Skip to content
Predictive Systems
PSI Daily

Two AI Agents Promise Privacy, but It Has Yet to Be Proven

Privacy

OpenAI and Meta each say their AI agent is the safe one. Here is why a privacy promise is only worth what outsiders can verify, and what to ask first.

Two friendly AI characters, a yellow triangle with glasses and a fuzzy cream plush, each holding up a gold padlock in front of dark doors with glowing keyholes.

Before you hand an AI agent the keys to your inbox, remember this: a privacy promise is only worth what outsiders can check. That is the lesson of a new Verge analysis comparing OpenAI's Dots with Meta's Muse, two agents that each claim to be safest.

When Meta launched Muse in September, Mark Zuckerberg said it was "built from the ground up for privacy and security." Meta says each user's data sits in its own isolated cloud computer. But The Verge notes that Meta itself can still reach that data, and a lock that would keep Meta out is only promised for later this year.

Promises Meet Reality

Within two weeks, security researcher Patrick Wardle found a zero day flaw in the Muse Mac app that could let malicious software on a computer take control of the agent. Meta patched it in about a day, but published no formal advisory or fixed version number, so users had little to verify. Muse also lets Meta train on what people type by default unless they opt out. As we have reported, it can keep files on friends who never signed up and once offered a user's home address to a stranger.

OpenAI saw an opening. Unveiling Dots at DevDay on September 29, Sam Altman said the company wants to "set a new standard for privacy in frontier AI." OpenAI says Dots ask permission before sensitive actions, follow rules you set, and let business customers avoid having their content stored. Those are claims too, and Dots, sold only on pricier plans, has far fewer users testing them.

Ask Before You Connect

Before connecting any agent, ask three questions. Who can read what it sees, including the company itself? Can you delete your data and confirm it is gone? And has anyone independent audited the system, or are you simply taking the company's word? If the answers are vague, keep your most private accounts disconnected.

Sources

  1. The Verge, AI agent makers are promising privacy. Will they deliver?, October 10, 2026
  2. OpenAI Help Center, Dots privacy, security, and safety FAQs, accessed October 11, 2026
  3. CNBC, OpenAI DevDay 2026: Live updates and announcements, September 29, 2026
  4. Ars Technica, Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day, September 2026
  5. VentureBeat, Meta patched Muse's zero-day, but security teams still lack visibility into what the agent can access, September 22, 2026
  6. Predictive Systems, Your Friends Never Agreed to Be in Your AI's Files, October 8, 2026
  7. Predictive Systems, Meta's Muse AI Agent Shared a User's Home Address With a Facebook Marketplace Buyer, September 30, 2026