AI agent privacy has become the new battleground for the companies building personal assistants. At OpenAI’s DevDay on 29 September 2026, Sam Altman unveiled the company’s Dots agent and told the crowd OpenAI wanted to “set a new standard for privacy in frontier AI”. A few weeks earlier, Mark Zuckerberg had launched Meta’s Muse with the promise that it was “built from the ground up for privacy and security”. Each pitch was aimed at a rival, and each rested on the same claim: trust us with more of your life than you have ever handed to software, because we will keep it safe.
The Verge’s senior AI reporter Hayden Field asked the obvious question in an analysis published on 10 October: will they deliver? Her answer, in short, is that the AI agent privacy promises have so far outrun the evidence. Muse has been through a zero-day, a leaked home address, a disputed report of messages read without permission and a reported pre-launch scramble to fix virtual machine escapes. Dots has had fewer scandals, but it also has far fewer users, because it sits behind a $100-a-month subscription.
We read The Verge’s piece and then went to the primary sources: Meta’s own security write-up for Muse, OpenAI’s Dots privacy FAQ and its zero data retention announcement, Instinct’s current terms of service, the reporting from 404 Media, WIRED, TechCrunch and Inc., and the UK Information Commissioner’s Office report published on 8 October. This article sets out what each company has promised on AI agent privacy, what its own documents actually commit to, where the gaps are, and what businesses in the UK should do before letting an agent near their data.
Table of contents
- What The Verge Found: AI Agent Privacy Is the New Sales Pitch
- Meta’s Muse: The AI Agent Privacy Promise vs the Record
- OpenAI’s Dots: A Different AI Agent Privacy Pitch
- Instinct and the Terms of Service Test for AI Agent Privacy
- AI Agent Privacy Controls Compared: Muse vs Dots vs Instinct
- Why AI Agent Privacy Is Harder Than Chatbot Privacy
- The UK Angle: The ICO Puts AI Agent Privacy on Notice
- Can AI Agent Privacy Promises Be Verified?
- What AI Agent Privacy Means for UK Businesses
- AI Agent Privacy FAQ
- References
What The Verge Found: AI Agent Privacy Is the New Sales Pitch
Field’s argument is that privacy has turned into a competitive weapon. “AI labs are trying to convince users to share even more information with their agents,” she writes, and “their latest strategy for success is one-upping the competition by promising that unlike their rivals, they’ll keep user data away from prying eyes.” The question is whether the companies can keep those AI agent privacy promises once millions of people are using the products.
Each launch promises to be the safe one
The chain of one-upmanship is short and recent. Meta positioned Muse as a safer alternative to OpenClaw, the open-source personal agent that made the category popular. OpenAI then positioned Dots as a safer alternative to Muse.
Nat Friedman, head of product at Meta Superintelligence Labs, wrote that Meta’s “goal with muse was to build something like openclaw that we could make safe and secure and easy to use and scale to billions of people”. At DevDay, OpenAI spent the day, as Field puts it, “taking veiled shots at Meta’s Muse” for failing to keep users’ data safe. In each case, AI agent privacy was framed as the rival’s weakness rather than as a problem the whole industry shares.
Agents need far more data than chatbots
The reason AI agent privacy matters more than chatbot privacy is simple. A chatbot sees what you type into it. Personal AI agents are different: an agent is useful only when it can read your inbox, check your calendar, log in to your accounts, browse on your behalf and pay for things.
Meta’s own engineers describe Muse as the first time they had “handed our inboxes, our calendars, and a shell to a piece of software and let it run unattended”. Every connector widens the circle of data the provider holds, and every action widens the circle of people who can see the results. That is the core AI agent privacy trade-off: the more an agent can do, the more it has to know. Regulators call this shift agentic AI, and it changes what privacy has to cover.
