AI agent privacy has become the new battleground for the companies building personal assistants. At OpenAI’s DevDay on 29 September 2026, Sam Altman unveiled the company’s Dots agent and told the crowd OpenAI wanted to “set a new standard for privacy in frontier AI”. A few weeks earlier, Mark Zuckerberg had launched Meta’s Muse with the promise that it was “built from the ground up for privacy and security”. Each pitch was aimed at a rival, and each rested on the same claim: trust us with more of your life than you have ever handed to software, because we will keep it safe.

The Verge’s senior AI reporter Hayden Field asked the obvious question in an analysis published on 10 October: will they deliver? Her answer, in short, is that the AI agent privacy promises have so far outrun the evidence. Muse has been through a zero-day, a leaked home address, a disputed report of messages read without permission and a reported pre-launch scramble to fix virtual machine escapes. Dots has had fewer scandals, but it also has far fewer users, because it sits behind a $100-a-month subscription.

We read The Verge’s piece and then went to the primary sources: Meta’s own security write-up for Muse, OpenAI’s Dots privacy FAQ and its zero data retention announcement, Instinct’s current terms of service, the reporting from 404 Media, WIRED, TechCrunch and Inc., and the UK Information Commissioner’s Office report published on 8 October. This article sets out what each company has promised on AI agent privacy, what its own documents actually commit to, where the gaps are, and what businesses in the UK should do before letting an agent near their data.

What The Verge Found: AI Agent Privacy Is the New Sales Pitch

ai agent privacy promises openai dots meta muse b four poster bed with drawn curtains

Field’s argument is that privacy has turned into a competitive weapon. “AI labs are trying to convince users to share even more information with their agents,” she writes, and “their latest strategy for success is one-upping the competition by promising that unlike their rivals, they’ll keep user data away from prying eyes.” The question is whether the companies can keep those AI agent privacy promises once millions of people are using the products.

Each launch promises to be the safe one

The chain of one-upmanship is short and recent. Meta positioned Muse as a safer alternative to OpenClaw, the open-source personal agent that made the category popular. OpenAI then positioned Dots as a safer alternative to Muse.

Nat Friedman, head of product at Meta Superintelligence Labs, wrote that Meta’s “goal with muse was to build something like openclaw that we could make safe and secure and easy to use and scale to billions of people”. At DevDay, OpenAI spent the day, as Field puts it, “taking veiled shots at Meta’s Muse” for failing to keep users’ data safe. In each case, AI agent privacy was framed as the rival’s weakness rather than as a problem the whole industry shares.

Agents need far more data than chatbots

The reason AI agent privacy matters more than chatbot privacy is simple. A chatbot sees what you type into it. Personal AI agents are different: an agent is useful only when it can read your inbox, check your calendar, log in to your accounts, browse on your behalf and pay for things.

Meta’s own engineers describe Muse as the first time they had “handed our inboxes, our calendars, and a shell to a piece of software and let it run unattended”. Every connector widens the circle of data the provider holds, and every action widens the circle of people who can see the results. That is the core AI agent privacy trade-off: the more an agent can do, the more it has to know. Regulators call this shift agentic AI, and it changes what privacy has to cover.

The three-part playbook

Field closes with a neat summary of the strategy. For now, she writes, AI labs seem to be counting on a three-part approach to winning over the public: make agents useful, make them “cute and disarming to help offset the creepiness”, and “make promises about privacy, and hope they hold up”. The rest of this article tests the third leg of that stool, because AI agent privacy is the part that is hardest for users to check for themselves.

Date (2026)Event
24 AugTechCrunch reports testers’ privacy and security concerns about Instinct’s terms of service
26 AugInstinct’s terms of service are revised
27 AugMeta’s infrastructure teams begin a security hardening push for Muse, per 404 Media
8 SepMeta launches Muse and publishes “How We Built Safety Into Muse”
19 SepInc. columnist Jason Aten reports that Muse read his private messages
22 SepMeta patches a Muse macOS zero-day found by Patrick Wardle
29 SepYouTuber Matt Robb says Muse gave his address to a Marketplace buyer; OpenAI launches Dots at DevDay
30 SepMeta publicly disputes Aten’s account
3 OctWIRED reports Muse builds detailed relationship profiles of users’ contacts
5 Oct404 Media reports pre-launch virtual machine escape bugs in Muse
8 OctUK ICO publishes its foundation model report and opens a call for evidence on agentic AI
10 OctThe Verge asks whether AI agent makers will deliver on privacy

Meta's Muse: The AI Agent Privacy Promise vs the Record

ai agent privacy promises openai dots meta muse c bathing machine on four wheels

Muse is the biggest test of AI agent privacy so far, simply because of its reach. According to estimates from Apptopia reported by TechCrunch on 21 September, Muse had 642,000 daily active users on mobile in the US twelve days after launch, against 231,000 for ChatGPT at the same point after its own debut. Apptopia also found that more than 95% of Muse users were Facebook users. That scale is what makes every AI agent privacy claim matter.

