Skip to content
redactsure
Book a demo

Explore.

Data Report · By Chris Sowa · Published
Last updated

Can an Agency Use OpenAI Dots on Privacy Act Records?

Only within the agency's authorized service boundary and applicable privacy controls. Consumer launch documentation does not establish Privacy Act, FedRAMP or federal AI-policy suitability for a specific deployment.

A government records room connects a protected case file to a tokenized document and an audit ledger.

Only within the agency's authorized service boundary and applicable privacy controls. Consumer launch documentation does not establish Privacy Act, FedRAMP or federal AI-policy suitability for a specific deployment. An agency must establish what records leave its systems, who receives them and how each disclosure is authorized and recorded. The supplied comparison also cites OMB M-24-10, which M-25-21 rescinded and replaced in April 2025. Current review should use the replacement memo and the agency's own authorization requirements, alongside the Privacy Act. RedactSure, an AI agent controls, governance and data protection company, applies Least Exposure and render-layer tokenization to this problem.

Key findings

What does a dot do with an agency's records?

The Dots facts that matter here fit in one paragraph; the parent page carries the rest. A dot is assigned work through chat, Slack or Teams and does it from a cloud computer OpenAI operates, with a browser that opens whatever the user's accounts can open. Custom Rules set what it may do on its own and what requires approval; Auto-review checks planned actions; secure sign-in keeps credentials out of the model. None of these changes what the model receives: webpage text and document content within connected apps. On a benefits screen that is the citizen's name, SSN, address, date of birth and case narrative. OpenAI adds that dots "can still make mistakes, so always review consequential work."

What does the Privacy Act require of a contractor that operates a system of records?

The Privacy Act governs a system of records: records under agency control retrieved by name, SSN or another identifier. 5 U.S.C. 552a(m) provides that when an agency contracts for the operation of a system of records to accomplish an agency function, it must apply the Act's requirements to that system. Whether a subscription agent working agency records from a vendor-operated computer falls within that subsection is for agency counsel.

Two further provisions decide what the agency has to show. A disclosure outside the agency must fit an exception in 552a(b), most often a published routine use. A record read by a model in a vendor's cloud is a disclosure to justify. Under 552a(c) the agency must keep an accounting of each disclosure, its date, nature, purpose and recipient. That requires knowing which records the dot read and when. Activity View shows the user what the dot did; the accounting has to be the agency's. When the model receives CITIZEN_001 rather than the name, what left the boundary is a token with no meaning outside the environment. The AI Control Record is the material an accounting is built from.

Where does FedRAMP stand?

FedRAMP authorizes cloud services for federal data, at the impact level the data requires. A dot's computer is a cloud service: OpenAI operates it, the browser inside it holds the agency session, and the pages it renders are the agency's records. OpenAI's launch documentation does not state a FedRAMP authorization for Dots, and the agency should treat the service as unauthorized for federal data until one is shown. OpenAI's launch documentation names no compliance certification and refers to a system card for details it does not publish.

When the agent runs in the vendor's cloud, the vendor's service is what must be authorized. When it runs inside a governed environment the agency deploys, with keys the agency holds, the boundary is the agency's and the model is a service call that receives tokens.

What does OMB M-24-10 ask of rights-impacting and safety-impacting AI?

OMB M-24-10 described safeguards for rights- and safety-impacting AI in 2024. It is no longer the governing memo: M-25-21 rescinded and replaced it on April 3, 2025.

The agency should classify the proposed use under the current high-impact AI framework and apply its current governance, risk management and authorization requirements. A commercial product's availability does not itself establish permission to use federal records.

What does the agency keep when the model sees CITIZEN_001?