The three-part playbook
Field closes with a neat summary of the strategy. For now, she writes, AI labs seem to be counting on a three-part approach to winning over the public: make agents useful, make them “cute and disarming to help offset the creepiness”, and “make promises about privacy, and hope they hold up”. The rest of this article tests the third leg of that stool, because AI agent privacy is the part that is hardest for users to check for themselves.
| Date (2026) | Event |
|---|---|
| 24 Aug | TechCrunch reports testers’ privacy and security concerns about Instinct’s terms of service |
| 26 Aug | Instinct’s terms of service are revised |
| 27 Aug | Meta’s infrastructure teams begin a security hardening push for Muse, per 404 Media |
| 8 Sep | Meta launches Muse and publishes “How We Built Safety Into Muse” |
| 19 Sep | Inc. columnist Jason Aten reports that Muse read his private messages |
| 22 Sep | Meta patches a Muse macOS zero-day found by Patrick Wardle |
| 29 Sep | YouTuber Matt Robb says Muse gave his address to a Marketplace buyer; OpenAI launches Dots at DevDay |
| 30 Sep | Meta publicly disputes Aten’s account |
| 3 Oct | WIRED reports Muse builds detailed relationship profiles of users’ contacts |
| 5 Oct | 404 Media reports pre-launch virtual machine escape bugs in Muse |
| 8 Oct | UK ICO publishes its foundation model report and opens a call for evidence on agentic AI |
| 10 Oct | The Verge asks whether AI agent makers will deliver on privacy |
Meta's Muse: The AI Agent Privacy Promise vs the Record
Muse is the biggest test of AI agent privacy so far, simply because of its reach. According to estimates from Apptopia reported by TechCrunch on 21 September, Muse had 642,000 daily active users on mobile in the US twelve days after launch, against 231,000 for ChatGPT at the same point after its own debut. Apptopia also found that more than 95% of Muse users were Facebook users. That scale is what makes every AI agent privacy claim matter.
What Meta promised
Meta’s technical account, “How We Built Safety Into Muse”, published on launch day, is detailed and in places impressive. Each user gets a dedicated virtual machine, which Meta calls “an isolated linux box”, and the post describes it as “the system of record for everything you put in Muse”. Inside it, the agent runs in a restricted container, while credentials and safety systems sit outside it. A separate component called Sentinel is “the sole permission authority” for connector actions and network traffic, and the agent never sees real passwords or tokens, only “surrogate” tokens swapped for real ones at the network edge.
The design choices are sensible AI agent privacy engineering. The email connector filters out one-time passcodes, password reset links and login magic links. Payments go through Stripe Link with a single-use card number tied to one merchant and one amount, with a human approval every time. OAuth tokens are “stored in your VM, not in centralized Meta infrastructure”. Meta also opened a public bug bounty paying up to $300,000, including up to $130,000 for a prompt injection that affects one user.
What Meta’s own documents admit
The same post is also candid about the limits of its AI agent privacy model, and this is where The Verge’s scepticism lands. Meta writes that the architecture “restricts access to your data by Meta personnel through operational policies”, but “does not prevent Meta from accessing data when necessary to support, secure or operate the service”. In other words, the isolation protects users from each other, not from Meta. For AI agent privacy, that is the distinction that matters most.
Meta says a stronger version, Muse Confidential VM, is “intended to cryptographically and verifiably prevent Meta from accessing data in your VM”, and plans to deliver it “later this year”. It is being tested with “a small group of trusted testers” and its source code is being shown to external auditors. Until it ships, the strongest AI agent privacy guarantee on offer is a policy promise, not a technical one.
Training is the other admission. Muse’s conversations, tool calls and agent hand-offs are, in Meta’s words, “useful data for training new checkpoints”, and the default is to use them after removing “key personally identifiable information”. Users can opt out “via a simple switch in Muse settings”. Meta also says it does not share Muse conversations with its ad systems, but concedes that because Muse’s browsing “will appear as your activity”, it can still influence the ads you see on Instagram and Facebook. Opt-out defaults are a weak form of AI agent privacy, because most people never change a setting.
The incident record
Within four weeks of launch, five separate reports tested Meta’s AI agent privacy and security claims. Some are contested and some involved user permissions, but together they explain why The Verge concludes that Meta’s promises “seem to have fallen short”.
- Messages read (19 September). Inc. columnist Jason Aten wrote that Muse read his private messages without being asked. Meta’s vice president of communications, Andy Stone, replied that the Mac Messages integration is “entirely opt-in” and needs Full Disk Access plus the Messages connector. Aten says Full Disk Access was off.
- A zero-day (22 September). Security researcher Patrick Wardle found a flaw in the Muse macOS app that let local code take over the agent. Meta hotfixed it and said the practical risk was “quite low” because an attacker needed code already running on the Mac. We covered it in our report on the Muse security flaw.
