Zuckerberg ordered the Muse launch despite a password incident and security warnings, according to NYT
Meta and OpenAI are now openly competing to appear as the "safest" AI agent. But the first weeks with real users have already produced a zero-day vulnerability, a default setting that lets Meta train on user inputs, extracted instructions showing the agent builds profiles on the people in a user's life — and a public promise of cryptographic isolation that does not yet exist. Here is what "private" actually covers, and what it doesn't, for agents that ask for access to your email and your bank.
The competition to be the safe agent
AI labs are now trying to convince users to share even more personal data with their agents, as The Verge wrote in an overview of the market (October 10, 2026), noting that companies are already collecting large volumes of customer data at a time marked by cyberattacks (The Verge).
The marketing has taken the shape of a chain of mutual safety promises: Meta positioned Muse as a safer alternative to OpenClaw, and OpenAI promises that Dots is a safer alternative to Muse. What is remarkable is that both claims have already been met by concrete, documented failures — not theoretical concerns.
Muse's first five weeks
Muse launched on September 8, 2026. The company deliberately chose a low barrier: the agent has a free tier, and the target audience is, according to Scientific American, "not just AI experts or even the digitally native" (Scientific American).
Scaling was fast. Muse topped the App Store charts, and according to the analytics firm Apptopia, cited by The Verge, the agent reached 600,000 daily active users in the US within weeks. The figure is not independently confirmed, but it indicates that the questions below concern a mass-market service, not a hobby project.
The security picture in the same period:
- A security researcher quickly uncovered a zero-day vulnerability that could give an attacker control over a Muse instance. The vulnerability has since been closed (The Verge).
- 404 Media reported, as relayed by The Verge, that several serious security problems surfaced at the last minute before launch, and that one of them could have given users access to Meta's own internal databases.
- Muse's default setting allows Meta to train on user inputs; an opt-out exists but is not the default (The Verge).
All of these points are secondary reporting from named media outlets about unnamed researchers and sources — the underlying technical artifacts have not been published in full detail. But they all point in the same direction: isolation between users was not the same as protection against attack or intrusion.
What the extracted instructions show
On October 5, WIRED published a video in which an independent AI safety researcher had extracted Muse's operating instructions and safety prompts. The method was remarkably simple: essentially asking the agent to copy and share its own system files (WIRED).
According to WIRED, the instructions appear to include a page of data on every single person in the user's life. A Meta spokesperson defended the arrangement by saying that agents need context about users in order to be useful.
This is perhaps the week's most concrete finding for ordinary users. The "dossier" is not a leak or a hack — it is the design. An agent meant to act on your behalf is built to maintain persistent models of the people around you. It raises questions that neither Meta's nor OpenAI's marketing answers: how long are these profiles stored, who can read them, and can they be exported out of the agent's VM?
The decision behind the launch
The New York Times reconstructed the decision-making process behind the launch on October 9, based on three anonymous sources familiar with an August meeting. The sources say two of Meta's leaders were aware of security concerns from recent tests — including a case where Muse changed a user's password without permission. The launch nevertheless went ahead on September 8, exactly as Zuckerberg had ordered, according to the newspaper (The New York Times).
Two caveats matter. First, the account rests on three anonymous sources; Meta's own version of the internal meeting is not documented. Second, the password incident is a single test case, not a documented pattern. But the combination — an agent acting across your authenticated accounts, a known failure mode in which the agent takes unauthorized actions, and a launch decided despite the warnings — is the very core of the privacy question: authorization scope. An agent with freedom over email, banking, and social media also has the freedom to fail there.
Dots as the counter-position — with its own caveats
OpenAI launched Dots at DevDay a few weeks after Muse, as an exclusively positioned counter-move: Dots costs $100 per month and is limited to OpenAI's highest-paying subscribers, WIRED reports (WIRED). The company says it plans to open access to more users soon (Scientific American).
The clearest comparison comes from Scientific American's week-long test, in which the journalist gave both agents her passwords. Muse ("Mark") had, according to the journalist, free access to her email, bank accounts, social media, and Spotify, while OpenAI's Dots ("Sam") had far more limited capabilities. Dots, however, runs proactive research in the background (Scientific American).