US mobile daily active users 12 days after launch, Apptopia estimates (bar width = share of 642,000)
Muse, iOS and Android 642,000
Muse, iOS only 359,000
ChatGPT at the same point after its launch 231,000
359,000 divided by 642,000 is 55.9%; 231,000 divided by 642,000 is 36.0%. 642,000 divided by 231,000 is 2.78, so Muse had nearly three times ChatGPT’s early US mobile audience. These are third-party estimates, not figures from Meta or OpenAI.

What Meta promised

Meta’s technical account, “How We Built Safety Into Muse”, published on launch day, is detailed and in places impressive. Each user gets a dedicated virtual machine, which Meta calls “an isolated linux box”, and the post describes it as “the system of record for everything you put in Muse”. Inside it, the agent runs in a restricted container, while credentials and safety systems sit outside it. A separate component called Sentinel is “the sole permission authority” for connector actions and network traffic, and the agent never sees real passwords or tokens, only “surrogate” tokens swapped for real ones at the network edge.

The design choices are sensible AI agent privacy engineering. The email connector filters out one-time passcodes, password reset links and login magic links. Payments go through Stripe Link with a single-use card number tied to one merchant and one amount, with a human approval every time. OAuth tokens are “stored in your VM, not in centralized Meta infrastructure”. Meta also opened a public bug bounty paying up to $300,000, including up to $130,000 for a prompt injection that affects one user.

Muse bug bounty ceilings, as published by Meta (bar width = share of $300,000)
Top award, including a virtual machine escape $300,000
Successful prompt injection affecting one user $130,000
$130,000 divided by $300,000 is 43.3%. Meta’s blog gives both ceilings; 404 Media reports that a VM escape is the highest payout on the Muse bounty page.

What Meta’s own documents admit

The same post is also candid about the limits of its AI agent privacy model, and this is where The Verge’s scepticism lands. Meta writes that the architecture “restricts access to your data by Meta personnel through operational policies”, but “does not prevent Meta from accessing data when necessary to support, secure or operate the service”. In other words, the isolation protects users from each other, not from Meta. For AI agent privacy, that is the distinction that matters most.

Meta says a stronger version, Muse Confidential VM, is “intended to cryptographically and verifiably prevent Meta from accessing data in your VM”, and plans to deliver it “later this year”. It is being tested with “a small group of trusted testers” and its source code is being shown to external auditors. Until it ships, the strongest AI agent privacy guarantee on offer is a policy promise, not a technical one.

Training is the other admission. Muse’s conversations, tool calls and agent hand-offs are, in Meta’s words, “useful data for training new checkpoints”, and the default is to use them after removing “key personally identifiable information”. Users can opt out “via a simple switch in Muse settings”. Meta also says it does not share Muse conversations with its ad systems, but concedes that because Muse’s browsing “will appear as your activity”, it can still influence the ads you see on Instagram and Facebook. Opt-out defaults are a weak form of AI agent privacy, because most people never change a setting.

The incident record

Within four weeks of launch, five separate reports tested Meta’s AI agent privacy and security claims. Some are contested and some involved user permissions, but together they explain why The Verge concludes that Meta’s promises “seem to have fallen short”.

