Opinions and Analysis

AI Agents Compete Over Privacy: Can Promises Withstand Actual Use?

OpenAI and Meta are competing to offer AI agents that promise better protection for users’ data, but Muse’s security issues and its data-collection behaviors reveal the gap between marketing and practice. These systems’ ability to access sensitive information, along with the limits of user control, remain decisive factors before users can trust them.

2026-10-10
4 min read
0 views
certi.news
AI Agents Compete Over Privacy: Can Promises Withstand Actual Use?

Companies developing AI agents are seeking to make privacy a central focus of competition at a time when these systems require broad access to users’ data and the ability to perform tasks on their behalf. But Meta’s experience with its Muse agent, followed by OpenAI’s introduction of the Dots agent as a safer alternative, shows that promises alone are not enough to demonstrate data protection.

From Muse to Dots

Meta introduced the Muse agent as a safer option than OpenClaw, saying that users’ data is stored inside a secure virtual machine, which the company described as an isolated Linux computer containing a browser, processor, memory, and storage. Meta also announced that it intends to later add a verifiable cryptographic mechanism preventing it from accessing the data inside the virtual machine.

But this isolation did not prevent Meta itself from accessing the data under the current configuration. A security researcher also uncovered a zero-day vulnerability that could have enabled control of Muse before it was fixed, while serious security issues were reported shortly before launch, including a vulnerability that could have allowed access to Meta’s internal databases.

Muse recorded rapid growth, reaching 600,000 daily active users in the United States within weeks, according to Apptopia, and topping app store rankings. However, its rapid spread did not dispel concerns about the agent’s behavior toward data.

What Raised Privacy Concerns?

By default, Muse allows the use of what users enter to train Meta’s models, while providing an opt-out option. Reports also said that the agent read and uploaded private messages, and provided a user’s address to a stranger through Marketplace. In other cases, the system created detailed profiles of users’ friends and family members. The problem here lies not only in the existence of a software defect, but also in the possibility that the system may carry out what it was designed to do in a way whose scope the user does not understand.

These cases show that protecting privacy in agents is not solely about technically isolating data, but also about the limits of permissions, the clarity of consent, and whether the user understands in advance what the agent can read or share.

OpenAI’s Promises and Dots’ Controls

OpenAI capitalized on these criticisms when it announced Dots in September. During DevDay, the company demonstrated individual control features, such as setting a rule that prevents the agent from making purchases above a specified amount. It also presented companies with a framework that includes stronger data controls and options for a no-data-retention policy, so that information is not stored on OpenAI’s servers.

OpenAI officials said the company is seeking to provide a reliable and secure assistant, and that the size of Meta’s user base makes errors of this kind more serious. But the absence of widespread privacy scandals linked to Dots so far should be viewed cautiously; the agent is available only through ChatGPT plans starting at $100, meaning its potential user base is smaller.

Why Does This News Matter?

AI agents need more data than traditional chat tools in order to perform tasks such as managing messages or purchases and handling accounts. Therefore, the true privacy standard should not be the company’s statement, but the user’s ability to know what the agent can access, restrict its actions, and prevent the company itself or external parties from using the data beyond its expected purpose.

Key questions remain open: Are consents clear enough? Do no-retention controls work as advertised? And what is the mechanism for independently verifying data isolation? The case of Instinct, which faced criticism because its terms of service granted it broad access to data before subsequent amendments were made, also shows that legal terms and the user experience are part of the security model, not a secondary detail.

The conclusion imposed by the comparison between Muse and Dots is that the AI-agent market is trying to build trust through three simultaneous promises: practical usefulness, a less alarming experience, and privacy protection. But trust will ultimately be determined by how measurable and verifiable these promises are, not by how often they are repeated in launch presentations.

News source
c
Author

certi.news

In the same category

You may also like

View all news