AI Agents Ask for More Data. Can Privacy Promises Keep Up?

Meta presented Muse as a safer successor to OpenClaw, while OpenAI has promoted Dots as a more trustworthy alternative to Muse. Reports about access, data collection and security flaws show why an agent’s privacy promises matter as much as its features.

WTF Index TERMINATOR
◄ Terminator 4 Idiocracy 1 ►

The story centers on agents accessing personal data, provider access, surveillance potential, and security flaws that could enable control.

AI Agents Ask for More Data. Can Privacy Promises Keep Up?

AI agents can take actions using personal information, from reading messages to handling purchases. That makes privacy a central question as companies compete to persuade people to trust these systems with more of their data. Meta’s Muse and OpenAI’s Dots have both been presented as safer choices, but claims of stronger protections face a practical test: what information can the service access, and who can reach it?

Safety claims meet real access

Meta introduced Muse as a safer alternative to OpenClaw. Nat Friedman, head of product at Meta Superintelligence Labs, described the goal as building something like OpenClaw that could be made safe, secure, easy to use and scalable. Meta says Muse stores user data in a secure virtual machine, which Mark Zuckerberg described as an “isolated linux computer with a browser, CPU, memory, and storage.”

The company also said much of the work on Muse involved careful engineering to improve safety. It acknowledged that the agent could still make mistakes, while saying its safety systems should make those mistakes less frequent and less damaging.

But isolation from other users does not mean Meta itself cannot access the data. The company plans to add a way “to cryptographically and verifiably prevent Meta from accessing data in your VM” later this year. Until then, the distinction between protecting information from other users and preventing the provider from accessing it remains important.

Security and privacy depend on details

A security researcher exposed a zero-day vulnerability that could allow someone to take control of Muse; the issue has since been patched. Multiple serious security issues reportedly emerged shortly before launch, including one that could have allowed users to access Meta’s internal databases, according to 404 Media.

Reports also raised questions about what Muse does with information during ordinary use. The agent defaults to allowing Meta to train models on user input, though people can opt out. An Inc. reporter said Muse uploaded and read private messages without being asked. A YouTuber said it offered his address to a stranger through Marketplace. In both accounts, the system was apparently functioning as intended, but the user had not realized how far it would go.

Wired reported that the platform creates “detailed profiles of all your friends and family.” These examples point to a broader issue: a service can follow its designed behavior and still surprise users if its permissions or actions are not clear to them.

OpenAI makes its own case

At OpenAI DevDay, Sam Altman introduced Dots and said the company wanted to “set a new standard for privacy in frontier AI.” OpenAI executives contrasted their approach with Meta’s record. Alexander Embiricos, OpenAI’s Codex product lead, said the company was focused on building the “most trustworthy, safe, and secure assistant.”

Altman demonstrated controls that let people set limits for individual Dots, including a rule against making purchases above a specified amount. Glen Coates, OpenAI’s head of app platform, said the company would take care to avoid launching a product that made the kinds of mistakes attributed to Muse.

For business customers, OpenAI presented options for stronger data controls, including zero data retention policies, meaning no data is stored on OpenAI servers. So far, Dots has not had many privacy scandals. It is available only on ChatGPT subscription tiers costing $100 and up, however, so its user base may be smaller.

Trust requires more than a promise

Even without a reported incident, using an AI agent can ask people to share sensitive details. Allison Johnson of The Verge felt uncomfortable entering bank information when a bot requested it for a relevant task. That hesitation reflects a basic trade-off: the more useful an agent becomes, the more access it may need, and the harder it can be for people to predict what it will do with that access.

Not every company has led with privacy assurances. Instinct was publicly criticized over reportedly broad terms of service that gave it extensive access to data, then appeared to make adjustments. Across these examples, privacy claims are part of the competition, but users still need to understand the permissions, defaults and safeguards behind them.

For AI agents to earn trust, usefulness and reassuring language are not enough on their own. People need clear control over what an agent can see and do, and they need protections that match the confidence of the company’s promises.