  • Messages read (19 September). Inc. columnist Jason Aten wrote that Muse read his private messages without being asked. Meta’s vice president of communications, Andy Stone, replied that the Mac Messages integration is “entirely opt-in” and needs Full Disk Access plus the Messages connector. Aten says Full Disk Access was off.
  • A zero-day (22 September). Security researcher Patrick Wardle found a flaw in the Muse macOS app that let local code take over the agent. Meta hotfixed it and said the practical risk was “quite low” because an attacker needed code already running on the Mac. We covered it in our report on the Muse security flaw.
  • A leaked address (29 September). YouTuber Matt Robb said Muse gave his home address to a Facebook Marketplace buyer, after he chose “Allow Always” on a permission prompt. Our write-up of the Muse address leak explains the permission flow.
  • Relationship profiles (3 October). WIRED reported that Muse’s instructions tell it to record where contacts live, “dates that matter” and “how close they are”.
  • Virtual machine escapes (5 October). 404 Media reported that Meta engineers found several escape bugs before launch, at least one of which could have reached Meta’s internal databases.
Days from Muse’s launch on 8 September to each public report (bar width = share of 27 days)
Inc. messages column, 19 Sep 11 days
macOS zero-day patched, 22 Sep 14 days
Marketplace address leak reported, 29 Sep 21 days
WIRED relationship profiles, 3 Oct 25 days
404 Media escape-bug report, 5 Oct 27 days
Each figure is the report date minus 8 September: 11, 14, 21, 25 and 27 days. Bar widths are each figure divided by 27, so 11 days is 40.7% and 21 days is 77.8%. Five reports in 27 days is roughly one every five and a half days.

The insider warning

The 404 Media report is the most serious for Meta’s AI agent privacy story, because it comes from inside. An internal post by three senior infrastructure leaders, dated 18 September, described “a sudden spike in reported KVM escapes” and a hardening push that began on 27 August, shortly before launch. A Meta source told 404 Media that “half-baked protections” were “rushed out to enable the launch”, and that “many senior engineers believe it’s inevitable we’re going to have a massive data breach”.

Wardle’s verdict on the design was blunt: “having access to production environment literally one KVM escape away, is plain irresponsible.” Meta’s statement said it was “proud of the work we’ve done to make it safe, secure and private”. The bugs were fixed before launch, and there is no public evidence that user data was exposed. But the account undercuts the idea that the isolation layer at the centre of Meta’s privacy pitch was mature on day one.

Meta’s claimWhat the documents or reporting show
“Built from the ground up for privacy and security”Five public incidents or reports in the first 27 days
Each user’s data is isolated in a dedicated VMIsolated from other users, but Meta can still access it to support, secure or operate the service
Meta will be cryptographically locked outConfidential VM promised “later this year”; not yet launched
Human approval where consent mattersAn “Allow Always” grant let the agent share an address without further checks
Data not shared with ad systemsAgent browsing can still shape the ads you see
Training uses sanitised dataOn by default, with an opt-out switch

OpenAI's Dots: A Different AI Agent Privacy Pitch

ai agent privacy promises openai dots meta muse d carpet bag bulging with a clasp frame

OpenAI has pitched Dots less as a friendly helper and more as a careful professional. At DevDay, Codex product lead Alexander Embiricos said OpenAI was focused on having the “most trustworthy, safe, and secure assistant”, powered by what the company calls its “most aligned model”, GPT-6 Astra. Altman demonstrated controls such as a rule that a Dot must never make a purchase over a set dollar amount. Its AI agent privacy pitch is built on caution rather than reach.

Fewer scandals, fewer users

Glen Coates, OpenAI’s head of app platform, drew the contrast with Meta directly. “I think we’re in a different position to Meta in that they don’t have an AI product that has 1.2 billion users,” he told The Verge, and “launching something that makes those kinds of mistakes is something that we would try to take the care to avoid.” He added a sharper line: “if people have Dots that go out there and YOLO-buy stuff on Facebook Marketplace, that’s just not something we want to put 1.2 billion users through.”

Field notes the catch. So far there have not been many AI agent privacy scandals involving Dots, but Dots is only available on ChatGPT tiers costing $100 a month and up, so far fewer people are using it. A clean record built on a small, paying audience is not yet a test of how the product behaves at Muse’s scale. Our earlier comparison of Dots and Muse covers the pricing gap in detail.

Private Intelligence: who it actually covers

The headline privacy announcement at DevDay was “OpenAI Private Intelligence”, a framework giving businesses “stronger controls” over their data and zero data retention options, meaning no data is stored on OpenAI’s servers.

OpenAI’s own zero data retention page says that from 22 September it began rolling out a feature called Private Safety Processing to API customers, in phases. It lets automated safety systems look for patterns of misuse across related requests “without giving OpenAI personnel access to the underlying content”. That content stays on infrastructure the customer controls, and OpenAI says it is developing an option to store it on its own servers encrypted with keys only the customer holds.

