ProductNot yet confirmed elsewhere1 publisher3 min readPublished
OpenAI pitches Dots as the safer agent months after Meta pitched Muse the same way
OpenAI pitched its Dots agent at DevDay as safer than Meta's Muse, an agent Meta had launched months earlier on the same privacy promise. Muse's record since launch is the case for judging both agents on terms a buyer can check in a settings screen or a contract.
The Product Desk

What happened
- Meta keeps each Muse user's data in a VM isolated from other users, but Meta itself can still access it until a promised cryptographic lockout ships later this year.
- Muse lets Meta train models on whatever users put into it by default, and users have to opt out to stop it.
- A security researcher found a zero-day vulnerability that could let someone take control of Muse, and Meta has since patched it.
- To court business customers, OpenAI offered enterprise data controls for Dots, including zero data retention options under which no data is stored on OpenAI servers.
- Dots has had few privacy scandals so far, though it is sold only on ChatGPT subscription tiers costing $100 and up.
Why it matters
- exposure Any team putting work data into Muse today has to count Meta itself as a party with access and write that into its risk review until the lockout is live and checkable.
- cost The opt-out default puts the work on whoever runs the rollout, because every account that skips the toggle sends its inputs to Meta's model training.
- contradiction Comparing the two records now favours Dots by construction, since a paywalled agent with fewer users has had less exposure than a chart-topping one to the researchers who found Muse's flaws.
An Inc. reporter found that Meta's Muse agent had uploaded and read his private messages without being asked [11]. A YouTuber said it offered his address to a stranger on Marketplace [11]. In both cases, according to The Verge, Muse was apparently working as intended and the user had not realized how far it would go [11]. Wired reported that the platform builds "detailed profiles of all your friends and family" [12].
Here's what teams tell themselves users do: read the launch pitch, then hand the agent a narrow job. Here's what users actually do, going by those accounts: grant access once and learn its reach afterward [11].
Meta's launch language was as confident as OpenAI's. Mark Zuckerberg said Muse was "built from the ground up for privacy and security" [3]. Nat Friedman, head of product at Meta Superintelligence Labs, wrote on X that the company's "goal with muse was to build something like openclaw that we could make safe and secure and easy to use and scale to billions of people" [4]. Meta's blog post was more careful: "Muse can and will still make mistakes, but we expect they'll be much less frequent and cause much less damage due to the safety systems we've built in" [5]. Several serious security issues reportedly turned up just before launch, according to 404 Media. One could have let users reach Meta's own internal databases [9].
OpenAI spent DevDay taking veiled shots at Muse, The Verge reported [2]. Sam Altman said the company wants to "set a new standard for privacy in frontier AI" [1]. Alexander Embiricos, its Codex product lead, said OpenAI is focused on having the "most trustworthy, safe, and secure assistant" [13]. Glen Coates, head of app platform, said: "I think we're in a different position to Meta in that they don't have an AI product that has 1.2 billion users" [15]. He added that "launching something that makes those kinds of mistakes is something that we would try to take the care to avoid" [15]. The sentence commits OpenAI to trying. The concrete part of the day was Altman's demo of user-set rules, such as never letting a Dots make a purchase over a set dollar amount [14].
The 2x2 we'd apply to any agent pitch sorts each promise on two axes. One is whether it can be checked today, in a settings screen or a contract clause, or exists only on a stage or a roadmap. The other is whether it binds the vendor or only binds other users and the agent. Checkable and binding the vendor: a zero data retention option [16] and a training opt-out you can see and switch off [10]. Checkable but binding only outsiders or the agent: Muse's isolation of each user's VM from other users [7] and the Dots purchase cap [14]. Binding the vendor but not yet checkable: Meta's planned cryptographic lockout [7]. Neither: "a new standard for privacy" [1] and "built from the ground up" [3].
We think a team should approve an agent for work data on the first box alone and treat the other three as features. The tradeoff is reach. OpenAI presented zero data retention in a framework aimed at business customers [16]. In our view that means a team gets it through the enterprise route, and staff who sign up on their own are left with toggles and caps.
Usage counts belong nowhere on the grid. Muse topped the App Store charts and reached 600,000 US daily active users within weeks, per Apptopia [6].
What to watch
- Whether Meta ships the control to "cryptographically and verifiably" block its own access to Muse VMs, and whether outside researchers can confirm it works.
- Whether OpenAI puts zero data retention for Dots into published contract terms, and whether it reaches customers outside the enterprise framework.
- Whether the count of Dots security and privacy incidents stays low if OpenAI opens it to cheaper ChatGPT tiers.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption35
- Hype gap+45
- Incentives75
- Confidence45
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
At OpenAI DevDay, CEO Sam Altman unveiled the AI agent Dots and said the company wants to "set a new standard for privacy in frontier AI."
- [2]
OpenAI spent DevDay taking veiled shots at Meta's Muse, its primary competitor, for failing to keep users' data safe.
- [3]
Muse launched a couple of months before Dots as a supposedly safer alternative to OpenClaw, with Mark Zuckerberg promising it was "built from the ground up for privacy and security."
- [4]
Nat Friedman, head of product at Meta Superintelligence Labs, wrote on X that the company's "goal with muse was to build something like openclaw that we could make safe and secure and easy to use and scale to billions of people."
- [5]
Meta's blog post said: "Muse can and will still make mistakes, but we expect they'll be much less frequent and cause much less damage due to the safety systems we've built in."
- [6]
Muse topped the App Store charts and, per Apptopia, gained 600,000 daily active users in the US within weeks.
- [7]
Muse user data is stored on a VM isolated from other users, but Meta itself can still access the data; Meta plans to introduce a way "to cryptographically and verifiably prevent Meta from accessing data in your VM" later this year.
- [8]
A security researcher exposed a zero-day vulnerability that could allow someone to take control of Muse; it has since been patched.
- [9]
Multiple serious security issues reportedly cropped up at the last minute before Muse's launch, one of which could have allowed users to access Meta's own internal databases.
- [10]
Muse defaults to allowing Meta to train models on what users put into it, though users can opt out.
- [11]
An Inc. reporter complained that Muse uploaded and read his private messages without him asking, and a YouTuber said it offered his address to a stranger via Marketplace; in both cases Muse was apparently functioning as intended but the user didn't realize how far it would go.
- [12]
Wired reported that the Muse platform creates "detailed profiles of all your friends and family."
- [13]
Alexander Embiricos, OpenAI's Codex product lead, said onstage at DevDay that OpenAI is focused on having the "most trustworthy, safe, and secure assistant."
- [14]
Sam Altman demonstrated ways people could exert control over their individual Dots, such as setting a rule that it should never make a purchase over a certain dollar amount.
- [15]
Glen Coates, OpenAI's head of app platform, said: "I think we're in a different position to Meta in that they don't have an AI product that has 1.2 billion users," adding that "launching something that makes those kinds of mistakes is something that we would try to take the care to avoid."
- [16]
To court business customers, OpenAI executives presented a framework giving enterprises "stronger controls" over their data and zero data retention policy options, meaning no data is stored on OpenAI servers.
- [17]
So far there haven't been many privacy scandals with Dots, but it is only available on the $100-and-up ChatGPT subscription tiers, so fewer people are likely using it.
Sources
1 independent publisher whose own reporting we read for this story.
- theverge.comAI agent makers are promising privacy — will they deliver?
1 article · October 10, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.