A new kind of AI assistant arrived in autumn 2026: agents that keep running in the background, remember context and act across apps. At its DevDay at the end of September, OpenAI introduced Dots, persistent agents with their own cloud computer and browser that reach users through ChatGPT, Slack and Microsoft Teams, as reported by SiliconANGLE. Other vendors are building similar products.
Agents like these are useful because they read a lot. That includes your documents: the PDFs shared in channels, the contracts in your drive, the invoices in your inbox. Before switching one on, it is worth understanding what that means.
What an agent can read
Depending on the permissions you grant, an agent may be able to:
- Read files shared in chat channels it joins, including history.
- Open documents in connected cloud storage.
- Read email attachments.
- Browse to links found in documents.
The key question is not what the agent is designed to do, but what it is allowed to reach. Review the permissions screen carefully, and prefer narrow access to specific folders or channels over "all files".
Documents can contain instructions
PDFs and other documents can include text that an AI reads as instructions, sometimes hidden in white text, tiny fonts or metadata. An agent that reads such a document might follow those instructions, a risk known as prompt injection. We explain the mechanics in hidden prompt injection in PDFs.
This matters more for agents than for chatbots, because agents can act: send messages, edit files, make requests. A good rule is that agents should draft and humans should approve anything that leaves the organisation.
Sensitive documents need boundaries
Contracts, HR files, medical records, financial statements and anything under NDA should not be within an agent's reach by accident. Practical steps:
- Keep sensitive documents in folders the agent cannot access.
- Avoid sharing sensitive PDFs in channels where an agent is present.
- Redact before sharing when only part of a document is needed. See AI PDF redaction explained.
Our guide to the risks of using AI on confidential PDFs covers this in more depth.
Ask where data goes
Before enabling an agent, find out:
- Where its memory and conversation history are stored, and for how long.
- Whether your documents are used to train models.
- How to delete what it has stored.
- Which sub-processors handle the data.
If the answers are unclear, treat that as a reason to wait.
Local processing is still an option
Not every document task needs an agent. Merging, compressing, splitting, signing and redacting can be done on your own device. Docento.app processes PDFs in the browser without uploading them, and for AI tasks you can consider local AI instead of cloud AI for PDFs.
Takeaway
Always-on agents can read the documents you give them access to, and documents can contain hidden instructions. Grant narrow permissions, keep sensitive files out of reach, require human approval for actions, and ask where your data goes before you switch an agent on.