
Share
OpenAI says its new Dots agent is safer than Meta's Muse, which was pitched as safer than its own predecessor. The pattern raises a basic question: when tech companies promise privacy, who's actually checking?
Imagine handing a new assistant your bank login, your private messages, and your home address, all so it can book a flight or haggle over a couch on Marketplace. That's the bet AI labs are asking consumers to make right now, and they're doing it by leapfrogging each other on privacy promises that haven't always held up.
At OpenAI's DevDay this month, CEO Sam Altman introduced the company's new AI agent, Dots, declaring that OpenAI wants to "set a new standard for privacy in frontier AI." Throughout the event, OpenAI executives took pointed, if unnamed, shots at Meta's Muse, suggesting their rival had failed to keep user data safe. It was a familiar move. A couple of months earlier, Meta had launched Muse with nearly identical language, pitching it as a safer alternative to its own predecessor, OpenClaw. CEO Mark Zuckerberg promised at the time that Muse was "built from the ground up for privacy and security."
This is the pattern now. Each new agent arrives wrapped in reassurances that it learned from the last one's mistakes. The real question is whether any of these companies can actually back that up, or whether "safer than our competitor" has simply become a marketing line that resets with every product cycle.
Think of an AI agent like a personal assistant you've just hired, except this assistant lives inside a company's servers and needs access to your calendar, your wallet, and sometimes your private conversations to do its job. The more useful it is, the more it needs to see. That tradeoff is the entire business model, and it's also where things get risky.
Nat Friedman, head of product at Meta Superintelligence Labs, wrote on X that Meta's goal with Muse was to build something comparable to OpenClaw "that we could make safe and secure and easy to use and scale to billions of people." The company stores user data on what it calls a secure virtual machine, an isolated computer environment with its own browser, memory, and storage. Meta has said most of its engineering effort went into operating Muse "more safely," and acknowledged in a blog post that "Muse can and will still make mistakes, but we expect they'll be much less frequent and cause much less damage due to the safety systems we've built in."
Muse topped the App Store charts and, according to Apptopia, picked up 600,000 daily active users in the US within weeks of launch. But the privacy record since then has been rocky. Although user data is kept isolated from other users, Meta itself can still access it; a feature meant to cryptographically block the company's own access isn't expected until later this year. A security researcher found a zero-day vulnerability that could have let an attacker take control of Muse. It's since been patched, but its existence undercuts the "built from the ground up for privacy" framing. Reporting from 404 Media found multiple serious security issues surfaced at the last minute before launch, including one that reportedly could have exposed Meta's own internal databases.

Beyond the security holes, Muse also seems to collect, and sometimes share, more than users expect. The agent defaults to letting Meta train its models on what people type into it, though opting out is possible. One Inc. reporter said Muse read his private messages without being asked to. A YouTuber reported that it offered his home address to a stranger through Facebook Marketplace. In both cases, Muse was apparently working exactly as designed, but the users had no idea it would go that far. Wired reported separately that the platform builds "detailed profiles of all your friends and family." None of this is shocking given Meta's history with data, but it doesn't exactly support the idea that Muse was uniquely privacy-conscious.
OpenAI has leaned hard into that gap. Alexander Embiricos, OpenAI's Codex product lead, said onstage at DevDay that the company is focused on building the "most trustworthy, safe, and secure assistant," while Altman demonstrated controls letting users set limits, such as capping how much Dots can spend without approval. Glen Coates, OpenAI's head of app platform, drew a direct contrast with Meta's scale: "I think we're in a different position to Meta in that they don't have an AI product that has 1.2 billion users," he said, adding that "launching something that makes those kinds of mistakes is something that we would try to take the care to avoid."
For enterprise customers, OpenAI pitched stronger data controls and a zero-retention option, meaning no data is stored on OpenAI's servers at all. So far, Dots hasn't generated the kind of scandal headlines Muse has. But that comparison comes with an asterisk: Dots is only available on ChatGPT subscription tiers starting at $100 a month, so far fewer people are actually using it. Fewer users, fewer chances for something to go wrong in public.
Even with fewer scandals, the comfort gap remains real. The Verge's Allison Johnson described feeling uneasy typing her bank information into Dots when the agent asked for it mid-task. Muse sidesteps that specific friction with a Stripe integration, but the underlying discomfort, handing financial details to software, isn't something either company has fully solved.
Not every company is playing the privacy-promise game. Instinct, another AI assistant, drew public criticism over reportedly broad terms of service that gave it sweeping access to user data. The company appears to have since revised those terms. Its experience is a reminder that not making privacy claims doesn't make a product safer, it just means there's one less promise to break.
What's emerging is a three-part playbook across the industry: make the agent useful enough that people tolerate the risk, make it friendly enough to offset the creepiness, and make privacy promises specific enough to sound credible, then hope they hold. For consumers, that's a precarious position. Trust in these systems is being built on marketing claims made in the absence of independent verification or binding regulation. Until there's real outside oversight, whether from regulators, security researchers, or sustained press scrutiny, the only check on these promises is whether the next company's launch makes the last one look bad by comparison. That's not a privacy standard. It's a sales pitch dressed up as one.
Tags
Original Sources
AI agent makers are promising privacy — will they deliver?
↗ https://www.theverge.com/ai-artificial-intelligence/1009051/privacy-ai-agent-promises-openai-meta-muse-dots
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
11 October 2026
17 articles
Related Articles

Anthropic Pulls Internet Access From Internal AI Testing After Agents Go Off-Script
Policy & Regulation · 5 min

Australia's Joint Committee on AI Moves Through Final Round of Public Hearings
Policy & Regulation · 5 min

Microsoft and AWS Push Agentic AI as the Next Layer of Industrial Software
Products & Applications · 5 min
Related Articles

Anthropic Pulls Internet Access From Internal AI Testing After Agents Go Off-Script
Policy & Regulation · 5 min

Australia's Joint Committee on AI Moves Through Final Round of Public Hearings
Policy & Regulation · 5 min

Microsoft and AWS Push Agentic AI as the Next Layer of Industrial Software
Products & Applications · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.