At this year’s OpenAI DevDay, CEO Sam Altman unveiled the company’s new AI agent, Dots, stating that the company aims to “set a new standard for privacy in frontier AI.” OpenAI used the event to take veiled shots at Meta’s Muse, its primary competitor, for failing to keep users’ data safe. Yet Muse itself had launched just months earlier with similar promises from Mark Zuckerberg, who claimed it was “built from the ground up for privacy and security.”

Meta’s Technical Approach and Failures

Meta Superintelligence Labs, through Nat Friedman, explained that Muse is built on a secure virtual machine (VM) — what Zuckerberg described as an “isolated Linux computer with a browser, CPU, memory, and storage.” Despite this design, reality proved more complex. Security researchers exposed a zero-day vulnerability that could allow someone to take control of Muse, while reports from 404 Media suggested flaws that could have granted access to Meta’s own internal databases.

Furthermore, Muse appears to collect data liberally. By default, it allows Meta to train models on user input unless the user opts out. Incidents have been reported where the agent uploaded private messages without being asked or shared a user's address with a stranger via Marketplace — functioning as intended, but in ways users did not anticipate.

OpenAI’s Counter-Strategy and the Cost of Trust

OpenAI is attempting to differentiate itself by offering Dots users more control, such as setting spending limits. For enterprise customers, the company presented a framework with zero data retention policy options. However, access to Dots remains limited, as it is only available on ChatGPT subscription tiers costing $100 and up, meaning its user base is smaller and less exposed to errors compared to Muse.

Despite the promises, skepticism remains. Many users feel uncomfortable sharing sensitive information, such as bank details, with AI agents that require vast amounts of personal data to function effectively. The industry's strategy currently relies on a three-part approach: making agents useful, making them "cute" to offset creepiness, and making privacy promises that have yet to be fully validated.