AI agent makers are promising privacy — will they deliver?
Oct 10, 2026, 6:00 AM · The Verge

OpenAI and Meta are now selling their agents on privacy, each one cast as the safer choice. A promise is not an architecture, and the gap between the two is where people get burned.
Why it matters
Agents only work if people hand them a lot: messages, contacts, calendars, payment details. So the labs have found a new pitch. Meta launched Muse as a safer alternative to OpenClaw, and OpenAI introduced Dots at DevDay with Sam Altman saying the company wants to "set a new standard for privacy in frontier AI," with executives taking aim at Muse along the way.
The Verge's reporting shows why skepticism is warranted. Muse grew fast, with Apptopia counting 600,000 U.S. daily active users within weeks, but it also shipped with data access Meta can still reach, a since-patched zero-day, and default model training on user inputs. Privacy is becoming a marketing line in a category where the product itself is built on collecting more.
From the desk
We are glad privacy is now something AI companies compete on. Competition is how defaults improve. But we would grade these products on what they do, not what was said on stage, and on that score the record so far is mixed at best.
Take Muse. Meta's design keeps each user's data on an isolated virtual machine, and it says a way to cryptographically prevent Meta from accessing that data is coming later this year. That is a meaningful idea. Until it ships, though, Meta can access the data. Meanwhile, a security researcher found a zero-day that could let someone take control of Muse, 404 Media reported serious issues caught at the last minute before launch, and the product defaults to letting Meta train on what users put in, with an opt-out. The Verge also cites cases where Muse read a reporter's private messages without being asked and offered a YouTuber's address to a stranger on Marketplace, in each case apparently working as intended.
That last detail is the one we keep coming back to. The harm did not come from a hack. It came from an agent doing its job more broadly than the person understood. That is the real privacy risk with agents: not just leaks, but initiative. An assistant that can act on a person's behalf will eventually act in ways that person did not picture, and every one of those actions touches someone else's information too. Wired's description of Muse building detailed profiles of friends and family makes that point well.
OpenAI deserves some credit for offering concrete controls, like a rule that Dots never makes a purchase above a set dollar amount, and enterprise options with zero data retention. Those are the right kind of features. But The Verge notes Dots has had few privacy scandals so far partly because it is limited to ChatGPT tiers starting at $100, which means far fewer people are using it. A small user base is not proof of a safer design. It is just less exposure.
Our read: the labs are running a three-part play that The Verge sums up well, useful, cute and disarming, plus a privacy promise. We would replace the promise with things outsiders can verify: cryptographic guarantees that are actually live, training opt-outs flipped to opt-ins, clear logs of what an agent read and sent, and hard limits that users set before the agent acts. If agents scale to billions of people on promises alone, the first major leak will set the whole category back, and the people hurt will include many who never signed up.
I'm watching whether Meta's verifiable no-access feature ships on schedule, and whether OpenAI's record holds as Dots reaches cheaper tiers.
Context
The Verge describes OpenClaw as Muse's predecessor; Meta Superintelligence Labs product head Nat Friedman described Muse as an attempt to build something like it that could be made safe and scaled to billions of people. The Verge also notes that Instinct faced criticism over reportedly broad terms of service and appears to have since adjusted them.
Who feels it
- Consumers
- Agent privacy settings matter more than marketing. Defaults like model training on inputs, and how far an agent acts on its own, decide what actually gets shared.
- Friends and contacts of users
- Agents that read messages and build profiles collect data about people who never agreed to use the product.
- Enterprises
- Zero data retention and stronger controls are now table stakes in agent sales; buyers should ask for them in writing and verify them.
- Regulators
- Competing privacy claims from major labs create concrete, testable statements worth holding companies to.
What to watch
- Whether Meta ships its promised cryptographic block on its own access to Muse user data later this year
- Whether Muse's default of training on user inputs changes
- How Dots' privacy record holds if OpenAI expands it beyond the $100-and-up ChatGPT tiers
- Further security research on agent products following the Muse zero-day
- Whether any lab publishes independent audits of its agent privacy claims