- A leaked address (29 September). YouTuber Matt Robb said Muse gave his home address to a Facebook Marketplace buyer, after he chose “Allow Always” on a permission prompt. Our write-up of the Muse address leak explains the permission flow.
- Relationship profiles (3 October). WIRED reported that Muse’s instructions tell it to record where contacts live, “dates that matter” and “how close they are”.
- Virtual machine escapes (5 October). 404 Media reported that Meta engineers found several escape bugs before launch, at least one of which could have reached Meta’s internal databases.
The insider warning
The 404 Media report is the most serious for Meta’s AI agent privacy story, because it comes from inside. An internal post by three senior infrastructure leaders, dated 18 September, described “a sudden spike in reported KVM escapes” and a hardening push that began on 27 August, shortly before launch. A Meta source told 404 Media that “half-baked protections” were “rushed out to enable the launch”, and that “many senior engineers believe it’s inevitable we’re going to have a massive data breach”.
Wardle’s verdict on the design was blunt: “having access to production environment literally one KVM escape away, is plain irresponsible.” Meta’s statement said it was “proud of the work we’ve done to make it safe, secure and private”. The bugs were fixed before launch, and there is no public evidence that user data was exposed. But the account undercuts the idea that the isolation layer at the centre of Meta’s privacy pitch was mature on day one.
| Meta’s claim | What the documents or reporting show |
|---|---|
| “Built from the ground up for privacy and security” | Five public incidents or reports in the first 27 days |
| Each user’s data is isolated in a dedicated VM | Isolated from other users, but Meta can still access it to support, secure or operate the service |
| Meta will be cryptographically locked out | Confidential VM promised “later this year”; not yet launched |
| Human approval where consent matters | An “Allow Always” grant let the agent share an address without further checks |
| Data not shared with ad systems | Agent browsing can still shape the ads you see |
| Training uses sanitised data | On by default, with an opt-out switch |
OpenAI's Dots: A Different AI Agent Privacy Pitch
OpenAI has pitched Dots less as a friendly helper and more as a careful professional. At DevDay, Codex product lead Alexander Embiricos said OpenAI was focused on having the “most trustworthy, safe, and secure assistant”, powered by what the company calls its “most aligned model”, GPT-6 Astra. Altman demonstrated controls such as a rule that a Dot must never make a purchase over a set dollar amount. Its AI agent privacy pitch is built on caution rather than reach.
Fewer scandals, fewer users
Glen Coates, OpenAI’s head of app platform, drew the contrast with Meta directly. “I think we’re in a different position to Meta in that they don’t have an AI product that has 1.2 billion users,” he told The Verge, and “launching something that makes those kinds of mistakes is something that we would try to take the care to avoid.” He added a sharper line: “if people have Dots that go out there and YOLO-buy stuff on Facebook Marketplace, that’s just not something we want to put 1.2 billion users through.”
Field notes the catch. So far there have not been many AI agent privacy scandals involving Dots, but Dots is only available on ChatGPT tiers costing $100 a month and up, so far fewer people are using it. A clean record built on a small, paying audience is not yet a test of how the product behaves at Muse’s scale. Our earlier comparison of Dots and Muse covers the pricing gap in detail.
Private Intelligence: who it actually covers
The headline privacy announcement at DevDay was “OpenAI Private Intelligence”, a framework giving businesses “stronger controls” over their data and zero data retention options, meaning no data is stored on OpenAI’s servers.
OpenAI’s own zero data retention page says that from 22 September it began rolling out a feature called Private Safety Processing to API customers, in phases. It lets automated safety systems look for patterns of misuse across related requests “without giving OpenAI personnel access to the underlying content”. That content stays on infrastructure the customer controls, and OpenAI says it is developing an option to store it on its own servers encrypted with keys only the customer holds.
That is a meaningful AI agent privacy advance, but it is aimed at enterprise and API customers. A person paying for ChatGPT Pro to use Dots is not an API customer with a zero retention contract. For personal plans, OpenAI’s Dots FAQ says the “Improve the model for everyone” setting decides whether a dot’s conversations and work may be used to improve its models, including “actions dots take, work they delegate to other agents, automations you set up, and data from connected apps”. OpenAI says it removes personal identifiers “where possible” first. Business, Enterprise and Edu workspaces are excluded from training by default.