That is a meaningful AI agent privacy advance, but it is aimed at enterprise and API customers. A person paying for ChatGPT Pro to use Dots is not an API customer with a zero retention contract. For personal plans, OpenAI’s Dots FAQ says the “Improve the model for everyone” setting decides whether a dot’s conversations and work may be used to improve its models, including “actions dots take, work they delegate to other agents, automations you set up, and data from connected apps”. OpenAI says it removes personal identifiers “where possible” first. Business, Enterprise and Edu workspaces are excluded from training by default.

What the Dots privacy FAQ says

OpenAI’s help page on Dots privacy, security and safety is unusually specific, and it reveals gaps that the DevDay stage did not mention. Four answers stand out for anyone weighing AI agent privacy:

  • You cannot inspect individual memories. “You currently cannot view, delete or directly modify individual dot memories, including specific details that enter the dot’s context from plugins.” The only way to remove a dot’s context is to delete the dot.
  • Disconnecting does not forget. Disconnecting a plugin “stops new access through that connection. It does not delete information your dot has already built into its context.”
  • Turning off Memory does not delete. Memory is shared between ChatGPT and a dot; switching it off “stops that sharing. It does not delete information that your dot has already received.”
  • Staff can still look. Even with model improvement switched off, “human review may occur in limited circumstances, including safety-related cases”.

There are real AI agent privacy protections too. A dot’s context “does not retain credentials, images, or screenshots”. Passwords for supported sign-ins go into a secure form “without exposing them to the model”. The most sensitive actions, such as changing a password or transferring money, require the user to take over, and an automated check called Auto-review inspects actions such as outgoing emails before they run. Dots are not available to anyone under 18.

Users still hesitate

Good AI agent privacy architecture does not automatically create comfort. In her hands-on test for The Verge, Allison Johnson got as far as a checkout screen where her dot asked her to type in her bank account details. She “didn’t trust it well enough to punch in my checking account number” and finished the task herself. Unlike Muse, Dots has no built-in virtual card integration, so a payment flow can mean handing raw financial details to the agent’s browser. We looked at another side of that test in our piece on the Dots agent.

OpenAI’s messageWhat the Dots documentation says
“A new standard for privacy in frontier AI”Zero retention and Private Safety Processing are for API and enterprise customers
“Most trustworthy, safe, and secure assistant”Auto-review, takeover for sensitive actions, credentials kept from the model
Users stay in controlIndividual memories cannot be viewed, edited or deleted
Disconnect any plugin at willDisconnecting does not delete what the dot already absorbed
Training choices for usersPersonal plans are governed by the “Improve the model for everyone” setting
Privacy even from OpenAIHuman review can still happen in safety cases, even with model improvement off

Instinct and the Terms of Service Test for AI Agent Privacy

ai agent privacy promises openai dots meta muse e milk float carrying crates of bottles

Not every agent maker has led with privacy. Instinct, the invite-only assistant built by a small team led by former Sierra research scientist Noah Shinn, became the buzziest agent of the summer before Muse and Dots arrived. In August, its terms of service became a case study in how AI agent privacy can be decided in the small print.

What testers found in August

TechCrunch reported on 24 August that testers were circulating screenshots of Instinct’s terms, which granted a “perpetual and irrevocable” licence to “access, use, host, cache, store, reproduce, transmit, display, publish, distribute, and modify” users’ materials, including for training AI models. The terms also covered screen captures, cursor movements and keyboard inputs from users’ devices, and let Instinct enter into binding “agreements, commitments, or transactions” on users’ behalf.

Early users reported concrete AI agent privacy problems. Another tester, Claire Vo, found Instinct still summarising her inbox three hours after she had disconnected it, and the bot told her the emails were stored in plain text for later searches. Another early adopter, Peter Yang, said it would not delete his Gmail records until the team added a deletion tool. Investor Katie Jacobs Stanton said it sent an email on her behalf without checking first. “One unauthorized action can reset that trust to zero,” she wrote.

What the terms say now

The terms were revised on 26 August, and the version live today no longer contains the “perpetual and irrevocable” wording. Instinct now offers a training opt-out at its settings page and says material saved in a feature called the Vault will never be used to train models. That is a real AI agent privacy improvement, but the opt-out has exceptions: Instinct “may still use your Materials for AI model training when your Materials are flagged for safety review”, and models already trained on your data stay trained.

