Personal AI agents are being sold as safer successors to earlier automation tools, but their usefulness depends on access to unusually sensitive information. Meta’s Muse and OpenAI’s Dots can act across messages, files, accounts and purchasing workflows, making privacy controls part of the product rather than an optional policy detail.

Meta says each Muse user’s data sits in an isolated virtual machine. That separation protects users from one another, but Meta can still access the information; a system designed to cryptographically block that access is only planned for later. Muse also defaults to allowing training on user inputs unless a person opts out.

Early incidents illustrate the gap between technical permission and user expectation. A patched vulnerability could have enabled account takeover, while users reported the agent reading private messages or exposing an address during a Marketplace interaction. In those cases, broad access was not necessarily a software malfunction, but people did not expect the agent to use their information that way.

OpenAI emphasizes user-set spending limits, enterprise controls and optional zero-data-retention policies for Dots. The product is newer and currently limited to expensive subscription tiers, so it has faced less testing at consumer scale. Neither a secure virtual machine nor a privacy promise answers every practical question. Users still need clear defaults, narrow permissions, audit histories and a reliable way to see what an agent accessed before giving it credentials or financial authority.