What the Dots privacy FAQ says
OpenAI’s help page on Dots privacy, security and safety is unusually specific, and it reveals gaps that the DevDay stage did not mention. Four answers stand out for anyone weighing AI agent privacy:
- You cannot inspect individual memories. “You currently cannot view, delete or directly modify individual dot memories, including specific details that enter the dot’s context from plugins.” The only way to remove a dot’s context is to delete the dot.
- Disconnecting does not forget. Disconnecting a plugin “stops new access through that connection. It does not delete information your dot has already built into its context.”
- Turning off Memory does not delete. Memory is shared between ChatGPT and a dot; switching it off “stops that sharing. It does not delete information that your dot has already received.”
- Staff can still look. Even with model improvement switched off, “human review may occur in limited circumstances, including safety-related cases”.
There are real AI agent privacy protections too. A dot’s context “does not retain credentials, images, or screenshots”. Passwords for supported sign-ins go into a secure form “without exposing them to the model”. The most sensitive actions, such as changing a password or transferring money, require the user to take over, and an automated check called Auto-review inspects actions such as outgoing emails before they run. Dots are not available to anyone under 18.
Users still hesitate
Good AI agent privacy architecture does not automatically create comfort. In her hands-on test for The Verge, Allison Johnson got as far as a checkout screen where her dot asked her to type in her bank account details. She “didn’t trust it well enough to punch in my checking account number” and finished the task herself. Unlike Muse, Dots has no built-in virtual card integration, so a payment flow can mean handing raw financial details to the agent’s browser. We looked at another side of that test in our piece on the Dots agent.
| OpenAI’s message | What the Dots documentation says |
|---|---|
| “A new standard for privacy in frontier AI” | Zero retention and Private Safety Processing are for API and enterprise customers |
| “Most trustworthy, safe, and secure assistant” | Auto-review, takeover for sensitive actions, credentials kept from the model |
| Users stay in control | Individual memories cannot be viewed, edited or deleted |
| Disconnect any plugin at will | Disconnecting does not delete what the dot already absorbed |
| Training choices for users | Personal plans are governed by the “Improve the model for everyone” setting |
| Privacy even from OpenAI | Human review can still happen in safety cases, even with model improvement off |
Instinct and the Terms of Service Test for AI Agent Privacy
Not every agent maker has led with privacy. Instinct, the invite-only assistant built by a small team led by former Sierra research scientist Noah Shinn, became the buzziest agent of the summer before Muse and Dots arrived. In August, its terms of service became a case study in how AI agent privacy can be decided in the small print.
What testers found in August
TechCrunch reported on 24 August that testers were circulating screenshots of Instinct’s terms, which granted a “perpetual and irrevocable” licence to “access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify” users’ materials, including for training AI models. The terms also covered screen captures, cursor movements and keyboard inputs from users’ devices, and let Instinct enter into binding “agreements, commitments, or transactions” on users’ behalf.
Early users reported concrete AI agent privacy problems. Another tester, Claire Vo, found Instinct still summarising her inbox three hours after she had disconnected it, and the bot told her the emails were stored in plain text for later searches. Another early adopter, Peter Yang, said it would not delete his Gmail records until the team added a deletion tool. Investor Katie Jacobs Stanton said it sent an email on her behalf without checking first. “One unauthorized action can reset that trust to zero,” she wrote.
What the terms say now
The terms were revised on 26 August, and the version live today no longer contains the “perpetual and irrevocable” wording. Instinct now offers a training opt-out at its settings page and says material saved in a feature called the Vault will never be used to train models. That is a real AI agent privacy improvement, but the opt-out has exceptions: Instinct “may still use your Materials for AI model training when your Materials are flagged for safety review”, and models already trained on your data stay trained.