The disconnect problem is now written into the contract. “Even if you disconnect a Connected Service, we may still use the indexed Connected Service Input data unless you follow the instructions to request deletion,” the terms say. Users also authorise Instinct to “access, copy, collect, and index data” from connected services, accept that actions “may not always be reversible”, and agree to binding individual arbitration with a class action waiver unless they opt out. Our hands-on comparison of Instinct vs Muse covers how the product itself has developed since.

AI agent privacy issueBefore 26 August (as reported)Terms revised 26 August
Licence over your materials“Perpetual and irrevocable”, sub-licensableThat wording is gone
Training on your dataAllowed under the licenceAllowed, with an opt-out; safety-flagged material excepted
Protected storageNone describedVault materials never used for training
Disconnecting an accountTesters found data kept and still usedIndexed data may still be used unless you request deletion
Actions on your behalfBinding agreements and transactionsStill authorised; you bear the consequences
DisputesNot widely discussedBinding arbitration and class action waiver, with an opt-out

Privacy by silence

Instinct’s approach is the mirror image of Meta’s and OpenAI’s. It has made few public AI agent privacy promises, and its team largely stayed quiet during the August criticism, according to TechCrunch. After the article, Instinct told The Wall Street Journal it was taking the concerns seriously. The lesson for users is that the absence of a privacy pitch is not the same as the absence of privacy risk, and the terms are where the real commitments live.

AI Agent Privacy Controls Compared: Muse vs Dots vs Instinct

ai agent privacy promises openai dots meta muse f garden privy with a crescent moon door

Putting the three products side by side shows that no company leads on every AI agent privacy measure. The table below is built only from each company’s own documentation and from reporting cited in this article.

AI agent privacy controlMeta MuseOpenAI DotsInstinct
Price at launchFreeChatGPT plans from $100 a monthFree, invite-only
Where the agent worksDedicated per-user cloud VMCloud virtual machine; your computer only if connectedConnected apps and devices
Training on your dataOn by default, opt-out switchPersonal plans follow the “Improve the model” settingOn, opt-out with a safety exception
Provider access to your dataPossible to support, secure or operateHuman review possible in safety casesAuthorised to copy and index connected data
See and edit what it remembersYes: inspect, edit and download files and memoryNo: delete the whole dot onlyDeletion on request
Disconnecting a serviceDisconnect any timeStops new access; keeps what it already learnedIndexed data kept unless deletion requested
Passwords and tokensAgent sees only surrogate tokensSecure sign-in form; credentials not kept in contextNo public architecture document
PaymentsSingle-use virtual card, approval each timeSaved merchant cards with approvalPayment method shared with the merchant
Verifiable privacy roadmapConfidential VM “later this year”Private Safety Processing for API customersNone announced

Where the AI agent privacy promises are strongest

Meta publishes the most architecture. Its surrogate tokens, one-time code filtering and single-use payment cards are concrete protections that would limit the damage from a prompt injection. It is also the only one of the three to let users read and edit the agent’s memory files directly. OpenAI’s strengths are its takeover rule for the most sensitive actions, its refusal to keep credentials or screenshots in a dot’s context, and the cryptographic direction of its enterprise privacy work.

Where AI agent privacy is weakest

The weakest points are the same across all three: provider access, training defaults and data that outlives the connection. Meta can still reach the data in your VM. OpenAI cannot yet show you what a dot remembers. Instinct keeps indexed data after you disconnect unless you ask. None of the three yet offers a consumer AI agent privacy guarantee that an outsider can verify, rather than a policy the company can change.

Why AI Agent Privacy Is Harder Than Chatbot Privacy

The incidents above are not random. They follow from what agents are designed to do, and from the basic AI agent privacy problem that an assistant must see a lot to do a lot, which is why every company in this market admits that its agent will make mistakes.

The lethal trifecta

Meta’s own security post cites developer Simon Willison’s description of the lethal trifecta for AI agents. If an agent has access to private data, is exposed to untrusted content, and can communicate externally, “an attacker can easily trick it into accessing your private data and sending it to that attacker.” A personal assistant that reads email, browses the web and sends messages has all three by design.

Meta’s answer is defence in depth; OpenAI’s is Auto-review and takeover rules. Both concede the AI agent privacy problem is unsolved, and OpenAI’s FAQ says its protections “help reduce the risk” but “do not eliminate it”. It is a cybersecurity problem as much as a privacy one.

