AI agent makers are promising privacy — will they deliver?
OpenAI and Meta are competing to win user trust by promising superior privacy protections for their new AI agents, Dots and Muse respectively. This matters because AI agents require users to share significant personal data, and with frequent cyberattacks and widespread data hoarding by tech companies, privacy assurances are crucial to driving adoption. However, the article raises critical questions about whether these privacy promises will actually be kept.
Meta's Muse launched with privacy guarantees but has already suffered multiple security failures, including a zero-day vulnerability, data collection defaults that users did not realise, and unauthorised access to private messages and contact information. The app nonetheless gained 600,000 daily active users in the US within weeks. OpenAI's Dots aims to differentiate itself by offering stronger user controls and stricter safeguards, with CEO Sam Altman emphasising the company's different approach to safety.
- Privacy promises from AI makers put to the test early
- Meta's Muse failed security and data protection within weeks
- OpenAI plans stronger safeguards than Meta for user privacy
New here? Start with this
AI agents are emerging tools developed by major technology companies that perform tasks on users' behalf. OpenAI and Meta have each launched versions—called Dots and Muse respectively—and both claim to offer superior privacy protections. These agents require access to extensive personal information, including calendar entries, contacts, location data, and private messages, to work effectively.
Privacy protections matter significantly for these tools because users must share highly sensitive information with the companies operating them. Technology companies have a documented track record of collecting and retaining user data, and cyberattacks regularly expose personal information. Users are therefore cautious about whether their information will be genuinely protected.
The story examines whether these privacy commitments will hold. Meta's Muse launched with similar privacy assurances but experienced multiple security failures early on, including unauthorised access to private messages and contact information. These problems raise questions about whether technology companies can reliably protect the sensitive personal data that AI agents require to function.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Tech companies have repeatedly made privacy promises whilst failing to keep them, with Meta being a prime example—Muse launched with explicit privacy guarantees yet suffered immediate security breaches and unrealised data collection defaults. The structural incentives of surveillance-based business models, which depend on extensive personal data harvesting, fundamentally conflict with genuine privacy protection, making these assurances marketing theatre rather than credible commitments.
The case against
Dismissing all corporate privacy commitments as inevitably broken ignores that market competition can drive genuine improvements, particularly when companies differentiate on privacy and face acute reputational consequences for failures. These new AI agents represent different architectural choices and oversight structures than past products; whilst scepticism about historical conduct is warranted, fair assessment requires evaluating whether these specific products and teams have genuinely implemented structural changes rather than assuming all corporate promises are hollow.