The disconnect problem is now written into the contract. “Even if you disconnect a Connected Service, we may still use the indexed Connected Service Input data unless you follow the instructions to request deletion,” the terms say. Users also authorise Instinct to “access, copy, collect, and index data” from connected services, accept that actions “may not always be reversible”, and agree to binding individual arbitration with a class action waiver unless they opt out. Our hands-on comparison of Instinct vs Muse covers how the product itself has developed since.
| AI agent privacy issue | Before 26 August (as reported) | Terms revised 26 August |
|---|---|---|
| Licence over your materials | “Perpetual and irrevocable”, sub-licensable | That wording is gone |
| Training on your data | Allowed under the licence | Allowed, with an opt-out; safety-flagged material excepted |
| Protected storage | None described | Vault materials never used for training |
| Disconnecting an account | Testers found data kept and still used | Indexed data may still be used unless you request deletion |
| Actions on your behalf | Binding agreements and transactions | Still authorised; you bear the consequences |
| Disputes | Not widely discussed | Binding arbitration and class action waiver, with an opt-out |
Privacy by silence
Instinct’s approach is the mirror image of Meta’s and OpenAI’s. It has made few public AI agent privacy promises, and its team largely stayed quiet during the August criticism, according to TechCrunch. After the article, Instinct told The Wall Street Journal it was taking the concerns seriously. The lesson for users is that the absence of a privacy pitch is not the same as the absence of privacy risk, and the terms are where the real commitments live.
AI Agent Privacy Controls Compared: Muse vs Dots vs Instinct
Putting the three products side by side shows that no company leads on every AI agent privacy measure. The table below is built only from each company’s own documentation and from reporting cited in this article.
| AI agent privacy control | Meta Muse | OpenAI Dots | Instinct |
|---|---|---|---|
| Price at launch | Free | ChatGPT plans from $100 a month | Free, invite-only |
| Where the agent works | Dedicated per-user cloud VM | Cloud virtual machine; your computer only if connected | Connected apps and devices |
| Training on your data | On by default, opt-out switch | Personal plans follow the “Improve the model” setting | On, opt-out with a safety exception |
| Provider access to your data | Possible to support, secure or operate | Human review possible in safety cases | Authorised to copy and index connected data |
| See and edit what it remembers | Yes: inspect, edit and download files and memory | No: delete the whole dot only | Deletion on request |
| Disconnecting a service | Disconnect any time | Stops new access; keeps what it already learned | Indexed data kept unless deletion requested |
| Passwords and tokens | Agent sees only surrogate tokens | Secure sign-in form; credentials not kept in context | No public architecture document |
| Payments | Single-use virtual card, approval each time | Saved merchant cards with approval | Payment method shared with the merchant |
| Verifiable privacy roadmap | Confidential VM “later this year” | Private Safety Processing for API customers | None announced |
Where the AI agent privacy promises are strongest
Meta publishes the most architecture. Its surrogate tokens, one-time code filtering and single-use payment cards are concrete protections that would limit the damage from a prompt injection. It is also the only one of the three to let users read and edit the agent’s memory files directly. OpenAI’s strengths are its takeover rule for the most sensitive actions, its refusal to keep credentials or screenshots in a dot’s context, and the cryptographic direction of its enterprise privacy work.
Where AI agent privacy is weakest
The weakest points are the same across all three: provider access, training defaults and data that outlives the connection. Meta can still reach the data in your VM. OpenAI cannot yet show you what a dot remembers. Instinct keeps indexed data after you disconnect unless you ask. None of the three yet offers a consumer AI agent privacy guarantee that an outsider can verify, rather than a policy the company can change.
Why AI Agent Privacy Is Harder Than Chatbot Privacy
The incidents above are not random. They follow from what agents are designed to do, and from the basic AI agent privacy problem that an assistant must see a lot to do a lot, which is why every company in this market admits that its agent will make mistakes.
The lethal trifecta
Meta’s own security post cites developer Simon Willison’s description of the lethal trifecta for AI agents. If an agent has access to private data, is exposed to untrusted content, and can communicate externally, “an attacker can easily trick it into accessing your private data and sending it to that attacker.” A personal assistant that reads email, browses the web and sends messages has all three by design.
Meta’s answer is defence in depth; OpenAI’s is Auto-review and takeover rules. Both concede the AI agent privacy problem is unsolved, and OpenAI’s FAQ says its protections “help reduce the risk” but “do not eliminate it”. It is a cybersecurity problem as much as a privacy one.
Permission is not the same as expectation
The Robb case shows the gap between legal consent and real understanding. He clicked “Allow Always” believing he would still approve offers later; instead, the grant let Muse send messages using a template that included his pickup address. “You never explicitly instructed me to share the address with buyers,” Muse’s own summary of the incident said, “and I never asked you for consent to do so.”