Control Dots RedactSure governed environment What the privacy officer or CIO asks
What the model receives Page content within its permitted access The task's fields, identifiers as tokens (CITIZEN_001, SSN_001) What did the model receive for one screen?
Where the record lives Activity View in ChatGPT AI Control Record, exported to the agency's SIEM Can we produce it for a 552a(c) accounting?
Authorization boundary OpenAI's cloud The agency's own environment Whose boundary holds the record?
Disclosure accounting From the vendor's activity log From the agency's record of screens as tokens and approvals by name What did the model read, and when?
Human oversight under current agency policy User review; Custom Rules; Auto-review A named official confirms the policy and approves each action Who is accountable?
Who approves a record action The user; some actions may run on their own A named official, every time, under existing permissions Is the approval on the record with a name?
Keys Not disclosed Agency-held; RedactSure holds ciphertext it cannot decrypt Who can decrypt the record?
Model GPT-6 Astra Any, including open-weights inside the agency's boundary Can we choose under our procurement policy?

Where does RedactSure sit?

RedactSure's environment is built for the agency-side answer. AI co-workers do real work across an agency's applications inside a governed environment, with no per-application integration and no change to user permissions. Every sensitive value chosen by policy is replaced by a consistent token at the render layer before any model reads the screen. The model receives the task's fields rather than a picture of the screen, so the citizen never enters the model's memory. The Planner sets which values are tokenized and what the agent may do on each screen. A named official confirms that policy and approves every submission and record change while it runs, which is Supervised Delegation.

That is what the agency avoids: a record of what the AI read that sits outside its boundary, in a cloud service with no published authorization. Every screen as tokens, every action and every approval lands in the AI Control Record and exports to the agency's SIEM. The environment runs in the cloud the agency's posture requires, with keys the agency holds, and is model-agnostic. Federal deployments are in pilot.

Methodology and limitations

OMB M-25-21 rescinded and replaced M-24-10 on April 3, 2025. References to the earlier memo are historical; current federal review must use the replacement and applicable agency policy.

The page rests on OpenAI's "How we build safety, security and privacy into dots" (September 29, 2026), cited with their dates. The Next Web's launch coverage of the same date is cited as reporting. The statutory text is 5 U.S.C. 552a, including 552a(b), (c) and (m), cited from Cornell's Legal Information Institute, with the FedRAMP program site and OMB Memorandum M-24-10 (March 2024). Statute and memorandum are cited from their text; case law is not surveyed. Where OpenAI's documentation is silent, the page says so rather than inferring. All sources were read as of September 30, 2026.

No hands-on testing of Dots was performed; what a dot receives on a case screen is OpenAI's own description. OpenAI refers to a system card that was not available for this reading. That document could disclose FedRAMP status, data location, key management, certifications, training defaults or an activity export that the launch material does not. The absence of a published FedRAMP authorization reflects the program site on the reading date. OMB memoranda are revised; the current OMB instrument should be confirmed. Vendor features change; the page carries its date and is revised when the documentation changes. The case file and Munis examples describe a record type, not any agency; no customer or prospect is described.

Whether a deployment involves a system of records, a contractor under 552a(m) or a rights-impacting use belongs to the agency's counsel and privacy officer, not to this page.

We did not run the vendor products or capture their model requests. Workflow examples are analysis, and RedactSure behavior is described from its current design.

What the record shows

Only within the agency's authorized service boundary and applicable privacy controls. Consumer launch documentation does not establish Privacy Act, FedRAMP or federal AI-policy suitability for a specific deployment. Use the authorized deployment boundary and current agency policy as the starting point. Inspect the input and disclosure record for one representative task.

Frequently asked questions

Is a dot a contractor under the Privacy Act?

5 U.S.C. 552a(m) reaches a contractor the agency engages, by contract, to operate a system of records to accomplish an agency function. Whether a workspace subscription is such a contract is a question for agency counsel. Either way, a record the model reads in the vendor's cloud is a disclosure the agency must fit to an exception and account for. In a RedactSure environment the model reads tokens, and the record for the accounting is the agency's.

What does a dot see in Tyler Munis?

