AI agent makers promise privacy as OpenAI's Dots takes aim at Meta's Muse
OpenAI unveiled its AI agent Dots at DevDay, promising it would set a privacy standard for frontier AI, two months after Meta launched Muse with similar pledges. Each company now cites the other's record on user data.
The two launches follow a similar pattern. Meta released Muse about two months before DevDay as a supposedly safer alternative to its predecessor, OpenClaw, with chief executive Mark Zuckerberg saying it was "built from the ground up for privacy and security." OpenAI now presents Dots as the safer alternative to Muse. Both companies are asking users to hand over more personal information even as data breaches and corporate data hoarding remain common, and both are betting that privacy claims will set them apart from rivals.
Nat Friedman, head of product at Meta Superintelligence Labs, wrote on X that the company's "goal with muse was to build something like openclaw that we could make safe and secure and easy to use and scale to billions of people." User data is stored on a secure virtual machine that Zuckerberg described as an "isolated linux computer with a browser, CPU, memory, and storage." Meta said most of the work in building Muse went into "careful design and engineering to operate [it] more safely," and its blog post said, "Muse can and will still make mistakes, but we expect they'll be much less frequent and cause much less damage due to the safety systems we've built in."
Muse topped the App Store charts and gained 600,000 daily active users in the United States within weeks, according to the analytics firm Apptopia. But researchers and reporters have since found gaps in Meta's promises. Although data is isolated from other users, Meta itself can still access it; the company says it plans to introduce a way "to cryptographically and verifiably prevent Meta from accessing data in your VM" later this year. A security researcher quickly exposed a zero-day vulnerability that could have allowed someone to take control of Muse, which has since been patched. According to 404 Media, several serious security issues emerged at the last minute before launch, one of which could have allowed users to reach Meta's own internal databases.
Data collection has drawn complaints as well. Muse defaults to allowing Meta to train models on what users put into it, though users can opt out. An Inc. reporter complained that Muse uploaded and read his private messages without being asked, and a YouTuber said it offered his address to a stranger through Marketplace; in both cases Muse appeared to be working as designed, but the users did not expect it to go that far. Wired reported that the platform creates "detailed profiles of all your friends and family."
OpenAI pointed to those problems when it announced Dots. Alexander Embiricos, OpenAI's Codex product lead, said onstage at DevDay that the company is focused on having the "most trustworthy, safe, and secure assistant," and Altman showed controls that let users constrain individual Dots, such as a rule barring purchases above a set dollar amount. Glen Coates, OpenAI's head of app platform, said, "I think we're in a different position to Meta in that they don't have an AI product that has 1.2 billion users," adding that "launching something that makes those kinds of mistakes is something that we would try to take the care to avoid."
Altman also pressed the privacy argument. To court business customers, OpenAI executives presented a framework giving enterprises "stronger controls" over their data and zero data retention options, under which no data is stored on OpenAI servers. Dots has so far produced few privacy scandals, though it is available only on ChatGPT subscription tiers costing $100 a month or more, which likely means fewer people are using it.
Handing over personal data remains a hurdle for users. The Verge's Allison Johnson wrote that she felt uncomfortable typing in her bank information when the bot asked for it during a task; Muse uses a Stripe integration to handle such payments.
Other companies have run into the same territory. Instinct was publicly criticized over terms of service that reportedly gave it unfettered access to user data, and the company appears to have made adjustments since.