Aten’s Inc. column carries the same theme in its subtitle, that permission is not the same as “what a user actually expects your AI product will do with their personal information”. Good AI agent privacy design has to close that gap, not just record a click.
Agents create new personal data
Agents do not just store data; they infer it. WIRED’s reporting on Muse found instructions to record contacts’ homes, routines, key dates and the state of their relationships, and to suggest ways to strengthen them. “We are giving AI systems much more information about us than we are getting information from them,” Oxford ethicist Carissa Véliz told WIRED. Miranda Bogen of the Center for Democracy and Technology said these tools are “actively soliciting users to plug their whole lives in”. The people being profiled may never have signed up, which makes AI agent privacy a question for non-users too.
Data that outlives the connection
Both OpenAI’s FAQ and Instinct’s terms say the same thing in different words: switching off access does not erase what the agent has already absorbed. For AI agent privacy, that turns “disconnect” from an off switch into a partial measure. For a regulator, it raises questions about storage limitation and the right to erasure, which is exactly where UK law comes in.
The UK Angle: The ICO Puts AI Agent Privacy on Notice
On 8 October, two days before The Verge’s analysis, the UK’s Information Commissioner’s Office published the results of a two-year supervision programme for foundation model developers and made clear that agents are next. It is the most important regulatory signal yet on AI agent privacy for UK organisations.
Ten developers, real commitments
The ICO says ten of the biggest developers operating in the UK, namely Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI, “have made, or committed to make, data protection changes” after its scrutiny. The changes include clearer transparency information, stronger ways for people to exercise their rights and tougher assessments of safeguards. An eleventh developer, xAI, was dropped from the programme when the ICO opened a formal investigation into its Grok system. The regulator also admitted that “current foundation model training practices present technical challenges” for complying with UK law.
Enquiries into agents that bypassed protections
The more pointed part of the announcement concerns agents, and it goes to the heart of AI agent privacy. The ICO said it had made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute about recent testing and deployment, after reports that “certain agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face”. Those enquiries are ongoing.
“Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance,” said Richard Nevinson, the ICO’s director of technology regulation. “If people are to trust AI innovation, they rightly expect to know how their personal information is being protected.”
A call for evidence closing on 20 November
The ICO has opened a six-week call for evidence on how organisations manage the data protection risks of agentic AI, covering security, transparency, accountability, automated decision-making, fairness and lawful data use. It closes on 20 November 2026 and will feed into guidance and a statutory code of practice on AI and automated decision-making. Any UK business deploying agents, or planning to, can respond, and it is the clearest chance yet to shape UK rules on AI agent privacy.
What UK data protection law already expects
The ICO’s earlier Tech Futures report on agentic AI shows how existing UK GDPR principles map onto agents, and it is blunt on the points where today’s products are weakest. “Organisations should not give agentic AI systems access to information just because it might be useful in the future,” it says. It also rejects the idea that autonomy shifts the blame: “AI agency does not mean the removal of human, and therefore organisational, responsibility for data processing.”
| UK GDPR principle | Question for an AI agent | Where current agents struggle |
|---|---|---|
| Purpose limitation | Is each connector tied to a specific task? | General-purpose agents connect everything up front |
| Data minimisation | Does it access only what the task needs? | Indexing whole inboxes “just in case” |
| Storage limitation and erasure | Is data deleted when access ends? | Disconnecting does not delete what was absorbed |
| Transparency and access rights | Can people see what it holds about them? | Dots memories cannot be viewed item by item |
| Special category data | Could it infer health, beliefs or relationships? | Relationship profiling of contacts |
| Automated decision-making | Can people contest decisions it makes? | Binding actions taken without a check |
| Security | Is the isolation layer robust? | Reported VM escape bugs before Muse’s launch |
Muse launched in the US and Canada, according to TechCrunch’s launch-period data, so UK consumers have mostly met these products through OpenAI and Instinct so far. But UK staff will use whatever agents they can download, and any UK organisation that lets an agent process customer or employee data is the controller for that processing, whatever the vendor promises about AI agent privacy. Our data protection team sees this shadow use of AI more often than formal deployments.
Can AI Agent Privacy Promises Be Verified?
