inside AWS. The day before the event, OpenAI withheld GPT-6.1 Astra after it failed internal safety testing.
OpenAI Moves Up the Stack and Competes With the Platforms It Powers
Analyst Take—ChatGPT stakes the work surface: OpenAI is moving ChatGPT from the place where people ask questions to the place where work gets done. Space holds shared knowledge, and Pages holds the documents built from it. Shared tasks run on a schedule or on triggers such as an email or a Slack message. The Meetings plugin turns calls into summaries and action items that land back in Space, and collaborative slides follow in the coming weeks. The releases keep source material, drafts, review, and handoff inside one environment, with dots working alongside people in it.
That is a claim on the work surface itself. AI is becoming the surface on which work happens, cutting across every application and owned by no single function, and OpenAI is building ChatGPT to be that surface. Atlassian staked the same layer on September 10 from Jira and Confluence, where work is already defined and approved. Anthropic has a head start with its daily updates to Claude Cowork. Microsoft, AWS, and Google won’t easily give ground either. They all compete for who holds the enterprise’s record of intent: the system where work is tracked, or the one where more of it is produced.
Connectors decide that contest. Dots connect to more than 4,000 apps, MCP Events lets activity in a connected app start an automation, and plugin extensions pull third-party software into ChatGPT’s sidebar and conversation flow. Every one of those paths is a decision about reach. The CIO’s durable leverage is authorizing what AI systems can reach, and dots make that decision concrete. Enterprises that govern dots at the connector layer, setting which apps and data each agent can touch, will scale them. Enterprises that approve plugins one app at a time will stall.
The connector layer is the authorization control point, where the CIO decides what each agent may reach. It sits inside the broader control plane, not in place of it, so governing there is the entry decision, not the whole of agent governance.
Adoption will not wait for procurement. OpenAI says @ChatGPT works in Slack and Teams channels without each participating teammate holding a ChatGPT license. Usage, therefore, enters through business units and working channels ahead of any seat purchase, and buying authority continues to move toward the leaders who own the outcome. Futurum’s AI Product Series has the shape of it: as of the September 2026 survey, 58% of enterprises reported AI development happening outside their formal IT or AI teams, up from the prior cycle, while the IT budget still funds that work at two-thirds of companies and rising (Futurum ETR AI Product Series, September 2026, n=600).
Origination is leaving IT while the purse is not. When usage shows up in Slack and Teams channels before it shows up in a seat purchase, a CIO watching seat counts is watching the wrong signal, and the first call is already made. A CIO who can still block a rollout may find the first call already made.
OpenAI ships dots off by default in Enterprise, Edu, and Healthcare workspaces, where an admin must enable the beta. That is a sensible starting control, and a narrow one. Once dots pursue ongoing goals across connected apps, IT’s accountability for what agents do grows faster than its share of what gets built. Enterprises that do not rebalance the two will accumulate AI risk they cannot see, and that risk surfaces first in audit and incident response, well before any procurement review.
Codex stakes the agent runtime
Codex now runs fully in OpenAI’s cloud, and the Agents API, in public beta, offers developers the harness, hosting, memory, multi-agent controls, and computer use that OpenAI says power Codex and dots. That is a claim on the runtime, the layer where agents execute. The harness is open source. The hosting and memory are what OpenAI runs, and they’re where a team’s context and task history build up. For dots and cloud Codex, that state lives with OpenAI, so choosing a runtime is a 12- to 24-month commitment, and lock-in tolerance should be the deciding factor. GitHub, Anthropic, AWS, and Google host their own agent runtimes. OpenAI is also supplying rival control planes: it is working with Microsoft to integrate specialist dots into Agent 365, and said the Bedrock-managed agents it powers run in AWS alongside a customer’s data. Enterprises will run several control planes at once, and each adds integration and governance overhead until a few dominant ones emerge at each layer of the AI stack.
OpenAI’s weak spots are referenceable customers and governance. Codex Security Cloud runs continuous and scheduled scans of cloud environments and prepares verified fixes. OpenAI’s agents write the code, so OpenAI is best positioned to secure it as written. It shipped a scanner that checks the code afterward. The evidence so far is OpenAI’s report that its own engineers fix dozens of bugs a day with dots. OpenAI named no customer outcomes, and governance got one sentence: users can set boundaries on a dot’s app and computer use. That controls what a dot may do, not what it did.
OpenAI writes the code, so it is positioned to ship the evidence with each pull request: what changed, what was tested, why it is safe to merge. It shipped a scanner that reads the code afterward instead. Until that evidence rides with the PR, the people approving agent work stay the throughput ceiling, and the only proof OpenAI offers that they can be trusted is its own engineers fixing their own bugs..
New tiers fund the climb
The Agents API packages the harness behind Codex as a managed service. It handles long-running sessions, tool search, sub-agents, and, as of DevDay, computer use. OpenAI charges only for the tokens and tools agents consume. Each orchestration feature OpenAI absorbs into its harness is one less reason to build an agent stack from a hyperscaler’s components.
AWS, Microsoft, and Google Cloud each sell a model-agnostic control plane for agents. For now, OpenAI cooperates where it must. Bedrock Managed Agents runs OpenAI agents entirely inside AWS on AgentCore, and specialist dots will be governed through Microsoft Agent 365. OpenAI supplies the harness and the model, while the hyperscaler keeps the control plane and the customer’s cloud commitment. We expect OpenAI to push on that boundary with every release.
OpenAI’s new pricing tiers are designed to fund the push. GPT-6.1 Sol comes close to Astra at one-fifth of the token price, which suits always-on agents. Ultrafast sells speed at a premium, and the Decisions API handles narrow routing jobs on the small Luna model. OpenAI Marketplace lets enterprises spend part of their OpenAI commitment on partner products, which gives OpenAI the kind of committed-spend lock-in hyperscalers have long enjoyed. Private Intelligence adds zero data retention for regulated buyers. Better retention terms from a US provider still do not settle whose laws can reach the data, and that question increasingly decides where non-US enterprises run their agents.
What to Watch:
- Whether OpenAI’s agent pulls requests start carrying evidence of what changed, what was tested, and why. Without it, the human review queue becomes the bottleneck that caps agent throughput.
- Whether OpenAI moves customer proof past its own engineers and governance past a single boundary-setting toggle before enterprises commit to a runtime for 12 to 24 months.
- How hard OpenAI presses on the hyperscaler boundary it now cooperates across, from Bedrock Managed Agents to Microsoft Agent 365, as it ships each release.
- Whether jurisdiction and data residency decide where non-US enterprises run their agents, given that Private Intelligence offers zero retention without extending legal reach.
- Whether OpenAI’s pre-release safety gating holds as it ships always-on agents that act across connected apps.
See the conference recap on OpenAI’s website.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Other Insights From Futurum:
OpenAI’s GPT-6 Astra: Benchmarks, Cyber Risks, and Market Impact
Atlassian Bets the Work Surface on Governed Agentic Workflows
NVIDIA Nears $12.9B Deal for Hugging Face, Escalating AI Ecosystem Strategy
Enterprise AI Overruns Hit 46.9%: Is the Reckoning in FY2027?
NVIDIA Wants Agent Safety Enforced in Silicon