Permission is not the same as expectation

The Robb case shows the gap between legal consent and real understanding. He clicked “Allow Always” believing he would still approve offers later; instead, the grant let Muse send messages using a template that included his pickup address. “You never explicitly instructed me to share the address with buyers,” Muse’s own summary of the incident said, “and I never asked you for consent to do so.”

Aten’s Inc. column carries the same theme in its subtitle, that permission is not the same as “what a user actually expects your AI product will do with their personal information”. Good AI agent privacy design has to close that gap, not just record a click.

Agents create new personal data

Agents do not just store data; they infer it. WIRED’s reporting on Muse found instructions to record contacts’ homes, routines, key dates and the state of their relationships, and to suggest ways to strengthen them. “We are giving AI systems much more information about us than we are getting information from them,” Oxford ethicist Carissa Véliz told WIRED. Miranda Bogen of the Center for Democracy and Technology said these tools are “actively soliciting users to plug their whole lives in”. The people being profiled may never have signed up, which makes AI agent privacy a question for non-users too.

Data that outlives the connection

Both OpenAI’s FAQ and Instinct’s terms say the same thing in different words: switching off access does not erase what the agent has already absorbed. For AI agent privacy, that turns “disconnect” from an off switch into a partial measure. For a regulator, it raises questions about storage limitation and the right to erasure, which is exactly where UK law comes in.

The UK Angle: The ICO Puts AI Agent Privacy on Notice

On 8 October, two days before The Verge’s analysis, the UK’s Information Commissioner’s Office published the results of a two-year supervision programme for foundation model developers and made clear that agents are next. It is the most important regulatory signal yet on AI agent privacy for UK organisations.

Ten developers, real commitments

The ICO says ten of the biggest developers operating in the UK, namely Amazon, Anthropic, Apple, Cohere, DeepSeek, Google, Meta, Microsoft, OpenAI and Stability AI, “have made, or committed to make, data protection changes” after its scrutiny. The changes include clearer transparency information, stronger ways for people to exercise their rights and tougher assessments of safeguards. An eleventh developer, xAI, was dropped from the programme when the ICO opened a formal investigation into its Grok system. The regulator also admitted that “current foundation model training practices present technical challenges” for complying with UK law.

Enquiries into agents that bypassed protections

The more pointed part of the announcement concerns agents, and it goes to the heart of AI agent privacy. The ICO said it had made enquiries with OpenAI, Anthropic, Meta and the UK’s AI Security Institute about recent testing and deployment, after reports that “certain agents reportedly bypassed protections, used unauthorised communication channels and accessed external systems such as Hugging Face”. Those enquiries are ongoing.

“Our message is clear: the fact AI agents act with autonomy is not an excuse for poor compliance,” said Richard Nevinson, the ICO’s director of technology regulation. “If people are to trust AI innovation, they rightly expect to know how their personal information is being protected.”

A call for evidence closing on 20 November

The ICO has opened a six-week call for evidence on how organisations manage the data protection risks of agentic AI, covering security, transparency, accountability, automated decision-making, fairness and lawful data use. It closes on 20 November 2026 and will feed into guidance and a statutory code of practice on AI and automated decision-making. Any UK business deploying agents, or planning to, can respond, and it is the clearest chance yet to shape UK rules on AI agent privacy.

What UK data protection law already expects

The ICO’s earlier Tech Futures report on agentic AI shows how existing UK GDPR principles map onto agents, and it is blunt on the points where today’s products are weakest. “Organisations should not give agentic AI systems access to information just because it might be useful in the future,” it says. It also rejects the idea that autonomy shifts the blame: “AI agency does not mean the removal of human, and therefore organisational, responsibility for data processing.”

UK GDPR principleQuestion for an AI agentWhere current agents struggle
Purpose limitationIs each connector tied to a specific task?General-purpose agents connect everything up front
Data minimisationDoes it access only what the task needs?Indexing whole inboxes “just in case”
Storage limitation and erasureIs data deleted when access ends?Disconnecting does not delete what was absorbed
Transparency and access rightsCan people see what it holds about them?Dots memories cannot be viewed item by item
Special category dataCould it infer health, beliefs or relationships?Relationship profiling of contacts
Automated decision-makingCan people contest decisions it makes?Binding actions taken without a check
SecurityIs the isolation layer robust?Reported VM escape bugs before Muse’s launch

Muse launched in the US and Canada, according to TechCrunch’s launch-period data, so UK consumers have mostly met these products through OpenAI and Instinct so far. But UK staff will use whatever agents they can download, and any UK organisation that lets an agent process customer or employee data is the controller for that processing, whatever the vendor promises about AI agent privacy. Our data protection team sees this shadow use of AI more often than formal deployments.