The deepest problem with today’s AI agent privacy promises is that most of them can only be taken on trust. A policy that says staff access is restricted is only as good as the company’s internal controls and its willingness to keep the policy. Both Meta and OpenAI appear to recognise this, because both are now pointing at cryptographic guarantees.
Policy promises vs technical guarantees
Meta’s Confidential VM aims to make it impossible, not just forbidden, for Meta to read a user’s VM, with “a continuous audit of the system that will be visible to and inspectable by anyone”. OpenAI’s Private Safety Processing already keeps flagged content away from its staff for API customers, and the company has signalled that confidential computing for inference itself is next. If either ships as described, it would mark a genuine shift in AI agent privacy from “trust us” to “check us”. Neither is yet available to the ordinary consumer of these agents.
What independent verification would look like
Users and businesses do not need to wait for perfect cryptography to ask better questions. Credible AI agent privacy claims would come with published third-party audits, regular transparency reports on staff access and law enforcement requests, public statistics from bug bounty programmes, and prompt disclosure when something goes wrong. Meta’s bug bounty and its offer of source code to auditors are steps in that direction. OpenAI’s FAQ is a model of plain-English disclosure about what the product does not yet do.
| AI agent privacy promise | Status in October 2026 | How it could be verified |
|---|---|---|
| Muse Confidential VM locks Meta out | Promised for later this year; testers and auditors only | Public, continuous audit Meta says it will publish |
| Muse isolates each user’s data | Live; pre-launch escape bugs fixed | Bug bounty results and incident disclosures |
| OpenAI staff cannot see flagged API content | Rolling out to API customers since 22 September | Customer-held keys and storage |
| Dots credentials never reach the model | Live for supported sign-ins | Independent security testing |
| Instinct Vault data never trains models | In the 26 August terms | Contractual; no technical evidence published |
| Developers give clearer transparency and rights | Committed to the ICO | ICO monitoring of delivery |
Four signals to watch
Four developments over the next few months will show whether AI agent privacy promises are being kept. First, whether Meta ships Confidential VM to ordinary users this year, as promised. Second, whether OpenAI adds a way to view and delete individual dot memories. Third, what the ICO says once its enquiries into agent testing conclude and its call for evidence closes. Fourth, whether any company publishes a transparency report covering staff access to agent data. Meta, Google, OpenAI and Anthropic are also due before a committee of MPs on AI security on 13 October, according to The Next Web, which may add detail.
What AI Agent Privacy Means for UK Businesses
For most organisations the immediate risk is not a headline breach at Meta or OpenAI. It is an employee connecting a personal agent to a work inbox, a shared drive or a customer system without anyone knowing. Treat AI agent privacy as a governance question first and a product question second.
Before you connect an agent to work accounts
Start with the principle the ICO keeps returning to: least privilege, the simplest AI agent privacy control there is. Give an agent read access before write access, connect only the accounts a specific task needs, and avoid “Allow Always” grants for anything that sends messages, shares files or spends money. Turn off model training where the option exists, and check whether business plans offer different defaults from personal ones, as OpenAI’s do.
Set a policy for personal agents
Most staff will meet agents as consumer apps. A short AI agent privacy policy that says which agents may touch company data, on which accounts, and with what approvals, prevents the most common failure: a well-meaning employee granting an agent full access to a mailbox full of client data. Our AI strategy team helps organisations write AI-use policies that cover agents as well as chatbots.
Ask vendors the hard questions
Before approving any agent, ask where the data is processed, who at the vendor can access it and under what conditions, whether it is used for training, what happens to absorbed data when an account is disconnected, how individual memories can be viewed and deleted, and how credentials and payments are handled. The answers should be in writing, and they should match the terms of service, not just the launch keynote. If a vendor cannot answer these AI agent privacy questions clearly, treat that as the answer.
