AI Agent Makers Are Promising Privacy: Will Meta's Muse and OpenAI's Dots Deliver?
OpenAI's Dots agent arrives with a promise of a new privacy standard, aimed at Meta's Muse. Months ago Muse itself was sold as a safer OpenClaw. Each generation sells safety while asking for more data. Only verifiable mechanisms can prove it.
On October 10, The Verge's senior AI reporter Hayden Field described a scene with more than a little irony. At this year's OpenAI DevDay, CEO Sam Altman unveiled the company's new agent, Dots, and told the crowd that OpenAI wants to "set a new standard for privacy in frontier AI." According to the report, OpenAI spent the day taking veiled shots at its main competitor, Meta's Muse, for failing to keep users' data safe. Yet a couple of months earlier, Muse had launched as a supposedly safer alternative to its predecessor, OpenClaw, and Mark Zuckerberg had promised it was "built from the ground up for privacy and security." A chain of promises emerges: Muse positioned against OpenClaw, Dots positioned against Muse, and each generation presented as the safety fix for the one before it.
A note on method. This analysis rests on the public portion of the report. Anything said below about how agents work internally is inference, and it does not claim that any company has disclosed technical detail. With that stated, the contradiction at the center of the story is hard to miss. The report frames the backdrop plainly: companies hoard customers' personal data, cyberattacks are a dime a dozen, and AI labs are nonetheless trying to convince users to share even more information with their agents. The industry asks for deeper trust while using "we are safer than the other guys" as the key to unlock it. Privacy has stopped being a compliance footnote. It is now a headline product feature, and at DevDay it became a competitive talking point aimed at a named rival.
Why does an agent sharpen the privacy problem? The reasoning comes from the product form itself. An ordinary chatbot handles what a user chooses to paste in. An agent earns its value by acting: reading email, arranging a calendar, searching files, operating accounts. To do that, it needs standing, broad, and often cross-application access. The wider the data surface, the more a single mistake costs. The larger the permission, the more attractive the agent becomes to an attacker. When one product can both read and act, a flaw can escalate from information leakage to actions taken in the user's name. For agents, then, a privacy promise is not a bonus. It is the precondition for users agreeing to delegate at all, which explains why three products are now bidding against each other on safety.
Between a promise and its delivery sits verifiability. A phrase such as "built for privacy" cannot be tested when no mechanism stands behind it. Serious privacy engineering tends to show up as practices that outsiders can check. User data is not used to train models by default, or at least a clear opt-out exists. Permissions are narrowed per task instead of granted all at once. Sensitive data is processed as close to the user as possible. An exportable access log tells the user what the agent read and did. Independent third parties audit security, and incidents are disclosed quickly and in full. This list is an evaluation framework. It is not a description of what Dots or Muse actually do. The fair test for both companies is whether they will write such mechanisms into product documentation, and not only into keynote lines.
The "each generation is safer than the last" story also carries a structural risk. When privacy becomes comparative advertising, the yardstick for safety is set by a rival's failures. A company looks trustworthy whenever the competitor stumbles, so the incentive drifts toward "do not be worse than the others" and away from "be truly good enough." If any one of the three suffers a serious breach, the damage will not stay with that company. It will fall on the credibility of the whole agent category, and users will think again about handing over their inboxes and file stores. Muse positioned itself as the safe successor to OpenClaw and is now criticized by the maker of Dots. That alone shows how quickly such a position can be flipped by the next entrant. The louder the promise, the more reason users have to demand evidence, and the more reason regulators have to ask questions.
For ordinary users and for businesses, the practical move is to turn the promise into questions that can be checked one by one. Is data used for training by default? Can it be deleted in one step? Can permissions be divided finely? Does an audit log exist? Who is responsible for notifying users after an incident? Until those questions have clear answers, it is sensible to confine agents to low-sensitivity tasks and widen their authority step by step. For the industry, a real new standard will not be born on a keynote stage. It will come from engineering and disclosure that outsiders can verify. Whether Dots sets the standard Altman described, and whether Muse's claim of being built from the ground up for privacy holds, only time and independent review can say. Until then, one point is worth keeping in mind: the more capable an agent becomes, the more trust it demands, and trust is built from evidence. It cannot be borrowed in advance from a slogan.
Sources
FAQ
What happened between OpenAI's Dots and Meta's Muse?
According to The Verge, OpenAI unveiled Dots at this year's DevDay. Sam Altman said the company wants to set a new standard for privacy in frontier AI, and OpenAI spent the day taking veiled shots at Meta's Muse for failing to keep user data safe. Muse had launched a couple of months earlier as a safer alternative to OpenClaw, with Mark Zuckerberg saying it was built from the ground up for privacy and security.
Why do agents raise more privacy risk than ordinary chatbots?
This is analysis, not a claim from the report. An agent acts for the user, so it usually needs access to email, calendars, files and accounts. The data surface is wider, and a leak costs more. That is why every maker now sells privacy.
How can a user judge whether a privacy promise is credible?
Look for checkable detail instead of slogans. Is data used for training by default? Can it be deleted? Can permissions be narrowed per task? Is there an independent audit and an exportable access log? A promise without a matching mechanism is marketing.