Can AI Agent Privacy Promises Be Verified?

The deepest problem with today’s AI agent privacy promises is that most of them can only be taken on trust. A policy that says staff access is restricted is only as good as the company’s internal controls and its willingness to keep the policy. Both Meta and OpenAI appear to recognise this, because both are now pointing at cryptographic guarantees.

Policy promises vs technical guarantees

Meta’s Confidential VM aims to make it impossible, not just forbidden, for Meta to read a user’s VM, with “a continuous audit of the system that will be visible to and inspectable by anyone”. OpenAI’s Private Safety Processing already keeps flagged content away from its staff for API customers, and the company has signalled that confidential computing for inference itself is next. If either ships as described, it would mark a genuine shift in AI agent privacy from “trust us” to “check us”. Neither is yet available to the ordinary consumer of these agents.

What independent verification would look like

Users and businesses do not need to wait for perfect cryptography to ask better questions. Credible AI agent privacy claims would come with published third-party audits, regular transparency reports on staff access and law enforcement requests, public statistics from bug bounty programmes, and prompt disclosure when something goes wrong. Meta’s bug bounty and its offer of source code to auditors are steps in that direction. OpenAI’s FAQ is a model of plain-English disclosure about what the product does not yet do.

AI agent privacy promiseStatus in October 2026How it could be verified
Muse Confidential VM locks Meta outPromised for later this year; testers and auditors onlyPublic, continuous audit Meta says it will publish
Muse isolates each user’s dataLive; pre-launch escape bugs fixedBug bounty results and incident disclosures
OpenAI staff cannot see flagged API contentRolling out to API customers since 22 SeptemberCustomer-held keys and storage
Dots credentials never reach the modelLive for supported sign-insIndependent security testing
Instinct Vault data never trains modelsIn the 26 August termsContractual; no technical evidence published
Developers give clearer transparency and rightsCommitted to the ICOICO monitoring of delivery

Four signals to watch

Four developments over the next few months will show whether AI agent privacy promises are being kept. First, whether Meta ships Confidential VM to ordinary users this year, as promised. Second, whether OpenAI adds a way to view and delete individual dot memories. Third, what the ICO says once its enquiries into agent testing conclude and its call for evidence closes. Fourth, whether any company publishes a transparency report covering staff access to agent data. Meta, Google, OpenAI and Anthropic are also due before a committee of MPs on AI security on 13 October, according to The Next Web, which may add detail.

What AI Agent Privacy Means for UK Businesses

For most organisations the immediate risk is not a headline breach at Meta or OpenAI. It is an employee connecting a personal agent to a work inbox, a shared drive or a customer system without anyone knowing. Treat AI agent privacy as a governance question first and a product question second.

Before you connect an agent to work accounts

Start with the principle the ICO keeps returning to: least privilege, the simplest AI agent privacy control there is. Give an agent read access before write access, connect only the accounts a specific task needs, and avoid “Allow Always” grants for anything that sends messages, shares files or spends money. Turn off model training where the option exists, and check whether business plans offer different defaults from personal ones, as OpenAI’s do.

Set a policy for personal agents

Most staff will meet agents as consumer apps. A short AI agent privacy policy that says which agents may touch company data, on which accounts, and with what approvals, prevents the most common failure: a well-meaning employee granting an agent full access to a mailbox full of client data. Our AI strategy team helps organisations write AI-use policies that cover agents as well as chatbots.

Ask vendors the hard questions

Before approving any agent, ask where the data is processed, who at the vendor can access it and under what conditions, whether it is used for training, what happens to absorbed data when an account is disconnected, how individual memories can be viewed and deleted, and how credentials and payments are handled. The answers should be in writing, and they should match the terms of service, not just the launch keynote. If a vendor cannot answer these AI agent privacy questions clearly, treat that as the answer.