| AI agent privacy check | What good looks like | Red flag |
|---|---|---|
| Provider access | Technically prevented, or tightly limited and audited | “Access when necessary to operate the service” |
| Training | Off by default for business data | On by default with exceptions to the opt-out |
| Memory | Viewable and deletable item by item | All-or-nothing deletion only |
| Disconnection | Deletes derived data, or offers to | Keeps indexed data unless you ask |
| Credentials | Never visible to the model | Passwords typed into chat |
| Payments | Single-use cards, approval every time | Stored card used without a check |
| Permissions | Scoped to one task and time-limited | “Allow Always” by default |
| Accountability | Audit log of every action | No record of what the agent did |
The bottom line
The honest answer to The Verge’s question is that it is too early to say whether AI agent makers will deliver, and the early evidence is mixed. Meta has the strongest published architecture and the longest list of reported incidents. OpenAI has the most careful documentation and a much smaller, paying user base. Instinct has the fewest promises and the most revealing contract. We asked a related question in our analysis of AI agent trust: whether anyone should let these products run their life. On AI agent privacy, the safest assumption for now is that the promise is a direction of travel, not a guarantee.
AI Agent Privacy FAQ
What does AI agent privacy mean?
AI agent privacy means how a personal assistant collects, stores, uses and shares the data it needs to act for you, including emails, messages, calendars, passwords, payment details and the information it infers about you and the people you deal with. Because agents act as well as read, it also covers what they disclose to others on your behalf.
Does Meta use Muse conversations to train its AI?
Yes, by default. Meta says Muse conversations, tool calls and agent hand-offs are sanitised to remove key personally identifiable information and then used for training, and users can opt out with a switch in Muse settings. Meta says it does not share Muse conversations with its ad systems.
Can I see what OpenAI’s Dots remembers about me?
Not item by item. OpenAI’s FAQ says you currently cannot view, delete or directly modify individual dot memories. You can delete a dot’s whole context by deleting the dot, and manage anything it has shared with ChatGPT Memory separately. That is a notable AI agent privacy gap for what OpenAI calls an always-on agent.
Does disconnecting an app delete what an agent learned?
Not necessarily, and it is one of the least understood AI agent privacy gaps. OpenAI says disconnecting a plugin stops new access but does not delete what a dot has already built into its context. Instinct’s terms say it may still use indexed data from a disconnected service unless you request deletion.
What is the ICO doing about AI agents?
On 8 October 2026 the ICO opened a six-week call for evidence on the data protection risks of agentic AI, closing on 20 November, and confirmed enquiries with OpenAI, Anthropic, Meta and the AI Security Institute about agents that reportedly bypassed protections. The evidence will shape guidance and a statutory code of practice that will set UK expectations for AI agent privacy.
Which AI agent is best for privacy?
None is clearly best yet. On published AI agent privacy controls, Muse has the most detailed architecture and lets you read and edit its memory, but Meta can still access your data and it has the longest list of reported incidents. Dots keeps credentials away from the model and makes you take over sensitive actions, but you cannot see individual memories. Instinct has made the fewest promises. Choose by the controls that matter for your data, not by the marketing.
References
AI agent makers are promising privacy: will they deliver? (The Verge)
How We Built Safety Into Muse (Meta AI Research)
Dots privacy, security, and safety FAQs (OpenAI Help Center)
Offering Zero Data Retention for frontier models (OpenAI)
Instinct Terms of Service, revised 26 August 2026
Meta rushed to fix Muse ‘VM escape’ vulnerability soon before launch (404 Media)
Muse creates detailed profiles of all your friends and family (WIRED)
Meta’s new Muse AI agent read my private messages. I never asked it to (Inc.)
Meta disputes claim that Muse read a user’s private messages without permission (TechCrunch)
Meta patches Muse exploit that let attackers control the AI agent (The Verge)
Meta’s Muse AI sent a YouTuber’s address to a stranger (The Verge)
OpenAI’s new agent is a shot at Meta, but can it compete with free? (The Verge)
OpenAI’s Dot agent is enterprise software that can also order your dinner (The Verge)
Instinct’s powerful AI assistant is raising privacy and security concerns (TechCrunch)
Meta’s Muse is outpacing ChatGPT’s early mobile launch (TechCrunch)
ICO secures changes from leading AI developers as scrutiny extends to AI agents (ICO)
Agentic AI call for evidence (ICO)
ICO tech futures: agentic AI, data protection and privacy risks (ICO)
AI giants promise to play nice with personal data after UK watchdog scrutiny (The Register)
ICO secures data protection changes from 10 AI developers, turns to agents (The Next Web)
More AI coverage: explore Progressive Robot's AI Models, Tools & Releases hub — hands-on reviews, setup guides and benchmarks in one place.