OpenAI pitches Dots on privacy after Meta's Muse security issues

OpenAI pitches Dots on privacy after Meta's Muse security issues

At this year's OpenAI DevDay, CEO Sam Altman unveiled Dots, the company's new AI agent, and said OpenAI wants to "set a new standard for privacy in frontier AI." OpenAI spent the day taking veiled shots at Meta's Muse, which the article calls its primary competitor, for failing to keep users' data safe. The Verge points out the irony: a couple of months earlier Muse had launched as a supposedly safer alternative to its predecessor OpenClaw, with CEO Mark Zuckerberg promising it was "built from the ground up for privacy and security."

Meta's pitch was detailed. Nat Friedman, head of product at Meta Superintelligence Labs, wrote on X that the "goal with muse was to build something like openclaw that we could make safe and secure and easy to use and scale to billions of people." User data sits on a secure VM, which Zuckerberg described as an "isolated linux computer with a browser, CPU, memory, and storage." Meta said most of the effort in building Muse went into "careful design and engineering to operate [it] more safely," and its blog post added: "Muse can and will still make mistakes, but we expect they'll be much less frequent and cause much less damage due to the safety systems we've built in."

The article argues the promises fell short. Muse topped the App Store charts and, per Apptopia, gained 600,000 daily active users in the US within weeks. Data is isolated from other users, and Meta plans to introduce a way "to cryptographically and verifiably prevent Meta from accessing data in your VM" later this year, but for now Meta itself can still access it. A security researcher quickly exposed a zero-day vulnerability that could allow someone to take control of Muse; it has since been patched. Multiple serious security issues reportedly cropped up at the last minute before launch, one of which could have let users reach Meta's internal databases, per 404 Media.

Muse also appears to collect, and sometimes hand out, a lot of data. By default it lets Meta train models on what users put into it, though users can opt out. An Inc. reporter complained that Muse uploaded and read his private messages without being asked, and a YouTuber said it had offered his address to a stranger via Marketplace. In both cases Muse was apparently working as intended, but the user did not realize how far it would go. Wired reported that the platform creates "detailed profiles of all your friends and family." The article says none of this is necessarily unexpected from Meta, but it does not back up the idea that Muse is uniquely privacy- or security-conscious.

OpenAI seized on that when announcing Dots in late September. Alexander Embiricos, OpenAI's Codex product lead, said onstage that OpenAI is focused on having the "most trustworthy, safe, and secure assistant," and Altman demonstrated user controls over individual Dots, such as a rule that it should never make a purchase over a certain dollar amount. Glen Coates, OpenAI's head of app platform, said: "I think we're in a different position to Meta in that they don't have an AI product that has 1.2 billion users," and added that "launching something that makes those kinds of mistakes is something that we would try to take the care to avoid."

For business customers, executives presented a framework giving enterprises "stronger controls" over their data, plus zero data retention policy options, meaning no data is stored on OpenAI servers. So far there have not been many privacy scandals with Dots, but the article notes it is only available on the $100-and-up ChatGPT subscription tiers, so likely far fewer people use it.

The piece closes on a wider worry. Agents need a lot of personal data to work; The Verge's Allison Johnson felt uncomfortable typing in her bank information when the bot asked for it as part of a task (Muse has a Stripe integration for payments). Not every company is making privacy promises: Instinct was publicly criticized for reportedly overly-broad terms of service that gave it unfettered access to data, and has since seemingly made adjustments. The article sums up the labs' playbook as three parts: make agents useful, make them cute and disarming to offset the creepiness, and promise privacy, then hope the promises hold up.

Key facts

  • OpenAI unveiled the Dots agent at DevDay and pitched it as a way to "set a new standard for privacy in frontier AI," with executives implicitly contrasting it with Meta's Muse.
  • Meta made a similar promise for Muse a couple of months earlier, yet Muse has had a patched zero-day vulnerability, reported last-minute security issues, and broad data collection with training on user input by default.
  • Meta can still access data in a user's Muse VM; a cryptographic way to prevent that is only planned for later this year.
  • Dots has had few privacy scandals so far, but it is available only on the $100-and-up ChatGPT tiers, so likely fewer people use it.
  • The article describes the labs' approach as three parts: make agents useful, make them cute and disarming, and make privacy promises.

Why it matters

Privacy has become the selling point in the race to get ordinary people to hand personal data to AI agents. OpenAI is positioning Dots against Meta's Muse, which was itself launched as a safer alternative to OpenClaw. The article's point is that each lab promises to be safer than the last, so a promise on a stage tells you little until it survives real use. Muse is the early test case: Meta's "built from the ground up for privacy and security" line met a zero-day, reported pre-launch security issues and complaints about data handling within weeks.

Who it affects

Anyone considering giving an agent access to messages, addresses or payment details, since agents need a lot of personal data to do their work. The article cites The Verge's Allison Johnson, who felt uncomfortable typing in her bank information when an agent asked for it. Muse users are directly exposed to the issues described, such as default training on their input. Enterprises are the other audience: OpenAI presented "stronger controls" and zero data retention options to court business customers. Meta and OpenAI are both affected competitively, as OpenAI uses Meta's trouble as a contrast.

How to use it

The article is analysis, not a how-to, but it names the controls on offer. For Dots, Altman showed rules a user can set, for example that the agent should never make a purchase over a certain dollar amount. Dots is available only on the $100-and-up ChatGPT subscription tiers. Enterprises can use OpenAI's framework with zero data retention options, meaning no data is stored on OpenAI servers. For Muse, training on user input is on by default and users can opt out. Muse has a Stripe integration to handle payment information.

How solid is it

This is a Verge analysis piece that leans on company statements and third-party reporting rather than its own testing. The Muse security claims are attributed: the zero-day is stated by the article and said to be patched, the pre-launch issues are described as "reportedly" and credited to 404 Media, the private-message and address incidents come from an Inc. reporter and a YouTuber, and the profiling claim from Wired. OpenAI's claims about Dots are promises made onstage, and the article does not verify them. It also says the absence of many Dots scandals is partly explained by low usage. The article gives no number of Dots users, and the technical details of the zero-day and of the 404 Media internal-database issue are not given.

Risks and caveats

Meta itself can still access data in Muse, and the planned cryptographic protection is a later-this-year intention, not a shipped feature. The article stresses that in the Muse data cases the product was apparently functioning as intended, so the risk comes from how far an agent goes, not only from bugs. For Dots, a clean record so far is weak evidence given its narrow, expensive availability. The article also does not say which of OpenAI's stated privacy promises, if any, it has failed to keep. Privacy promises are also not universal: Instinct was criticized over reportedly overly-broad terms of service that gave it unfettered access to data.

“built from the ground up for privacy and security.”

— Mark Zuckerberg, on Meta's Muse agent, as quoted by The Verge