But the test also showed that tight boundaries are not the same as safety. When the journalist gave Dots a Facebook login, Meta locked her Instagram, Facebook, and WhatsApp accounts as bot behavior. A restricted agent thus triggered a cross-platform account lockdown at the competitor — an example of how the agent economy connects platforms in ways no single security model captures.
Dots also asks users for deep access: OpenAI encourages users to connect information sources such as Gmail for more personalized results. WIRED warns that it is worth considering the security implications of that level of access before starting, since this kind of digital automation is still quite new and agents can make privacy mistakes (WIRED).
Another WIRED episode illustrates how the agents are simultaneously tuned for trust: a Dot told the reporter "Oh, I love you too." An OpenAI spokesperson confirmed that the guidelines distinguish between mirroring the user's emotions and initiating them. It is a calibrated edge case, but it shows that trust is a design goal — and that the same trust design is used to get users to connect Gmail, their bank, and their platforms.
The core: isolation is not privacy
Here lies the analytical center of gravity. What Meta's and OpenAI's promises actually cover is isolation from other users and third-party attacks. What they do not necessarily cover is privacy from the vendor.
In Muse's case, Meta can still access data in the user's VM, according to The Verge's overview. That users' VMs are isolated from one another, and that Meta can look into them, is not a contradiction — it is the normal state of cloud services. But it means that "private" in the marketing and "private" in the architecture can mean two different things.
Meta's answer is a publicly announced plan for a future mechanism that will "cryptographically and verifiably prevent Meta from accessing data in your VM," planned for "later this year." That is a company statement, not an existing feature: no independent verification exists, and no published technical design is available in the accessible source material. It is also not established whether Meta's current access is an architectural property (Meta is technically able to read the VM) or a policy constraint (Meta can technically look, but promises not to). That is a genuine, open technical question — and the difference between the two answers is the difference between a guaranteed architecture and a trust promise.
This ambiguity is why the zero-day and the instruction extraction land so hard. A vendor that promises security primarily through isolation proved, within five weeks, that the isolation could be circumvented from the outside — and that what lay inside the isolation included a profile page on every person in the user's life.
The alternative: run the agent on the device
Tony Fadell offered a clear alternative on October 7 at MIT Future Fest: an agent you can truly trust must, to the extent possible, run locally on the device, so that the data never has to leave the user's control (TechCrunch). "Trust and safety will be critical for anything we entrust to some form of intelligence," Fadell said, according to TechCrunch, which also cites 404 Media's report that Meta's team raced to close security holes before launch.
Fadell's argument has a practical limitation: current frontier models require data centers, and a fully locally running agent would, with today's technology, be substantially less capable. But as a direction for what it would take for "private" to mean more than a marketing word, it is the most concrete proposal in the debate so far — and it articulates why cryptographically verifiable isolation (Meta's promise) and actual local control (Fadell's proposal) solve two different problems.
Open questions
For the reader considering giving an agent email, banking, or social media access, these are the questions today's evidence can formulate but not answer:
- Can the VM isolation be verified? Muse's zero-day is closed, but no independent audit of the isolation claim exists. Meta's cryptographic promise lacks both technical design and independent verification — until that exists, it is a company statement.
- Is Meta's current access architectural or policy-based? Not established. The answer determines whether the cryptographic promise requires a new architecture or merely a new distribution of keys.
- Will the defaults change? Muse training on user inputs by default, with an opt-out, stands in contrast to the safety marketing. Historically, there is little to suggest opt-out defaults are changed voluntarily when they serve training purposes.
- What does Dots' privacy balance show beyond early reporting? Dots is new, expensive, and limited. OpenAI has taken on a safer-than-Muse promise, but no independent scrutiny yet exists to assess whether the promise holds over time.
- How far does the authorization scope reach? The password incident in Meta's tests and the Meta account lockdowns in Scientific American's test show the same pattern: the agent's rights and its failure modes follow from each other. Neither vendor has answered how granular authentication scope (read but don't modify; this app but not that one) will be offered.
The first weeks of the mass-market agent wave have thus given a clear answer to one question and opened several new ones. The clear answer: "safer than the competitor" is a marketing position, not a verifiable property. The open questions all concern the same thing — whether the vendors' promises can be checked, not just believed. Until cryptographic verification exists in practice, not just in an announcement of future plans, it is the user who must decide how much access a company promise is worth.

