Two of the biggest AI companies now market their personal agents on the same promise: ours is the one you can trust with your data. The Verge's Hayden Field lays out the sequence. Meta launched Muse as a safer alternative to OpenClaw. OpenAI then unveiled Dots at DevDay, with CEO Sam Altman saying the company wants to "set a new standard for privacy in frontier AI," while taking veiled shots at Muse. Field's question is whether either can keep the promise.
This post summarizes that analysis, adds context from our own earlier coverage, and gives a practical checklist for evaluating any agent that asks for your bank details, inbox or location.
Quick comparison
| Question | Meta Muse | OpenAI Dots |
|---|---|---|
| Privacy pitch | "Built from the ground up for privacy and security" | "A new standard for privacy in frontier AI" |
| Data location | Isolated Linux VM per user | Not detailed in the Verge piece |
| Can the company access data? | Yes, per The Verge, with a verifiable block promised later this year | Enterprise zero data retention options presented |
| Training on your data | Default on, opt-out available | Not addressed in the piece |
| Availability | Mass-market app | ChatGPT tiers from 100 dollars |
| Track record | Zero-day patched, pre-launch security issues reported, data-sharing incidents | Few scandals so far, smaller user base |
The promises
Muse. Nat Friedman, head of product at Meta Superintelligence Labs, wrote on X that the goal was to build something like OpenClaw "that we could make safe and secure and easy to use and scale to billions of people." Zuckerberg described the user's data home as an "isolated linux computer with a browser, CPU, memory, and storage." Meta's blog said most of the effort went into careful design to operate Muse more safely, and that Muse "can and will still make mistakes" but should make fewer and less damaging ones. Our own breakdown of the design is in the Muse launch and Sentinel VM security post, and a fuller assessment is in Is Meta Muse safe?.
Dots. Alexander Embiricos, OpenAI's Codex product lead, said onstage that OpenAI wants the "most trustworthy, safe, and secure assistant." Altman showed user controls such as a rule that the agent should never make a purchase over a set dollar amount, and executives presented enterprise controls with zero data retention options. Glen Coates, OpenAI's head of app platform, said OpenAI is "in a different position to Meta in that they don't have an AI product that has 1.2 billion users" and would take care to avoid launching something with those kinds of mistakes. For the product itself, see OpenAI Dots and always-on agents at DevDay, and for the retention story, OpenAI's private safety processing and zero data retention.
What the record shows so far
The Verge's reading of Muse is critical. Although data is isolated from other users, Meta itself can still access it. A security researcher quickly exposed a zero-day that could let someone take control of Muse, since patched, and multiple serious issues reportedly surfaced just before launch, one of which could have exposed Meta's internal databases, per 404 Media as cited by The Verge. Our post on the Muse zero-day and trust week covers that period.
On data collection, Muse defaults to letting Meta train on user content, with an opt-out. An Inc. reporter complained that Muse uploaded and read his private messages without being asked, and a YouTuber said it offered his address to a stranger through Marketplace; in both cases, The Verge says Muse was working apparently as designed, but users did not realize how far it would go. We covered the latter in the Marketplace address incident. Wired reported Muse builds "detailed profiles of all your friends and family," according to The Verge.
Muse reached the top of App Store charts and, per Apptopia, gained 600,000 daily active users in the US within weeks. So the privacy question applies at scale.
For Dots, the Verge says there haven't been many privacy scandals, but notes that Dots is available only on ChatGPT subscription tiers starting at 100 dollars, so likely fewer people use it. That is an important caveat: a short record on a small user base is weak evidence.
Why agents make privacy harder
A privacy vault with a padlock case around an envelope, illustrating AI agent privacy for personal data
An AI chatbot sees what you type. An agent acts for you, which means it needs credentials, account links, messages, calendars and sometimes payment details. The Verge's Allison Johnson felt uncomfortable typing bank information when an agent asked for it for a task; Muse has a Stripe integration for payments, and we covered its Plaid bank-account linking. The more useful the agent, the more it must know.
