Sam Altman photo
Sam Altman’s OpenAI launches Dots as Meta’s Muse races up the App Store, with both AI agents raising fresh questions over access, privacy and security Steve Jurvetson/Wikimedia Commons

Meta's Muse AI agent shot to the top of Apple's US free iPhone app chart within 10 days of its 8 September launch, overtaking ChatGPT. Just weeks later, on 29 September, OpenAI unveiled its own always-on AI agent, 'Dots', designed to run continuously on dedicated cloud computers and plug into services such as Slack and Microsoft Teams.

Both companies are pushing new kinds of AI agents into workplaces and onto personal devices, with contrasting approaches to pricing, access and security. Meta lets people start with Muse for free, while OpenAI has put Dots behind some of its most expensive subscriptions.

Each system includes safeguards around permissions, credentials and the actions that agents can take. Both, however, face the same core security question: how much access should an AI agent have to private data and workplace systems when it is operating with limited human oversight?

Meta Uses Free Access To Get People on Board

Muse is available on a free tier, with paid options priced at $20 and $100 a month. That gives users a relatively low-cost route into agentic AI, and its position at the top of Apple's free App Store rankings suggests strong early consumer interest.

OpenAI has taken a different approach. A first Dot is included with ChatGPT Pro (Pro 100 at $100 a month, Pro 200 at $200 and Pro 500 at $500), Business Premium ($125 a seat monthly) and, once administrators switch it on, Enterprise.

It is not available on the free or Go plans. At launch, Pro access excludes the European Economic Area, Switzerland and the UK, while Business Premium is available in all supported regions.

OpenAI Claims Dots Can Act Like Digital Co-Workers

Each primary Dot operates on its own cloud computer with an isolated browser. Access to a user's laptop requires explicit permission.

Dots can also be brought directly into workplace conversations. A colleague can tag one in a Slack thread, for example, and continue work that started in ChatGPT without having to repeat the task. A project can also move into a mobile voice call.

OpenAI says Dots can connect to more than 4,000 plugins. That allows an agent to investigate issues reported in Slack, examine a codebase and submit a proposed fix through Codex Cloud.

They can also identify issues such as unbilled invoices or calendar conflicts and suggest actions for human approval. Their activity is recorded in an Activity View, where managers can pause or redirect tasks.

Meta Says Muse Is Separate From Your Computer

Meta's system runs inside a dedicated Ubuntu Linux virtual machine called the Muse Secure VM. A separate service, Sentinel, controls network access and connector actions. It can apply restrictions below standard OAuth permissions.

Credentials are kept in an external token store, while filters are designed to block sensitive material including one-time passcodes and password-reset links.

OpenAI uses a different set of controls. Dots rely on an encrypted credential service that enters saved passwords directly into login forms, meaning the model is not intended to see the credentials themselves.

Users can also create Custom Rules to permit, require approval for or block certain actions. An Auto-review system checks consequential tasks, while some actions, including password changes, always require human approval.

Unlinking an App Does Not Erase the Agent's Stored Data

The two systems also raise similar questions about what happens to information after an app is disconnected. Muse uses sanitised interaction logs for model training by default, although users can opt out. Disconnecting an application does not automatically remove information already stored in its long-term memory or interaction history.

OpenAI says Business, Enterprise and Edu content is excluded from training by default. Personal subscribers have separate training controls. However, disconnecting an application does not immediately clear information already ingested by a Dot. A full reset is needed to erase its memories, schedules and chat history.

Background Research Still Carries Security Risks

When a Dot is idle, its proactive research is restricted to read-only tools. Those tools cannot send messages, change documents or control browsers. That limits what an agent can do without approval, but it does not remove exposure to untrusted information.

Connected apps can still contain unredacted data, while emails, messages and web pages may include text designed to influence the agent through indirect prompt injection.

Clear-text passwords pasted into content can also remain visible to the system. Another agent system, Grok Bot, takes a different approach.

Bots created by one user share a single cloud computer, command-line credentials, browser sessions and file storage on Cursor's backend. Giving each Bot a different name therefore does not create a separate security boundary.