AI agent privacy checkWhat good looks likeRed flag
Provider accessTechnically prevented, or tightly limited and audited“Access when necessary to operate the service”
TrainingOff by default for business dataOn by default with exceptions to the opt-out
MemoryViewable and deletable item by itemAll-or-nothing deletion only
DisconnectionDeletes derived data, or offers toKeeps indexed data unless you ask
CredentialsNever visible to the modelPasswords typed into chat
PaymentsSingle-use cards, approval every timeStored card used without a check
PermissionsScoped to one task and time-limited“Allow Always” by default
AccountabilityAudit log of every actionNo record of what the agent did

The bottom line

The honest answer to The Verge’s question is that it is too early to say whether AI agent makers will deliver, and the early evidence is mixed. Meta has the strongest published architecture and the longest list of reported incidents. OpenAI has the most careful documentation and a much smaller, paying user base. Instinct has the fewest promises and the most revealing contract. We asked a related question in our analysis of AI agent trust: whether anyone should let these products run their life. On AI agent privacy, the safest assumption for now is that the promise is a direction of travel, not a guarantee.

AI Agent Privacy FAQ

What does AI agent privacy mean?

AI agent privacy means how a personal assistant collects, stores, uses and shares the data it needs to act for you, including emails, messages, calendars, passwords, payment details and the information it infers about you and the people you deal with. Because agents act as well as read, it also covers what they disclose to others on your behalf.

Does Meta use Muse conversations to train its AI?

Yes, by default. Meta says Muse conversations, tool calls and agent hand-offs are sanitised to remove key personally identifiable information and then used for training, and users can opt out with a switch in Muse settings. Meta says it does not share Muse conversations with its ad systems.

Can I see what OpenAI’s Dots remembers about me?

Not item by item. OpenAI’s FAQ says you currently cannot view, delete or directly modify individual dot memories. You can delete a dot’s whole context by deleting the dot, and manage anything it has shared with ChatGPT Memory separately. That is a notable AI agent privacy gap for what OpenAI calls an always-on agent.

Does disconnecting an app delete what an agent learned?

Not necessarily, and it is one of the least understood AI agent privacy gaps. OpenAI says disconnecting a plugin stops new access but does not delete what a dot has already built into its context. Instinct’s terms say it may still use indexed data from a disconnected service unless you request deletion.

What is the ICO doing about AI agents?

On 8 October 2026 the ICO opened a six-week call for evidence on the data protection risks of agentic AI, closing on 20 November, and confirmed enquiries with OpenAI, Anthropic, Meta and the AI Security Institute about agents that reportedly bypassed protections. The evidence will shape guidance and a statutory code of practice that will set UK expectations for AI agent privacy.

Which AI agent is best for privacy?

None is clearly best yet. On published AI agent privacy controls, Muse has the most detailed architecture and lets you read and edit its memory, but Meta can still access your data and it has the longest list of reported incidents. Dots keeps credentials away from the model and makes you take over sensitive actions, but you cannot see individual memories. Instinct has made the fewest promises. Choose by the controls that matter for your data, not by the marketing.

References

AI agent makers are promising privacy: will they deliver? (The Verge)

How We Built Safety Into Muse (Meta AI Research)

Dots privacy, security, and safety FAQs (OpenAI Help Center)

Offering Zero Data Retention for frontier models (OpenAI)

Instinct Terms of Service, revised 26 August 2026

Meta rushed to fix Muse ‘VM escape’ vulnerability soon before launch (404 Media)

Muse creates detailed profiles of all your friends and family (WIRED)

Meta’s new Muse AI agent read my private messages. I never asked it to (Inc.)

Meta disputes claim that Muse read a user’s private messages without permission (TechCrunch)

Meta patches Muse exploit that let attackers control the AI agent (The Verge)

Meta’s Muse AI sent a YouTuber’s address to a stranger (The Verge)

OpenAI’s new agent is a shot at Meta, but can it compete with free? (The Verge)

OpenAI’s Dot agent is enterprise software that can also order your dinner (The Verge)

Instinct’s powerful AI assistant is raising privacy and security concerns (TechCrunch)

Meta’s Muse is outpacing ChatGPT’s early mobile launch (TechCrunch)

ICO secures changes from leading AI developers as scrutiny extends to AI agents (ICO)

Agentic AI call for evidence (ICO)

ICO tech futures: agentic AI, data protection and privacy risks (ICO)

AI giants promise to play nice with personal data after UK watchdog scrutiny (The Register)

ICO secures data protection changes from 10 AI developers, turns to agents (The Next Web)

The lethal trifecta for AI agents (Simon Willison)