KI-Agenten

AI agents promise privacy but struggle to deliver on security

Meta and OpenAI market their new AI agents as secure alternatives to predecessors, yet early incidents reveal persistent data risks and user trust gaps.

A glass box with digital files and a padlock, symbolizing AI data privacy concerns.
Für diesen Artikel generierte Illustration

Dieser Artikel ist nur auf Englisch verfügbar.

At OpenAI DevDay in late September 2026, CEO Sam Altman introduced Dots, positioning it as a privacy-focused successor to Meta’s Muse. This launch continues a cycle where major tech firms claim their latest AI agents are safer than the competition, even as previous releases face significant security scrutiny.

What happened

Meta launched its Muse agent a few months prior to OpenAI’s announcement, marketing it as a secure upgrade from its predecessor, OpenClaw. CEO Mark Zuckerberg stated that Muse was built from the ground up for privacy and security, aiming to scale safely to billions of users. The company emphasized that most engineering effort went into safe operation, acknowledging that mistakes might still occur but would be less frequent and damaging due to built-in safety systems.

Despite these assurances, Muse faced immediate challenges. A security researcher discovered a zero-day vulnerability that could allow external control of the agent, though this was patched quickly. Reports from 404 Media indicated that multiple serious security issues emerged just before launch, including one that potentially allowed users to access Meta’s internal databases. Additionally, while Meta plans to introduce cryptographic verification later in the year to prevent its own access to user data, the company currently retains the ability to view information stored in the isolated virtual machines.

OpenAI leveraged these shortcomings during its DevDay presentation. Executives criticized Meta’s handling of user data while highlighting Dots’ features, such as enterprise controls and zero data retention options. Glen Coates, OpenAI’s head of app platform, noted that Meta’s large existing user base makes avoiding mistakes more difficult, implying that OpenAI’s approach allows for greater care in deployment. However, Dots is currently limited to higher-tier ChatGPT subscriptions, which may limit its exposure to widespread privacy incidents compared to Muse’s rapid adoption.

How it works

Muse stores user data in what Meta describes as an isolated Linux computer with its own browser, CPU, memory, and storage. This virtual machine (VM) architecture is designed to keep individual user data separate from others. The goal is to create a sandboxed environment where the agent can operate without exposing data to the broader network or other users. However, isolation from other users does not equate to isolation from the provider, as Meta can still access the data within these VMs until planned cryptographic updates are released.

Dots, by contrast, offers enterprises stronger controls over data handling, including options for zero data retention. This means that for certain business use cases, no data is stored on OpenAI servers after processing. Users can also set specific rules for their agents, such as limiting purchase amounts, to maintain control over autonomous actions. These mechanisms aim to reduce the risk of unintended data exposure or unauthorized financial transactions.

Key details

  • Muse gained 600,000 daily active users in the US within weeks of launch, according to Apptopia.
  • A zero-day vulnerability in Muse allowed potential external control but has since been patched.
  • Muse defaults to allowing Meta to train models on user data, though users can opt out.
  • Incidents included Muse reading private messages without explicit requests and sharing a user’s address via Marketplace.
  • Dots is available only on ChatGPT subscription tiers costing $100 or more per month.
  • OpenAI offers zero data retention policies for enterprise customers using Dots.

Why it matters

For developers and technical leaders, these incidents highlight the gap between marketing claims and technical reality in AI agent deployment. The promise of isolated environments like VMs provides a layer of security, but it does not eliminate risks from provider access or software vulnerabilities. Teams building products with AI agents must scrutinize how data is stored, who can access it, and what default permissions are granted. Relying on vendor assurances without independent verification can lead to unexpected data leaks or compliance violations.

The competitive dynamic between Meta and OpenAI also affects product strategy. As companies race to add privacy features, the focus often shifts to differentiating from competitors rather than solving fundamental trust issues. Users remain hesitant to share sensitive information, such as bank details, with agents that have demonstrated unpredictable behavior. This hesitation slows adoption and forces engineers to design more robust consent and control mechanisms into their applications.

What you can do

  • Audit the default data retention and training policies of any AI agent platform you integrate.
  • Implement strict user consent flows for accessing sensitive data like messages or financial info.
  • Test for edge cases where agents might share personal data unintentionally, such as address leakage.
  • Prefer platforms that offer verifiable isolation or zero data retention options for critical tasks.
  • Monitor security advisories for zero-day vulnerabilities in agent frameworks and patch promptly.
  • Educate users on the limits of agent privacy and provide clear opt-out mechanisms for data usage.

Tools aus dem Bytechap-Shop

Weiterlesen

KI-Agenten

Einen lokalen Sprach-Agenten in Rust mit Voxlocal erstellen

Voxlocal ist ein minimalistischer, quelloffener Sprach-Agent, der in Rust geschrieben wurde und lokal auf macOS läuft. Er demonstriert, wie man Spracherkennung, Vektorsuche und kleine Sprachmodelle für niedrige Latenzzeiten verkettet.

Alle Artikel