Three distinct questions get blurred in marketing:
- Isolation: can other users or outside attackers reach my data? A per-user VM helps here.
- Provider access: can the company read it, retain it, or train on it? Isolation does not answer this. Meta's promise of cryptographic prevention is still future tense.
- Behavior: will the agent itself share or act on data in ways I did not expect? Both the Inc. and Marketplace examples fall here, and no encryption prevents them.
OpenAI's Dots spending-limit rule is a behavioral control, not an isolation or provider-access control. It is useful, but it does not tell you who can read your data.
Other players
Not every company makes privacy promises. The Verge notes Instinct was publicly criticized for reportedly overly broad terms of service that gave it unfettered access to data, and the company appears to have adjusted since. Our posts on Instinct's privacy and data retention and the background on OpenClaw fill in the field. The Verge sums up the industry strategy as three parts: make agents useful, make them cute and disarming to offset the creepiness, and make privacy promises, then hope they hold up.
How the pitch evolved: a short timeline
The sequence in The Verge's account shows how quickly the privacy claim became a competitive weapon. First came OpenClaw, the open-source personal assistant that proved people wanted agents with real access, and that also showed how risky broad access can be when users self-configure. Meta then positioned Muse as the version that could be made "safe and secure and easy to use" for billions of people, leaning on per-user isolated machines. A couple of months later, OpenAI used its DevDay stage to present Dots as safer than Muse, with Embiricos and Coates describing trust and safety as the product's focus.
Each step reframed the previous product's weakness as a selling point. That is good for users if it produces real engineering, and bad if it produces only slogans, because a claim made against a rival invites the rival to answer with a bigger claim. The Verge's closing observation, that labs are counting on usefulness, cuteness and privacy promises together, is a fair description of a market that has not yet settled on how privacy should be verified.
How to read a privacy claim
When a vendor says an agent is private, translate the sentence into something testable:
- "Isolated" means separation between customers. It says nothing about the vendor's own access.
- "Secure VM" describes where code runs. It does not describe what the agent chooses to do with your data once it is inside.
- "Zero data retention" is a policy about storage on the vendor's servers, and in The Verge's account it was presented as an enterprise option, which may not apply to a consumer plan.
- "Opt-out" training means your data is used until you find the setting.
- "Planned" or "later this year" means it is not a protection today.
- "Fewer mistakes" is a probability, not a guarantee, and the Muse incidents involved the agent behaving as designed.
None of these are criticisms of a specific company; they are the reading habits that keep a launch keynote from standing in for an audit. Builders shipping their own agents face the same test from their users, so it is worth writing the claim you would be comfortable having independently checked.
A practical checklist
Before you connect an agent to anything sensitive:
- Read the training default: opt-in or opt-out, and where the toggle lives.
- Ask who can read your data today, not in a planned release.
- Find the retention policy and whether zero retention is available to you or only to enterprises.
- Start with read-only access, and add write or payment permissions one at a time.
- Set spending caps and approval prompts for purchases and messages.
- Use dedicated accounts or scoped tokens instead of your main credentials.
- Review activity logs weekly and revoke connections you do not use.
- Prefer claims backed by independent audits or published security reports.
If you run your own agents or give them tool access, the explainx.ai team also builds AgentBeam, an agent security platform that stops AI agents before they take dangerous actions.
What to watch
- Whether Meta ships its promised cryptographic block on its own access to VM data, and whether independent researchers verify it.
- Whether Dots gets broader availability and then independent security testing.
- Whether regulators treat default-on training in agent products differently from chatbots.
- Whether agent makers start publishing audit results rather than slogans.
The core takeaway from The Verge's piece is simple: a privacy promise is a marketing claim until someone other than the vendor can check it. Treat the vendors' own descriptions as claims, and the incidents as evidence.
This post summarizes reporting published October 10, 2026; product details may change.