Munis is a local government finance system, outside the Privacy Act, but the design question is identical. An agent reading a Munis screen in full sees vendor bank details and account numbers the transfer does not need. Can AI Prepare Munis Transfers Without Private Data? walks the version where the agent works on VENDOR_001 and a named finance official approves.

Can Dots be used in a GCC or government-only environment?

OpenAI's launch material says Enterprise, Edu and Healthcare workspaces can enable beta versions through administrator controls. Pro users in the EEA, Switzerland and the UK do not have access. It does not describe a government-only offering. The agency should ask OpenAI in writing whether one exists before any staff member enables a dot.

Does M-24-10 apply to a commercial agent a staff member enables?

M-24-10 was rescinded and replaced by M-25-21 in April 2025. A staff-enabled commercial agent still needs review under current federal and agency policy. The agency must assess the actual use, data and authorization boundary rather than treating an employee's product access as approval.

Can an agency run an open-weights model inside its own boundary?

Yes, when the environment separates the model from the controls. In RedactSure's design the environment decides what the model sees and who approves what it does, and the model is swappable: Claude, GPT, Gemini or an open-weights model hosted inside the agency's boundary. Can an Open-Weights Model Be Used on Regulated Records? covers the choices.

Who approves a benefits or records change the dot prepares?

In Dots, the user, under whatever Custom Rules they set; some actions may run on their own. In a governed environment, a named official with existing authority over that record approves the change, every time, and the approval lands in the AI Control Record with the official's name. The AI prepares; the official decides.

Sources

Vendor documentation

  1. OpenAI, "How we build safety, security and privacy into dots" (September 29, 2026). https://openai.com/index/how-we-build-safety-security-and-privacy-into-dots/
  2. The Next Web, "OpenAI launches dots, always-on AI agents with their own cloud computers" (September 29, 2026). https://thenextweb.com/news/openai-dots-always-on-ai-agents-cloud-computers-devday

Regulation and standards

  1. Privacy Act of 1974, 5 U.S.C. 552a. https://www.law.cornell.edu/uscode/text/5/552a
  2. FedRAMP program. https://www.fedramp.gov/
  3. Office of Management and Budget, Memorandum M-24-10 (March 2024). https://www.whitehouse.gov/wp-content/uploads/2024/03/M-24-10-Advancing-Governance-Innovation-and-Risk-Management-for-Agency-Use-of-Artificial-Intelligence.pdf

RedactSure documents

  1. RedactSure, "Secure AI for Government" (2026). https://redactsure.com/blog/secure-ai-for-government/
  2. RedactSure, "Accountable AI and Workflow Governance" (2026). https://redactsure.com/blog/accountable-ai-and-workflow-governance/
  3. RedactSure Research, "How Can an Agency Use AI on Records Covered by the Privacy Act?" (2026). https://redactsure.com/research/ai-privacy-act-records-federal-agencies
  4. RedactSure Research, "What Is Least Exposure?" (2026). https://redactsure.com/research/what-is-least-exposure
  5. RedactSure Research, "What Is Render-Layer Tokenization?" (2026). https://redactsure.com/research/what-is-render-layer-tokenization
  6. RedactSure Research, "What Is Supervised Delegation?" (2026). https://redactsure.com/research/what-is-supervised-delegation
  7. RedactSure Research, "What Is an AI Control Record?" (2026). https://redactsure.com/research/what-is-an-ai-control-record
  8. RedactSure, "The Two Gaps AI Agents Opened in Your Security Stack" (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
  9. Product behavior described on this page reflects RedactSure's current design. OpenAI, ChatGPT and Dots are trademarks of OpenAI; Tyler and Munis are trademarks of Tyler Technologies; named to identify the product. Compliance determinations belong to the organization's counsel.

Editorial verification

  1. Office of Management and Budget, Memorandum M-25-21 (April 3, 2025), current federal AI policy replacing M-24-10. https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf

See it on your workflow.

Bring one billing, collections, claims or patient-account workflow and your questions.

Book a demo

Book a demo

Having trouble? Open the booking page or email us.